Blockchain Security Engineer
What security roles in crypto pay
67 salaries · our own dataMost security roles in crypto pay between $143k and $268k, with a median of $200k.
As a Blockchain Security Engineer at MetaComp, you strengthen the security of digital asset and blockchain platforms for a Singapore-based payment solution provider licensed by the Monetary Authority of Singapore (MAS). You are responsible for security across the end-to-end digital asset lifecycle, from blockchain applications and wallet architecture through key management, transaction execution, monitoring, and incident response. Your key objective is to establish defense-in-depth controls so that compromise of a single employee, account, endpoint, application, or system cannot result in unauthorized transactions or material loss of digital assets.
What you'll do
- Design and review security architecture for blockchain, digital asset, wallet, and custody systems.
- Assess and secure hot, warm, and cold wallet architectures, including asset segregation, operational liquidity, and treasury/custody flows.
- Establish security controls for the complete private-key lifecycle, including key generation, storage, access, signing, backup, recovery, rotation, and retirement.
- Review and strengthen cold-wallet security, including offline key management, signing processes, multi-person authorization, physical security, and recovery controls.
- Secure the end-to-end transaction lifecycle from transaction initiation and approval through signing, broadcasting, confirmation, and settlement.
- Design controls to prevent wallet drains and unauthorized transactions, including segregation of duties, least privilege, multi-person approval, transaction limits, address allowlisting, velocity controls, and emergency suspension mechanisms.
- Perform security architecture, threat modelling, and security reviews for blockchain applications, APIs, backend services, smart contracts, and third-party integrations.
- Identify vulnerabilities across application, infrastructure, identity, wallet-access, signing, and transaction-control layers and drive remediation.
- Establish monitoring and detection for suspicious account activity, privileged access, wallet operations, abnormal transactions, and other indicators of compromise.
- Strengthen defenses against phishing, credential theft, social engineering, compromised endpoints, malicious transaction signing, insider threats, and supply-chain attacks.
- Assess new blockchain protocols, digital assets, custody technologies, and blockchain integrations before production adoption.
- Lead or support incident response for wallet compromise, unauthorized transactions, key exposure, application compromise, and other blockchain-related security incidents.
- Define security standards, controls, operational procedures, and technical requirements for digital asset systems.
- Work closely with Engineering, Infrastructure, DevOps, Risk, Compliance, and Operations teams to embed security throughout the system lifecycle.
- Support regulatory and security compliance requirements, including MAS Transaction Reporting and Monitoring (TRM), ISO 27001, PCI DSS, and applicable digital-asset security requirements.
What you bring
- 5+ years of hands-on cybersecurity experience, preferably within blockchain, digital assets, fintech, payments, banking, or financial services.
- Strong understanding of blockchain architecture, wallet security, custody models, digital asset transaction flows, and common blockchain attack vectors.
- Strong knowledge of hot, warm, and cold wallet architectures and associated operational and security controls.
- Solid understanding of cryptography, private-key lifecycle management, transaction signing, multi-party security mechanisms, HSM/KMS, and institutional custody controls.
- Strong application and API security knowledge, including authentication, authorization, secrets management, privileged access, and secure service-to-service communication.
- Experience with cloud and infrastructure security, including IAM, key management, network security, audit logging, monitoring, and workload protection.
- Good understanding of attacks involving credential compromise, phishing/social engineering, endpoint compromise, application/API exploitation, supply-chain compromise, insider threats, and unauthorized transaction signing.
- Hands-on experience with threat modelling, security architecture reviews, vulnerability assessment, incident investigation, and technical root-cause analysis.
- Ability to translate security risks into practical preventive and detective controls.
- Strong communication skills and ability to work effectively across Engineering, Operations, Risk, Compliance, and management teams.
Nice to have
- Experience securing cryptocurrency exchanges, custodians, payment platforms, stablecoin infrastructure, or other digital-asset businesses.
- Experience designing or reviewing institutional-grade wallet and custody architectures.
- Smart contract auditing or blockchain protocol security experience.
- Experience with SIEM, EDR, threat intelligence, security monitoring, and blockchain transaction monitoring.
- Knowledge of secure software development practices and DevSecOps.
- Relevant certifications such as CISSP, OSCP, CCSP, cloud security certifications, or equivalent.
About MetaComp
MetaComp Pte Ltd is a Singapore-based digital payment solution provider licensed by the Monetary Authority of Singapore (MAS) as a Major Payment Institution for Digital Payment Token Services and Cross-border Payment Transfers. Through its CAMP platform, MetaComp and its parent company Metaverse Green Exchange Pte. Ltd. (a MAS-licensed CMS holder) empower businesses to develop and scale digital asset offerings including over-the-counter transactions, fiat payments, digital asset custody, and prime brokerage.
