Principal Security Engineer Crypto Digital Assets
Capital.comDubai, Dubai, United Arab Emirates
Type
Full-time
Work setup
Remote
Experience
Senior
Posted
Today
🌍 Fully remote
What security roles in crypto pay
73 salaries · our own dataMost security roles in crypto pay between $145k and $268k, with a median of $200k.
As a Principal Security Engineer at Capital.com, you lead security across the regulated digital-asset business. You own the security architecture, engineering, operations and regulatory assurance for custody and on-chain services as the company builds spot trading, staking and blockchain services. This is a hands-on senior role where you understand that in digital-asset custody, a single key-management failure is a firm-ending event, and you build controls accordingly.
What you'll do
- Own the full custody stack: MPC key management, transaction authorisation, signing quorums, address whitelisting and withdrawal controls
- Govern hot and cold wallet segregation, key ceremonies and delegated cold custodians
- Secure staking architecture and on-chain deposit and withdrawal paths
- Define crypto-specific hardening requirements for the custody and exchange stack within the existing multi-account AWS environment; partner with InfraSec on account segmentation, network and data-residency controls
- Partner with AppSec to embed crypto-specific checks into the SDLC (SAST, DAST, SCA, CI/CD security gates) for custody and exchange services
- Partner with IAM and IAM Tech on privileged access and secrets governance for crypto signing keys and custody credentials
- Define custody and blockchain-specific detection use cases and feed them into the SOC's monitoring and alerting
- Own incident response for crypto-specific scenarios including key compromise, unauthorised transaction and on-chain incidents; partner with CorpSec on group-wide incident response, forensics and breach notification
- Contribute custody and blockchain-specific scenarios into AppSec's pentest and red-team programme
- Own security assessment and ongoing assurance of the crypto vendor stack: custody platforms, execution systems, blockchain analytics, Travel Rule and treasury tooling
- Apply CorpSec's vendor onboarding and contract security process to crypto vendor engagements
- Own control mapping against MiCA and the crypto-specific provisions of DORA and FCA rules; partner with IT Governance on ISO 27001, SOC 2, NIST CSF and GDPR mapping
- Feed crypto services into the group's business continuity and disaster recovery and important-business-service mapping owned by IT Governance
- Maintain crypto-specific security policy addenda; support regulatory and IT audits on crypto scope
What you bring
- 6+ years in information security, including recent experience as a senior security engineer, security architect or security lead
- Direct experience securing crypto, digital-asset custody or a regulated financial platform; strong understanding of blockchain security, wallet architecture and key management
- Working knowledge of cloud security fundamentals (AWS preferred, Azure or GCP acceptable) in a regulated environment
- Practical knowledge of security in regulated finance and how controls map to licence conditions (ISO 27001, SOC 2, NIST)
- Experience running threat modelling, risk assessments and incident response
- Comfortable operating in a matrixed security model, partnering with dedicated IAM, AppSec, SOC and infrastructure security teams rather than owning those functions outright
- Strong analytical and problem-solving skills
- Ability to translate technical risk into business and regulatory impact
- Ability to explain security risks and mitigations to non-security teams and to regulators
- Cross-functional collaboration with risk, compliance, product and engineering teams
- Clear documentation and communication skills
Nice to have
- Hands-on Kubernetes, containers, API security and infrastructure as code
- Python proficiency for automation and scripting
- Experience running third-party and vendor security assurance
- Recognised certifications: CISSP, CISM, CCSP or equivalent
- Hands-on experience with MPC-based custody, key ceremonies and signing-policy design
- Familiarity with MiCA, DORA, FCA crypto rules or comparable digital-asset regimes
- Background in secure SDLC and DevSecOps (OWASP, secure-by-design)
- Experience with smart contract security review: threat modelling, commissioning and managing external audits, and driving findings through to resolution
- Experience designing transaction signing and approval flows so that what a user or operator authorises is provably what gets signed and broadcast
- Experience reviewing business logic in the money path including withdrawal sequencing, balance idempotency and internal ledger integrity, where the flaw sits in the logic rather than the cryptography
- Familiarity with supply-chain assurance for crypto-specific dependencies: wallet SDKs, chain libraries, node clients and signing tooling, including pinning, provenance and upgrade discipline
- Experience defining bug bounty scope for crypto assets and triaging and calibrating severity for on-chain findings
What we offer
- Competitive salary
- Annual leave policy to recharge and enjoy life outside work
- Employee referral programme with rewards for bringing in talent
- Comprehensive health and pension benefits, including location-specific perks
- 30 extra days to work remotely from anywhere in the world (some restrictions apply)
- Two additional paid volunteer days each year to support causes you care about
About Capital.com
Capital.com is a regulated digital-asset business building spot trading, custody, staking and on-chain services for its client base.
