Security Architect @ITRex Group
All Others
Salary unspecified
Remote Location
Employment Type full-time
Posted 3wks ago

[Hiring] Security Architect @ITRex Group

3wks ago - ITRex Group is hiring a remote Security Architect. πŸ’Έ Salary: unspecified πŸ“Location: Armenia

Role Description

We are looking for a Security Architect to be the single technical owner of security and privacy assurance for a self-custody crypto wallet during its first delivery phase. Security work here is preventive and continuous, not a hardening phase before launch. You will report to the Project Manager / Delivery Lead, work daily alongside the wallet SDK integration, backend, mobile and DevOps engineers and QA, co-sign the exit checklist of every milestone, and act as the technical counterpart to the independent auditor engaged by the client.

Our Expectations

  • Mobile and application security:
    • iOS and Android threat models
    • iOS Secure Enclave and Android Keystore / StrongBox
    • Biometric APIs
    • Platform attestation
    • RASP and anti-tamper
    • Certificate pinning
    • Hands-on mobile reverse engineering (Frida, objection, MobSF)
  • Applied cryptography at review-level depth:
    • BIP-32 / BIP-39 / BIP-44
    • ECDSA over secp256k1
    • AES-GCM
    • Modern KDFs
    • Envelope encryption
    • KMS and HSM operation
    • Key rotation
  • Backend and cloud security:
    • AWS security services (IAM, KMS, VPC, CloudTrail, GuardDuty)
    • OAuth 2.0 / OIDC / JWT / JWKS
    • WebAuthn
    • Session and device binding
    • API authorisation
    • Rate limiting
    • Secure service-to-service design
  • Secure SDLC and supply chain:
    • Threat modelling
    • Secure code review
    • SAST / DAST / SCA
    • SBOM formats
    • Secret scanning
    • CI/CD hardening
  • Digital-asset security:
    • EVM and Bitcoin transaction structure
    • ERC-20 approval semantics
    • ERC-4337 account abstraction and paymaster abuse
    • Smart-account wallets
    • Address-poisoning and drainer patterns
    • The trust assumptions of RPC providers and indexers
  • Compliance-adjacent engineering:
    • Sanctions and address-screening flows
    • KYC/CDD data handling
    • The Travel Rule data model
    • Audit logging
    • Retention design
    • US privacy requirements
    • Working familiarity with ISO/IEC 27001, SOC 2 and NIST CSF
  • Incident response:
    • Detection
    • Severity triage
    • On-call practice
    • Postmortem discipline
  • Strong written communication for auditors, counsel and non-technical stakeholders; English at C1 level; a working day with consistent overlap with US Central Time

Nice to have

  • Prior work with a non-custodial wallet SDK, ideally an existing wallet SDK or a comparable open-source kit
  • Smart-contract audit background
  • Penetration-testing certification
  • Experience with app-store review for financial applications
  • Bug-bounty triage experience

Your Responsibilities

  • Own and extend the threat model across device, backend and every third-party integration, finalised before the audit-ready build
  • Defend the self-custody boundary: no private keys, no plaintext seed phrases and no user funds ever reachable from the server side
  • Design the split recovery backup and the recovery-guard controls: new-device verification, secondary authentication, cooling-off delay, rate limiting, alerts and fraud logging
  • Carry out a line-by-line internal security review of the signing path and drive mobile hardening: device integrity attestation, jailbreak / root detection, anti-tamper, certificate pinning, and biometric gating both at app open and at transaction approval
  • Implement the fail-closed AML / sanctions screening gate on the send path, and the pre-signing phishing and drainer risk scan on destination addresses and calldata
  • Specify the append-only audit record for every verification, screening and decision, and enforce privacy boundaries: PII segregation, field-level encryption, US-only residency, and retention and deletion by data category
  • Own SAST, secret scanning, SCA and licence scanning in the build pipeline, produce an SBOM for every release candidate, and set dependency policy for the signing and address-handling path
  • Co-sign the exit checklist of every milestone with the Delivery Lead, act as technical counterpart to the independent auditor, and own the remediation register for all findings
  • Prepare the audit-ready build, triage and drive remediation of Severity 1 / Severity 2 findings, and define the rollout guardrail metrics and minimum-version policy
  • Participate in the Severity 1 on-call rotation and produce a written postmortem within five business days of resolution
  • Define the bug-bounty scope and severity-to-reward schedule, and triage, reproduce and coordinate remediation of confirmed findings

What We Offer

  • Remote flexibility: Work where and how you work best - we trust you to deliver
  • Fair compensation: Competitive salary + benefits that matter (medical, wellness, learning)
  • Ownership opportunities: See a problem worth solving? Own it. We back smart risks over bureaucratic safety
  • AI enhancement: We leverage AI to make you faster and stronger - complementing your abilities, not replacing them
  • Learning investment: English classes, professional development, well-being support
  • Career progression: Real paths up, not just sideways shuffling
  • Responsive teammates: No ignored Slacks, no "not my problem" attitudes
  • Supportive culture: When you're stuck, people help. When things break, we fix them together
  • Human connections: Regular meetups, tech talks, and actual relationships beyond work
Before You Apply
️
remote Be aware of the location restriction for this remote position: Armenia
β€Ό Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Security Architect @ITRex Group
All Others
Salary unspecified
Remote Location
Employment Type full-time
Posted 3wks ago
Apply for this position
Did not apply βœ“
Applied βœ“
Sent Follow-Up βœ“
Interview Scheduled βœ“
Interview Completed βœ“
Offer Accepted βœ“
Offer Declined βœ“
Application Denied βœ“
Unlock 125,000+ Remote Jobs
️
remote Be aware of the location restriction for this remote position: Armenia
β€Ό Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Apply for this position
Did not apply βœ“
Applied βœ“
Sent Follow-Up βœ“
Interview Scheduled βœ“
Interview Completed βœ“
Offer Accepted βœ“
Offer Declined βœ“
Application Denied βœ“
Unlock 125,000+ Remote Jobs
Γ—
Apply to the best remote jobs
before everyone else

Access 125,000+ vetted remote jobs and get daily alerts.

4.9 β˜…β˜…β˜…β˜…β˜… from 500+ reviews

⚑ 126,868+ remote jobs, refreshed hourly

πŸ”” Real-time alerts: Apply first, direct to employer

πŸ›‘οΈ Vetted companies, no scams, true remote only

Unlock All Jobs Now

Maybe later