JobRaahGet matched free

Jobs

Security Architect (f/m/d)

ITRex Group · Remote · Poland · Remote

Posted Sep 15, 2026

Apply with JobRaah

Sign up free: we match you to jobs like this, tailor your application and fill the form. 2 free applications every day.

About ITRex THE PLACE ITRex - AI pioneers who build systems that actually work in the real world, not just in demos. We're 250+ people spread across the US and Europe, creating solutions for companies like Procter & Gamble and Shutterstock. We keep it simple, build it right, and focus on what works. THE PEOPLE We're the kind of people who don't ignore messages in Slack, who jump in to help when you're stuck on a problem, and who offer solutions instead of blame when things go sideways. We believe in openness, accountability, and having each other's backs. No office politics, no hidden agendas - just people who care about doing good work together and supporting each other to get there. THE ROLE We are looking for a Security Architect to be the single technical owner of security and privacy assurance for a self-custody crypto wallet during its first delivery phase. Keys are generated, stored and used on the user's own device, in code that has already been distributed through the app stores - a defect on the signing path can't be fixed server-side or pulled back from devices that already hold the build. Security work here is preventive and continuous, not a hardening phase before launch. You will report to the Project Manager / Delivery Lead, work daily alongside the wallet SDK integration, backend, mobile and DevOps engineers and QA, co-sign the exit checklist of every milestone, and act as the technical counterpart to the independent auditor engaged by the client. Requirements Our Expectations Mobile and application security: iOS and Android threat models, iOS Secure Enclave and Android Keystore / StrongBox, biometric APIs, platform attestation, RASP and anti-tamper, certificate pinning, and hands-on mobile reverse engineering (Frida, objection, MobSF) Applied cryptography at review-level depth: BIP-32 / BIP-39 / BIP-44, ECDSA over secp256k1, AES-GCM, modern KDFs, envelope encryption, KMS and HSM operation, key rotation Backend and cloud security: AWS security services (IAM, KMS, VPC, CloudTrail, GuardDuty), OAuth 2.0 / OIDC / JWT / JWKS, WebAuthn, session and device binding, API authorisation, rate limiting, and secure service-to-service design Secure SDLC and supply chain: threat modelling, secure code review, SAST / DAST / SCA, SBOM formats, secret scanning, and CI/CD hardening Digital-asset security: EVM and Bitcoin transaction structure, ERC-20 approval semantics, ERC-4337 account abstraction and paymaster abuse, smart-account wallets, address-poisoning and drainer patterns, and the trust assumptions of RPC providers and indexers Compliance-adjacent engineering: sanctions and address-screening flows, KYC/CDD data handling, the Travel Rule data model, audit logging, retention design, and US privacy requirements; working familiarity with ISO/IEC 27001, SOC 2 and NIST CSF Incident response: detection, severity triage, on-call practice and postmortem discipline Strong written communication for auditors, counsel and…