Crypto.com

Head of Custody Security

Posted: 3 days ago

Job Description

ResponsibilitiesConduct, design, and implement testing of security controls covering identity management, key management, and infrastructure (network and cloud) configurationsSupport client assurance activities, including responding to Requests for Proposals (RFPs), Requests for Information (RFIs), and Due Diligence Questionnaires (DDQs)Identify and analyze trends in client inquiries and provide feedback to internal teams to improve documentation and control readinessPerform security due diligence and ongoing monitoring for Web3/blockchain vendors, including assessing their control maturity, reviewing SOC reports and security documentation, and identifying residual risksFacilitate external audit activities, including coordination of walkthroughs, evidence collection, and response trackingIdentify and analyze gaps in current and new processes, then develop and track remediation recommendations to completion (e.g., onboarding flow)Develop and maintain understanding of applicable financial regulatory security requirements and ensure alignment of controlsResearch and share information security best practices, emerging threats, and mitigation strategies with internal teamsEvaluate and propose next-generation security tools, automation, and technologies to enhance overall security postureReview blockchain network or protocol upgrades for their potential security impact on the platformRequirementsAt least 8 years of relevant experience in security assurance, audit, compliance, or cloud security engineeringDemonstrated experience testing and validating security controls across IAM, key management, and network/cloud environmentsStrong understanding of Identity and Access Management (IAM) principlesKnowledge of cryptographic key management, HSMs, and KMS systemsSolid grasp of cloud and network security architecture and configurationProven experience supporting SOC 1, SOC 2, ISO 27001, PCI DSS, or similar external audits and assessmentsExposure to major cloud platforms (AWS, GCP, Azure) and infrastructure-as-codeExperience in preparing client assurance materials, RFP/RFI/DDQ responses, and evidence documentationFamiliarity with blockchain platforms or digital asset custody systems is advantageousCan work independently and under pressureExcellent verbal and written communication skillsPragmatic and solution-oriented approach, ability to balance security requirements with operational feasibility and business needsWe may use artificial intelligence tools to analyze the content of your Resume/CV against the specific requirements for the position. The purpose is to support our recruitment team in reviewing applications more effectively. These tools assist our recruitment team in their evaluation of your application by providing recommendations, but they do not replace human judgment. Final hiring decisions are ultimately made by humans who consider the insights generated by the tools along with other relevant information. If you would like more details about how your personal information is processed, please contact us.

Job Application Tips

  • Tailor your resume to highlight relevant experience for this position
  • Write a compelling cover letter that addresses the specific requirements
  • Research the company culture and values before applying
  • Prepare examples of your work that demonstrate your skills
  • Follow up on your application after a reasonable time period

You May Also Be Interested In