Head of Custody Security
Madrid, Spain
Full time
Hybrid
Compensation is not specified
Role
Security Engineer
Description
Responsibilities
- Conduct, design, and execute testing of security controls encompassing identity management, key management, and infrastructure (network and cloud) configurations.
- Assist client assurance activities, including addressing Requests for Proposals (RFPs), Requests for Information (RFIs), and Due Diligence Questionnaires (DDQs).
- Identify and analyze trends in client inquiries, offering feedback to internal teams to enhance documentation and control readiness.
- Engage in security due diligence and continuous monitoring for Web3/blockchain vendors, evaluating control maturity, reviewing SOC reports and security documentation, and pinpointing residual risks.
- Coordinate external audit activities, such as walk-throughs, evidence collection, and response tracking.
- Recognize and evaluate gaps in existing and new processes, subsequently formulating and monitoring remediation recommendations to completion (e.g., onboarding flow).
- Develop and sustain comprehension of applicable financial regulatory security requirements, ensuring control alignment.
- Research and share information security best practices, emerging threats, and mitigation strategies with internal teams.
- Evaluate and suggest next-generation security tools, automation, and technologies to enhance overall security posture.
- Review blockchain network or protocol upgrades for potential security impacts on the platform.
Requirements
- Minimum of 8 years of pertinent experience in security assurance, audit, compliance, or cloud security engineering.
- Demonstrated proficiency in testing and validating security controls regarding IAM, key management, and network/cloud environments.
- Solid understanding of Identity and Access Management (IAM) principles.
- Knowledge of cryptographic key management, HSMs, and KMS systems.
- Proficient in cloud and network security architecture and configuration.
- Proven track record in supporting SOC 1, SOC 2, ISO 27001, PCI DSS, or equivalent external audits and assessments.
- Exposed to major cloud platforms (AWS, GCP, Azure) and infrastructure-as-code.
- Experience in preparing client assurance materials, RFP/RFI/DDQ responses, and evidence documentation.
- Familiarity with blockchain platforms or digital asset custody systems considered a plus.
- Capable of working autonomously and effectively under pressure.
- Excellent verbal and written communication skills.
- Pragmatic and solution-oriented approach, capable of balancing security requirements with operational feasibility and business needs.
Skills Required

Сrypto.com
Website
Сrypto.comCompany size
Not specified
Location
United States
Description
Not specified