Head of Custody Security
Los Angeles, USA
Full time
Hybrid
Compensation is not specified
Role
Security Engineer
Description
Responsibilities
- Conducting, designing, and executing security control testing for identity management, key management, and infrastructure (network and cloud) configurations.
- Supporting client assurance activities, including addressing Requests for Proposals (RFPs), Requests for Information (RFIs), and Due Diligence Questionnaires (DDQs).
- Identifying and analyzing trends in client inquiries, providing feedback to internal teams to enhance documentation and control readiness.
- Performing security due diligence and continuous monitoring for Web3/blockchain vendors, evaluating their control maturity, reviewing SOC reports and security documentation, and identifying residual risks.
- Facilitating external audit activities by coordinating walkthroughs, collecting evidence, and tracking responses.
- Identifying and analyzing gaps in current and new processes, developing and tracking remediation recommendations to completion (e.g., onboarding flow).
- Developing and maintaining understanding of applicable financial regulatory security requirements, ensuring alignment of controls.
- Researching and sharing information on security best practices, emerging threats, and mitigation strategies with internal teams.
- Evaluating and recommending next-generation security tools, automation, and technologies to strengthen overall security posture.
- Reviewing blockchain network or protocol upgrades for potential security impacts on the platform.
Requirements
- Minimum 8 years of relevant experience in security assurance, audit, compliance, or cloud security engineering.
- Demonstrated experience in testing and validating security controls across IAM, key management, and network/cloud environments.
- Solid understanding of Identity and Access Management (IAM) principles.
- Knowledge of cryptographic key management, HSMs, and KMS systems.
- Strong grasp of cloud and network security architecture and configuration.
- Proven experience in supporting SOC 1, SOC 2, ISO 27001, PCI DSS, or similar external audits and assessments.
- Exposure to major cloud platforms (AWS, GCP, Azure) and infrastructure-as-code.
- Experience in preparing client assurance materials, RFP/RFI/DDQ responses, and evidence documentation.
- Familiarity with blockchain platforms or digital asset custody systems is a plus.
- Capability to work independently and under pressure.
- Excellent verbal and written communication skills.
- Pragmatic and solution-oriented approach, ability to balance security requirements with operational feasibility and business needs.
Salary: $190,000 - $230,000 a year
We may utilize artificial intelligence (AI) tools for parts of the hiring process, like reviewing applications, analyzing resumes, or assessing responses. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you need more information about how your data is handled, please contact us.
Skills Required

Сrypto.com
Website
Сrypto.comCompany size
Not specified
Location
United States
Description
Not specified