Head of Custody Security
London, United Kingdom
Full time
Hybrid
Compensation is not specified
Role
Security Engineer
Description
Responsibilities
- Conduct, design, and implement testing of security controls encompassing identity management, key management, and infrastructure (network and cloud) configurations.
- Assist in client assurance activities, including responding to Requests for Proposals (RFPs), Requests for Information (RFIs), and Due Diligence Questionnaires (DDQs).
- Recognize and analyze trends in client inquiries and provide internal teams with feedback to enhance documentation and control preparedness.
- Conduct security due diligence and continuous monitoring for Web3/blockchain vendors, assessing their control maturity, reviewing SOC reports and security documentation, and identifying residual risks.
- Coordinate external audit efforts, including walkthroughs, evidence collection, and response tracking.
- Identify and assess gaps in existing and new processes, develop, and monitor remediation recommendations to completion (e.g., onboarding flow).
- Maintain a comprehensive understanding of relevant financial regulatory security requirements and ensure control alignment.
- Research and share best practices in information security, emerging threats, and mitigation strategies with internal teams.
- Evaluate and suggest next-generation security tools, automation, and technologies to enhance overall security posture.
- Assess blockchain network or protocol upgrades for potential security impacts on the platform.
Requirements
- Minimum of 8 years of pertinent experience in security assurance, audit, compliance, or cloud security engineering.
- Demonstrated proficiency in testing and verifying security controls across IAM, key management, and network/cloud environments.
- Strong comprehension of Identity and Access Management (IAM) concepts.
- Knowledge of cryptographic key management, HSMs, and KMS systems.
- Sound understanding of cloud and network security architecture and configuration.
- Proven experience supporting SOC 1, SOC 2, ISO 27001, PCI DSS, or equivalent external audits and evaluations.
- Exposure to leading cloud platforms (AWS, GCP, Azure) and infrastructure-as-code.
- Experience in preparing client assurance materials, RFP/RFI/DDQ responses, and evidence documentation.
- Familiarity with blockchain platforms or digital asset custody systems is beneficial.
- Capable of working independently and under pressure.
- Excellent verbal and written communication skills.
- Pragmatic and solution-focused approach, ability to balance security requirements with operational feasibility and business needs.
Skills Required

Сrypto.com
Website
Сrypto.comCompany size
Not specified
Location
United States
Description
Not specified