Head of Custody Security
Dublin, Ireland
Full time
Hybrid
Compensation is not specified
Role
Security Engineer
Description
Responsibilities
- Conduct, create, and execute testing of security controls across identity management, key management, and infrastructure (network and cloud) setups.
- Assist with client assurance tasks, including addressing Requests for Proposals (RFPs), Requests for Information (RFIs), and Due Diligence Questionnaires (DDQs).
- Recognize and assess trends in client inquiries and offer feedback to internal teams for enhancing documentation and control readiness.
- Perform security due diligence and continuous monitoring for Web3/blockchain vendors, by evaluating their control maturity, reviewing SOC reports and security documents, and identifying any remaining risks.
- Coordinate external audit activities, such as walkthroughs, gathering evidence, and tracking responses.
- Pinpoint and study gaps in current and new processes, and then create and monitor remediation suggestions to completion (e.g., onboarding processes).
- Develop and sustain knowledge of pertinent financial regulatory security requirements and guarantee control alignment.
- Investigate and distribute details on information security best practices, emerging risks, and mitigation approaches with internal teams.
- Evaluate and suggest next-generation security tools, automation, and technologies to enhance overall security stance.
- Review potential security impacts on the platform resulting from blockchain network or protocol upgrades.
Requirements
- Minimum of 8 years of suitable experience in security assurance, audit, compliance, or cloud security engineering.
- Demonstrated proficiency in testing and affirming security controls within IAM, key management, and network/cloud environments.
- Deep comprehension of Identity and Access Management (IAM) principles.
- Familiarity with cryptographic key management, HSMs, and KMS systems.
- Strong understanding of cloud and network security architecture and configuration.
- Proven track record supporting SOC 1, SOC 2, ISO 27001, PCI DSS, or similar external audits and evaluations.
- Exposure to leading cloud platforms (AWS, GCP, Azure) and infrastructure-as-code practices.
- Experience in preparing client assurance materials, RFP/RFI/DDQ responses, and evidence documentation.
- Knowledge of blockchain platforms or digital asset custody systems is advantageous.
- Ability to work autonomously and handle demanding situations effectively.
- Outstanding verbal and written communication skills.
- Pragmatic and solution-driven mindset, capable of harmonizing security requirements with operational viability and business demands.
Skills Required

Сrypto.com
Website
Сrypto.comCompany size
Not specified
Location
United States
Description
Not specified