NextRaiseNextRaiseFind jobs
Sign inSign up free
Jobs
8 days ago
Apply with autofill
Apply with autofill
IG
Itrex-group·8 days ago
8 days ago

Security Architect (f/m/d)

PolandFull-timeRemoteMid · 2-5 yearsArchitect

Sign up free to see how well your resume matches this role.

Boost your chances at itrex-group

How you compare FREE

?
Your scoreYour score: not yet known
→
23
Top 10%Top 10%: 23 out of 100

Top 10% of NextRaise users matched against Architect roles in Poland.

Must-have skills for this role

  • ios security
  • android security
  • applied cryptography
  • threat modelling

PDF or DOCX · no account needed

Apply faster with autofill FREEitrex-group uses Workable - autofill it instead of retyping.careers.example.com/applyAutofillingFull namePriya SharmaEmailpriya.sharma@example.comPhone+49 30 1234567LocationBerlGet the extension

What you'll do

  • Own and extend the threat model across device, backend and every third-party integration, finalised before the audit-ready build
  • Defend the self-custody boundary: no private keys, no plaintext seed phrases and no user funds ever reachable from the server side
  • Design the split recovery backup and the recovery-guard controls: new-device verification, secondary authentication, cooling-off delay, rate limiting, alerts and fraud logging
  • Carry out a line-by-line internal security review of the signing path and drive mobile hardening: device integrity attestation, jailbreak / root detection, anti-tamper, certificate pinning, and biometric gating both at app open and at transaction approval
  • Implement the fail-closed AML / sanctions screening gate on the send path, and the pre-signing phishing and drainer risk scan on destination addresses and calldata
  • Specify the append-only audit record for every verification, screening and decision, and enforce privacy boundaries: PII segregation, field-level encryption, US-only residency, and retention and deletion by data category
  • Own SAST, secret scanning, SCA and licence scanning in the build pipeline, produce an SBOM for every release candidate, and set dependency policy for the signing and address-handling path
  • Co-sign the exit checklist of every milestone with the Delivery Lead, act as technical counterpart to the independent auditor, and own the remediation register for all findings
  • Prepare the audit-ready build, triage and drive remediation of Severity 1 / Severity 2 findings, and define the rollout guardrail metrics and minimum-version policy
  • Participate in the Severity 1 on-call rotation and produce a written postmortem within five business days of resolution
  • Define the bug-bounty scope and severity-to-reward schedule, and triage, reproduce and coordinate remediation of confirmed findings

What they're looking for

  • Mobile and application security: iOS and Android threat models, iOS Secure Enclave and Android Keystore / StrongBox, biometric APIs, platform attestation, RASP and anti-tamper, certificate pinning, and hands-on mobile reverse engineering (Frida, objection, MobSF)
  • Applied cryptography at review-level depth: BIP-32 / BIP-39 / BIP-44, ECDSA over secp256k1, AES-GCM, modern KDFs, envelope encryption, KMS and HSM operation, key rotation
  • Backend and cloud security: AWS security services (IAM, KMS, VPC, CloudTrail, GuardDuty), OAuth 2.0 / OIDC / JWT / JWKS, WebAuthn, session and device binding, API authorisation, rate limiting, and secure service-to-service design
  • Secure SDLC and supply chain: threat modelling, secure code review, SAST / DAST / SCA, SBOM formats, secret scanning, and CI/CD hardening
  • Digital-asset security: EVM and Bitcoin transaction structure, ERC-20 approval semantics, ERC-4337 account abstraction and paymaster abuse, smart-account wallets, address-poisoning and drainer patterns, and the trust assumptions of RPC providers and indexers
  • Compliance-adjacent engineering: sanctions and address-screening flows, KYC/CDD data handling, the Travel Rule data model, audit logging, retention design, and US privacy requirements; working familiarity with ISO/IEC 27001, SOC 2 and NIST CSF
  • Incident response: detection, severity triage, on-call practice and postmortem discipline
  • Strong written communication for auditors, counsel and non-technical stakeholders; English at C1 level; a working day with consistent overlap with US Central Time

Nice to have

  • Prior work with a non-custodial wallet SDK, ideally an existing wallet SDK or a comparable open-source kit
  • Smart-contract audit background
  • Penetration-testing certification
  • Experience with app-store review for financial applications
  • Bug-bounty triage experience

Summarised by NextRaise from the employer’s description, which follows in full below.

Full description from employer

About ITRex

THE PLACE

ITRex - AI pioneers who build systems that actually work in the real world, not just in demos. We're 250+ people spread across the US and Europe, creating solutions for companies like Procter & Gamble and Shutterstock. We keep it simple, build it right, and focus on what works.

THE PEOPLE

We're the kind of people who don't ignore messages in Slack, who jump in to help when you're stuck on a problem, and who offer solutions instead of blame when things go sideways. We believe in openness, accountability, and having each other's backs. No office politics, no hidden agendas - just people who care about doing good work together and supporting each other to get there.

THE ROLE

We are looking for a Security Architect to be the single technical owner of security and privacy assurance for a self-custody crypto wallet during its first delivery phase. Keys are generated, stored and used on the user's own device, in code that has already been distributed through the app stores - a defect on the signing path can't be fixed server-side or pulled back from devices that already hold the build. Security work here is preventive and continuous, not a hardening phase before launch. You will report to the Project Manager / Delivery Lead, work daily alongside the wallet SDK integration, backend, mobile and DevOps engineers and QA, co-sign the exit checklist of every milestone, and act as the technical counterpart to the independent auditor engaged by the client.

Requirements

Our Expectations

  • Mobile and application security: iOS and Android threat models, iOS Secure Enclave and Android Keystore / StrongBox, biometric APIs, platform attestation, RASP and anti-tamper, certificate pinning, and hands-on mobile reverse engineering (Frida, objection, MobSF)
  • Applied cryptography at review-level depth: BIP-32 / BIP-39 / BIP-44, ECDSA over secp256k1, AES-GCM, modern KDFs, envelope encryption, KMS and HSM operation, key rotation
  • Backend and cloud security: AWS security services (IAM, KMS, VPC, CloudTrail, GuardDuty), OAuth 2.0 / OIDC / JWT / JWKS, WebAuthn, session and device binding, API authorisation, rate limiting, and secure service-to-service design
  • Secure SDLC and supply chain: threat modelling, secure code review, SAST / DAST / SCA, SBOM formats, secret scanning, and CI/CD hardening
  • Digital-asset security: EVM and Bitcoin transaction structure, ERC-20 approval semantics, ERC-4337 account abstraction and paymaster abuse, smart-account wallets, address-poisoning and drainer patterns, and the trust assumptions of RPC providers and indexers
  • Compliance-adjacent engineering: sanctions and address-screening flows, KYC/CDD data handling, the Travel Rule data model, audit logging, retention design, and US privacy requirements; working familiarity with ISO/IEC 27001, SOC 2 and NIST CSF
  • Incident response: detection, severity triage, on-call practice and postmortem discipline
  • Strong written communication for auditors, counsel and non-technical stakeholders; English at C1 level; a working day with consistent overlap with US Central Time

Nice to have

  • Prior work with a non-custodial wallet SDK, ideally an existing wallet SDK or a comparable open-source kit
  • Smart-contract audit background
  • Penetration-testing certification
  • Experience with app-store review for financial applications
  • Bug-bounty triage experience

Your Responsibilities

  • Own and extend the threat model across device, backend and every third-party integration, finalised before the audit-ready build
  • Defend the self-custody boundary: no private keys, no plaintext seed phrases and no user funds ever reachable from the server side
  • Design the split recovery backup and the recovery-guard controls: new-device verification, secondary authentication, cooling-off delay, rate limiting, alerts and fraud logging
  • Carry out a line-by-line internal security review of the signing path and drive mobile hardening: device integrity attestation, jailbreak / root detection, anti-tamper, certificate pinning, and biometric gating both at app open and at transaction approval
  • Implement the fail-closed AML / sanctions screening gate on the send path, and the pre-signing phishing and drainer risk scan on destination addresses and calldata
  • Specify the append-only audit record for every verification, screening and decision, and enforce privacy boundaries: PII segregation, field-level encryption, US-only residency, and retention and deletion by data category
  • Own SAST, secret scanning, SCA and licence scanning in the build pipeline, produce an SBOM for every release candidate, and set dependency policy for the signing and address-handling path
  • Co-sign the exit checklist of every milestone with the Delivery Lead, act as technical counterpart to the independent auditor, and own the remediation register for all findings
  • Prepare the audit-ready build, triage and drive remediation of Severity 1 / Severity 2 findings, and define the rollout guardrail metrics and minimum-version policy
  • Participate in the Severity 1 on-call rotation and produce a written postmortem within five business days of resolution
  • Define the bug-bounty scope and severity-to-reward schedule, and triage, reproduce and coordinate remediation of confirmed findings

Benefits

What We Offer

Why people stay

First, the foundation:

  • Remote flexibility: Work where and how you work best - we trust you to deliver
  • Fair compensation: Competitive salary + benefits that matter (medical, wellness, learning)

Then, the growth:

  • Ownership opportunities: See a problem worth solving? Own it. We back smart risks over bureaucratic safety
  • AI enhancement: We leverage AI to make you faster and stronger - complementing your abilities, not replacing them
  • Learning investment: English classes, professional development, well-being support
  • Career progression: Real paths up, not just sideways shuffling

Finally, the people:

  • Responsive teammates: No ignored Slacks, no "not my problem" attitudes
  • Supportive culture: When you're stuck, people help. When things break, we fix them together
  • Human connections: Regular meetups, tech talks, and actual relationships beyond work

Company

IG
Itrex-group
Poland

Company facts come from this company's own listings. We only show what the postings themselves carry.

Sourced from Itrex Group's careers site·first seen 15 Sept 2026·last verified 15 Sept 2026·How we source jobs

Similar jobs

  • Operations Quality Principal Architect at RocheWarsaw, Poland–match not yet calculated
  • Operations Quality Principal Architect at RochePoland–match not yet calculated
  • Data Architect (100% Remote) (EMEA Only) at Allshore TalentAny, Poland–match not yet calculated
  • Finance AI Value Architect at Rockwell AutomationKatowice, Poland–match not yet calculated
  • Azure Virtual Desktop Architect at harmanLodz, Poland–match not yet calculated

Browse more jobs

  • Architect jobs in United States
  • Architect jobs in India
  • Architect jobs in United Kingdom
  • Retail Sales Associate jobs in United States