368,634open jobs
9,437companies
50,578added this week
Browse all
Location
Remote/Hybrid (Dubai, United Arab Emirates)
Seniority
Principal · 6+ years exp
Overview
Company
Impact
Profile match
Capital.com is a global fintech company and online trading platform headquartered in Limassol, Cyprus, and founded in 2016. The company provides access to over 5,500 financial instruments including contracts for difference (CFDs) on stocks, indices, commodities, forex, and cryptocurrencies. It operates internationally with offices in London, Melbourne, Warsaw, and Dubai, serving over three million registered accounts through its proprietary AI-powered web and mobile platforms.

We are looking for a Principal Security Engineer with deep crypto domain expertise to lead security across our regulated digital-asset business. As we build out spot trading, custody, staking and on-chain services for our client base, security is the foundation the whole business stands on. This role owns it.

You will be the security owner for our crypto platform's custody and on-chain layer end to end: architecture, engineering, operations and regulatory assurance for the parts of the stack that are unique to digital assets. For platform capabilities already owned by central security teams (cloud, application security, IAM, SOC), you'll define the crypto-specific requirements and partner on delivery rather than duplicate ownership. You will work closely with risk, compliance, product and engineering, and report into the central security function.

This is a hands-on senior role for someone who understands that in digital-asset custody, a single key-management failure is a firm-ending event, and who builds controls accordingly.

Key Responsibilities:

    Digital asset and custody security (owned by this role):

  • Own the full custody stack: MPC key management, transaction authorisation, signing quorums, address whitelisting and withdrawal controls
  • Govern hot/cold wallet segregation, key ceremonies and delegated cold custodians
  • Secure staking architecture and on-chain deposit/withdrawal paths
  • Platform, cloud and application security (partner with InfraSec, AppSec and IAM):

  • Define crypto-specific hardening requirements for the custody and exchange stack within the existing multi-account AWS environment; partner with InfraSec on account segmentation, network and data-residency controls
  • Partner with AppSec to embed crypto-specific checks into the SDLC (SAST, DAST, SCA, CI/CD security gates) for custody and exchange services
  • Partner with IAM and IAM Tech on privileged access and secrets governance for crypto signing keys and custody credentials
  • Threat detection, response and testing (partner with SOC, CorpSec and AppSec):

  • Define custody- and blockchain-specific detection use cases and feed them into SOC's monitoring and alerting
  • Own incident response for crypto-specific scenarios (key compromise, unauthorised transaction, on-chain incident); partner with CorpSec on the group-wide IR process, forensics and breach notification
  • Contribute custody- and blockchain-specific scenarios into AppSec's pentest and red-team programme
  • Third-party and vendor security (own crypto vendor risk, partner with CorpSec on process):

  • Own security assessment and ongoing assurance of the crypto vendor stack: custody platforms, execution systems, blockchain analytics, Travel Rule and treasury tooling
  • Apply CorpSec's vendor onboarding and contract security process to crypto vendor engagements
  • Regulatory, resilience and governance (own crypto-specific mapping, partner with IT Governance):

  • Own control mapping against MiCA and the crypto-specific provisions of DORA and FCA rules; partner with IT Governance on ISO 27001, SOC 2, NIST CSF and GDPR mapping
  • Feed crypto services into the group's BC/DR and important-business-service mapping owned by IT Governance
  • Maintain crypto-specific security policy addenda; support regulatory and IT audits on crypto scope

Required Qualifications:

    • 6+ years in information security, including recent experience as a senior security engineer, security architect, or security lead;
    • Direct experience securing crypto, digital-asset custody, or a regulated financial platform; strong understanding of blockchain security, wallet architecture and key management;
    • Working knowledge of cloud security fundamentals (AWS preferred, Azure/GCP acceptable) in a regulated environment;
    • Practical knowledge of security in regulated finance and how controls map to licence conditions (ISO 27001, SOC 2, NIST);
    • Experience running threat modelling, risk assessments and incident response;
    • Comfortable operating in a matrixed security model - partnering with dedicated IAM, AppSec, SOC and infrastructure security teams rather than owning those functions outright.

Nice to have:

    • Hands-on Kubernetes, containers, API security and infrastructure as code;
    • Python proficiency for automation and scripting;
    • Experience running third-party / vendor security assurance;
    • Recognised certifications: CISSP, CISM, CCSP, or equivalent;
    • Hands-on experience with MPC - based custody, key ceremonies and signing-policy design;
    • Familiarity with MiCA, DORA, FCA crypto rules, or comparable digital-asset regimes;
    • Background in secure SDLC and DevSecOps (OWASP, secure-by-design);
    • Experience with smart contract security review: threat modelling, commissioning and managing external audits, and driving findings through to resolution;
    • Experience designing transaction signing and approval flows, so that what a user or operator authorises is provably what gets signed and broadcast;
    • Experience reviewing business logic in the money path - withdrawal sequencing, balance idempotency, internal ledger integrity - where the flaw sits in the logic rather than the cryptography;
    • Familiarity with supply-chain assurance for crypto-specific dependencies: wallet SDKs, chain libraries, node clients and signing tooling, including pinning, provenance and upgrade discipline;
    • Experience defining bug bounty scope for crypto assets, and triaging and calibrating severity for on-chain findings.

Soft Skills:

    • Strong analytical and problem-solving skills;
    • Able to translate technical risk into business and regulatory impact;
    • Able to explain security risks and mitigations to non-security teams and to regulators;
    • Cross-functional collaboration with risk, compliance, product and engineering teams;
    • Clear documentation and communication skills.

What You Will Get in Return:

    • Competitive Salary: We believe great work deserves great pay. Your skills and talents will be rewarded with a salary that makes you feel valued and motivated.
    • Work-Life Harmony: Join a company that genuinely cares about you, because your life outside of work matters just as much as your time on the clock. #LI-Hybrid
    • Generous Time Off: Need a breather? Our annual leave policy lets you recharge and enjoy life outside of work without a worry.
    • Employee Referral Program: Love working here? Share the love. Bring your talented friends on board and get rewarded for growing our team.
    • Comprehensive Health & Pension Benefits: From medical insurance to pension plans, we’ve got your back. Plus location-specific benefits and perks.
    • Workation Wonderland: Live your digital nomad dreams with 30 extra days to work remotely from anywhere in the world (some restrictions apply).
    • Volunteer Days: Take two additional paid days each year to support causes you care about and give back to the community.
Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
368,634 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
Dubai
$185k – $260k per year • Remote • Full-Time • 8+ years exp • Bachelor's Degree
DevOps
AWS
CI/CD
GCP
Kubernetes
GitHub
Cybersecurity
Clair
Dependabot
OWASP Top 10
OWASP ZAP
Snyk
Trivy
Apply
$68k – $85k per year • In office • Full-Time • Master's Degree • San Jose
Python
AI/ML
AI Agents
DevOps
Amazon EC2
AWS
AWS Lambda
Bitbucket
CI/CD
CloudFormation
Docker
Git
Kubernetes
Terraform
Amazon S3
IAM
HPC
Cybersecurity
Least Privilege
Apply
$19k – $47k per year (Estimated) • Remote • Full-Time • Perm
C#
C#
ASP.NET Core
Dapper
Entity Framework Core
Databases
Apache Kafka
ClickHouse
ElasticSearch
PostgreSQL
RabbitMQ
Redis
DevOps
CI/CD
Docker
Docker Compose
GitHub Actions
Kubernetes
TeamCity
GitHub
GitLab
Apply
$17k – $43k per year (Estimated) • In office • Full-Time • Tomsk
C#
Java
Python
DevOps
CI/CD
Docker
Git
Grafana
Graylog
Kubernetes
Prometheus
Splunk
Apply
$19k – $47k per year (Estimated) • Remote • Full-Time • Tomsk
C#
C#
ASP.NET Core
Dapper
Entity Framework Core
Databases
Apache Kafka
ClickHouse
ElasticSearch
PostgreSQL
RabbitMQ
Redis
DevOps
CI/CD
Docker
Docker Compose
GitHub Actions
Kubernetes
TeamCity
GitHub
GitLab
Apply
Junior AI Engineer 1 month ago
Remote/Hybrid • Limassol
JavaScript
Python
SQL
AI/ML
LLM
DevOps
Rest API
Management
n8n
Zapier
Apply
$62k – $111k per year (Estimated) • Remote/Hybrid • 5+ years exp • Warsaw
Python
AI/ML
AI Agents
LLM
RAG
EU AI Act
Function Calling
LLM Guardrails
Cybersecurity
GDPR
Apply
$39k – $84k per year (Estimated) • Remote/Hybrid • Warsaw
Python
SQL
AI/ML
AI Agents
dbt
Prompt Engineering
Management
Slack
n8n
Apply
Applied AI Engineer 1 month ago
$27k – $112k per year (Estimated) • In office • Mumbai
Python
SQL
Databases
Chroma
FAISS
Pinecone
Weaviate
AI/ML
AI Agents
Claude
Gemini
LLM
Prompt Engineering
RAG
OpenAI
Apply
$68k – $111k per year (Estimated) • Remote/Hybrid • 5+ years exp • Warsaw
JavaScript
Python
SQL
Python
Django
FastAPI
Flask
Databases
MySQL
PostgreSQL
AI/ML
AI Agents
Anomaly Detection
AWS Bedrock
Embeddings
LLM
Vertex AI
Anthropic
LLM Guardrails
OpenAI
Structured Outputs
Model Context Protocol
RAG
DevOps
AWS
CI/CD
Docker
GitLab CI
Grafana
Kubernetes
Prometheus
Rest API
Vector
GitLab
Cybersecurity
Okta
Management
Confluence
Jira
Slack
Apply
Remote/Hybrid • Full-Time • Bachelor's Degree • Dubai
Apply
Remote/Hybrid • Full-Time • 15+ years exp • Master's Degree • Dubai
Apply
In office • Full-Time • 5+ years exp • Bachelor's Degree • Dubai
Apply
In office • Dubai
Apply
In office • 1+ year exp • Dubai
C++
JavaScript
Python
TypeScript
Apply
See all jobs
This is one of many
368,634 more open roles from verified company boards, updated every day.