Principal Security Architect (On-Chain & Digital Assets)

Btse · Hong Kong · posted Sep 17, 2026

Open to candidates in Hong Kong

Full-timeprincipalfintech

What this role actually asks for

Extracted by RemoteHunt

Must have

  • 10+ years in information security
  • Security architect or technical lead experience
  • Securing digital-asset custody
  • Wallet architecture, MPC, HSMs, key ceremonies
  • Cloud security fundamentals (AWS preferred)
  • Threat modeling, risk assessments, incident response

Nice to have

  • Kubernetes, containers, IaC
  • API security
  • Python for automation
  • Web3 dependency supply-chain assurance
  • CISSP, CISM, CCSP, CCSSA certifications

Tools and technologies

AWSHSMMPCKubernetesTerraformPython

The full posting

About BTSE: BTSE Group is a global leader in fintech and blockchain technology, anchored by three core business pillars: Exchange, Payments, and Infrastructure Development. Serving over 100 corporate clients worldwide, we provide white-label exchange and payment solutions. Our offerings encompass everything from exchange infrastructure hosting and development to custody, wallets, payments, blockchain integration, trading, and more.

We are looking for talented professionals in marketing, operations, customer support, and other departments. The roles offered may be on-site, remote, or hybrid, in collaboration with our local partner. About

the Opportunity

We are looking for a Principal Security Architect with deep crypto domain expertise to own security for the custody and on-chain layer of our regulated digital-asset platform end to end, spanning architecture, engineering, operations and regulatory assurance. Reporting into the central security function, you will define crypto-specific requirements and partner with dedicated InfraSec, AppSec, IAM and SOC teams on the platform capabilities they already own, rather than duplicating those functions.

You will work closely with risk, compliance, product and engineering as we build out spot trading, custody, staking and on-chain services. This is a hands-on senior role for someone who understands that in digital-asset custody a single key-management failure is a firm-ending event, and who builds controls accordingly.

Responsibilities

Lead end-to-end security architecture for the full custody stack: HSM/MPC key management, transaction authorization, signing quorums, address whitelisting, hot/cold wallet segregation, key ceremonies, delegated cold custodians, and secure staking deposit/withdrawal paths. Establish crypto-specific baseline standards, privileged-access controls, and secure SDLC requirements within our multi-account AWS environment, partnering with central InfraSec, AppSec, and IAM teams on delivery.

Define custody and blockchain detection use cases for the SOC, and directly manage incident response procedures for crypto-specific scenarios (key compromise, unauthorized transactions, on-chain incidents) alongside Corporate Security. Conduct rigorous threat modeling and security reviews across internal ledger mechanics, balance idempotency, withdrawal sequencing, and smart contract integrations to guarantee transaction money-path integrity.

Direct security assessments and ongoing assurance for external custody providers, execution systems, blockchain analytics, Travel Rule tools, and treasury integrations using group vendor security processes. Own control mapping against international regulatory standards (MiCA, DORA, FCA, MAS) and collaborate with Global Market Teams to maintain compliance during international expansion.

Responsibilities

10+ years in information security, with a proven track record as a security architect or technical lead securing digital-asset custody, high-throughput crypto platforms, or regulated financial infrastructure. Direct operational experience securing crypto custody, with deep domain expertise in wallet architecture, Multi-Party Computation (MPC), Hardware Security Modules (HSMs), key ceremonies, and signing-policy design.

Strong cloud security fundamentals (AWS preferred) in a regulated environment, with practical experience mapping security controls to licensing conditions (ISO 27001, SOC 2, NIST). Demonstrated experience running threat modeling, risk assessments, and incident response, with the ability to translate technical cryptographic risk into clear business and regulatory impact for non-security teams and regulators. Proven comfort operating in a matrixed security model, collaborating with dedicated IAM, AppSec, SOC, and infrastructure security teams rather than owning those central functions outright.

Nice-to-Haves

Hands-on experience with Kubernetes, containers, Infrastructure as Code (Terraform), API security, Python for automation, Web3 dependency supply-chain assurance, or industry certifications (CISSP, CISM, CCSP, CCSSA). Professional fluency in spoken and written Mandarin to support regional market operations and cross-functional engineering collaboration.

Perks & Benefits

Competitive compensation package Various team-building programs and company events And many more! Apply and let us tell you more!

Is this one actually worth your time?

RemoteHunt scores every remote job 0–100 against your own resume, so you apply to the handful that fit instead of the hundred that don't. Free plan, no card required.