Security Architect

đŸ”„ 3 minutes ago

🌐 Poland, Cyprus, +3 more countries – Remote

infoinfo

⏰ Full Time

🟡 Mid-level

🟠 Senior

đŸ‘źâ€â™‚ïž Cybersecurity / Security Engineer

đŸ‘» Ghost score 10%

infoinfo
Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of ITRex Group

ITRex Group

201 - 500 employees

Founded 2009

đŸ„ Healthcare

📩 Logistics

🏭 Manufacturing

Healthcare ‱ Logistics ‱ Manufacturing

ITRex Group is a technology consultancy and engineering firm that builds applied AI, generative AI, data platforms, and intelligent edge/IoT solutions for enterprise clients across healthcare, logistics, manufacturing, and other regulated industries. They provide end-to-end services including AI strategy and readiness assessments, product discovery and PoCs, LLM fine-tuning, MLOps/LLMOps and governance, data architecture and platform modernization (warehouses, lakes, vector DBs), and embedded hardware and edge software development. ITRex focuses on production-ready, compliant deployments that integrate models, data infrastructure, and edge devices to deliver scalable, secure AI-driven products and operations.

📋 Description

‱ Own and extend the threat model across the device, backend, and every third-party integration before the audit-ready build ‱ Defend the self-custody boundary by ensuring private keys, plaintext seed phrases, and user funds are never reachable from the server side ‱ Design split recovery backup and recovery-guard controls, including new-device verification, secondary authentication, cooling-off delays, rate limiting, alerts, and fraud logging ‱ Conduct a line-by-line internal security review of the signing path ‱ Drive mobile hardening through device integrity attestation, jailbreak/root detection, anti-tamper, certificate pinning, and biometric gating ‱ Implement the fail-closed AML/sanctions screening gate on the send path ‱ Implement pre-signing phishing and drainer risk scans for destination addresses and calldata ‱ Specify append-only audit records for every verification, screening, and decision ‱ Enforce privacy boundaries including PII segregation, field-level encryption, US-only residency, and retention/deletion by data category ‱ Own SAST, secret scanning, SCA, and licence scanning in the build pipeline ‱ Produce an SBOM for every release candidate and set dependency policy for signing and address-handling paths ‱ Co-sign every milestone exit checklist with the Delivery Lead ‱ Act as technical counterpart to the independent auditor and own the remediation register ‱ Prepare the audit-ready build, drive remediation of Severity 1/Severity 2 findings, and define rollout guardrail metrics and minimum-version policy ‱ Participate in the Severity 1 on-call rotation and produce a written postmortem within five business days of resolution ‱ Define the bug-bounty scope and severity-to-reward schedule ‱ Triage, reproduce, and coordinate remediation of confirmed findings

🎯 Requirements

‱ Experience with iOS and Android threat models ‱ Knowledge of iOS Secure Enclave and Android Keystore / StrongBox ‱ Experience with biometric APIs, platform attestation, RASP and anti-tamper, certificate pinning ‱ Hands-on mobile reverse engineering with Frida, objection, and MobSF ‱ Applied cryptography knowledge including BIP-32 / BIP-39 / BIP-44, ECDSA over secp256k1, AES-GCM, modern KDFs, envelope encryption, KMS and HSM operation, and key rotation ‱ Backend and cloud security experience with AWS security services, IAM, KMS, VPC, CloudTrail, GuardDuty, OAuth 2.0, OIDC, JWT, JWKS, WebAuthn, session and device binding, API authorisation, rate limiting, and secure service-to-service design ‱ Secure SDLC and supply-chain knowledge including threat modelling, secure code review, SAST, DAST, SCA, SBOM formats, secret scanning, and CI/CD hardening ‱ Digital-asset security knowledge including EVM and Bitcoin transaction structure, ERC-20 approval semantics, ERC-4337 account abstraction and paymaster abuse, smart-account wallets, address-poisoning and drainer patterns, and RPC provider and indexer trust assumptions ‱ Familiarity with sanctions and address-screening flows, KYC/CDD data handling, the Travel Rule data model, audit logging, retention design, US privacy requirements, ISO/IEC 27001, SOC 2, and NIST CSF ‱ Incident response experience including detection, severity triage, on-call practice, and postmortem discipline ‱ Strong written communication for auditors, counsel, and non-technical stakeholders ‱ English at C1 level ‱ Consistent overlap with US Central Time during the working day

đŸ–ïž Benefits

‱ Remote flexibility: Work where and how you work best - we trust you to deliver ‱ Competitive salary + benefits that matter (medical, wellness, learning) ‱ English classes ‱ Professional development ‱ Well-being support ‱ Career progression ‱ Regular meetups ‱ Tech talks

Apply Now

Similar Jobs

đŸ”„ 14 hours ago

Solvd, Inc.

501 - 1000

đŸ’Œ Consulting

đŸ„ Healthcare

📩 Logistics

Application Security Engineer securing a high-traffic digital news platform for Solvd, an AI-native consulting and technology services firm. Validating architecture, APIs, privacy, and full-lifecycle security controls.

AEM

🕒 August 26

Akamai Technologies

5001 - 10000

🔒 Cybersecurity

Security Architect II defending Akamai's global DDoS mitigation platform. Analyzing customer traffic and resolving real-time network security issues for leading brands.

DNS

TCP/IP

🕒 August 25

Aras Corporation

501 - 1000

🏭 Manufacturing

đŸ’Œ Consulting

📩 Logistics

Product Security Engineer securing Aras products, cloud platforms, and SDLC through DevSecOps. Building secure CI/CD pipelines and automating security controls across engineering teams.

AWS

Azure

Cloud

Cyber Security

Groovy

Jenkins

Kubernetes

Python

SDLC

Terraform

🕒 August 21

MWDN

51 - 200

đŸ’Œ Consulting

📩 Logistics

đŸ„ Healthcare

Security Researcher investigating browser, mobile, and AI-driven fraud signals. Supporting MWDN’s IAM cybersecurity client with detection research, experiments, and SDK requirements.

Android

Cyber Security

iOS

Java

JavaScript

Kotlin

Objective-C

Python

Swift

TypeScript

🕒 August 19

Callstack

51 - 200

đŸ’Œ Consulting

📣 Marketing

IT Security Officer securing systems, devices, identities, and data at Callstack, a cross-platform development consultancy. Managing cybersecurity, infrastructure, compliance, incident response, and security awareness.

AWS

Azure

Cloud

Cyber Security

DNS

Firewalls

Google Cloud Platform

Linux

MacOS