Principal Security Architect

Principal Security Architect

Full-Time 80000 - 100000 £ / year (est.) No working from home possible
Copper.co

At a Glance

  • Tasks: Lead security architecture and ensure robust systems at Copper.
  • Company: Join a forward-thinking tech firm transforming digital asset engagement.
  • Benefits: Enjoy 35+ days off, comprehensive medical insurance, and enhanced pension contributions.
  • Other info: Diverse and inclusive workplace committed to employee growth.
  • Why this job: Shape the future of security in a dynamic, innovative environment.
  • Qualifications: Expertise in multi-chain architecture and cloud security required.

The predicted salary is between 80000 - 100000 £ per year.

The Principal Security Architect is the senior technical authority for security architecture at Copper. The role reports to the CISO and partners closely with Engineering. The holder sets architectural direction, reviews and approves designs for major change, and acts as the firm's reference point on the security of the systems, protocols, and integrations Copper depends on. The role is predominantly architecture and assurance, with limited hands-on solution design in the cloud and integration space where reference patterns are needed.

Key Responsibilities

  • Architectural authority: Hold formal security sign-off authority for major changes to Copper's platforms, infrastructure, and integrations. Shape and maintain the security architecture patterns, principles, and reference designs that engineering teams build against. Provide the senior technical security position in architectural and business decisions, including escalations where security and delivery pressures conflict.
  • Custody, signing, and cryptographic architecture: Provide architectural security leadership over Copper's signing infrastructure, working alongside specialist engineering and cryptography teams. Scope covers the people, process, and operational design around MPC-based signing. Solid conceptual grounding in threshold cryptography and signature schemes is required; cryptographer-level work is not. Review and approve changes to transaction construction, signing flows, approval policy, and key lifecycle operations. Provide architectural assurance over chain-of-trust constructs adjacent to custody, including verifiable build pipelines, hardware-backed code signing, and authenticator-bound administrative paths.
  • Multi-chain and integration security: Reason at architectural depth across the range of blockchains Copper supports, including EVM, UTXO, and account-based non-EVM families. This requires a working understanding of transaction construction, signing semantics, consensus assumptions, and validator and staking models across these environments, without being a protocol engineer in any of them. Assess third-party smart contract architectures, implementations, and audit reports to a level sufficient to understand the exploit and risk surface, without performing line-by-line code review. Review first-party integrations with partner networks, including those underpinning staking and similar on-chain participation, and form a defensible security position on the operational and contract risk Copper inherits.
  • Settlement, collateral, and off-exchange architecture: Provide architectural ownership of the security model for Copper's settlement, collateral mirroring, and off-exchange product surfaces. Reason about the trust boundaries between Copper, venues, and clients, and ensure architectural controls match the obligations each side carries.
  • Identity and access architecture: Own identity and access architecture as a dedicated pillar of the role. Set patterns for workforce, workload, and third-party identity across Entra ID, federated SSO, OAuth2 / OIDC, SAML, and modern authenticators. Govern entitlement design, privileged access, and access models for contractors, vendors, and external operators.
  • Cloud and platform security: Maintain working architectural fluency in both AWS and Azure, including network topology, segmentation, secrets handling, and platform telemetry. Produce reference patterns and, where needed, direct integration designs in the cloud and platform space.
  • Third-party and protocol risk: Lead technical security review of vendors, integrated venues, and protocols, including challenge of assurances that do not stand up to scrutiny. Support client and counterparty due diligence on the technical content most likely to be misrepresented or under-specified.
  • Policy, regulatory, and assurance support: Maintain a working understanding of the regulatory regimes applicable to Copper's licensed entities sufficient to translate architectural decisions into language Compliance and GRC can defend. Primary ownership of regulatory positioning sits elsewhere. Contribute to security policy, standards, and control framework development as the senior technical reviewer. Participate in resilience exercises and incident reviews where architectural input materially shapes the outcome.

Skills and Experience

Essential:

  • Multi-chain architectural literacy. Able to reason across EVM, UTXO, and non-EVM account-based chains at the level of transaction construction, signing, consensus, and validator models. Comfortable assessing third-party smart contract designs, implementations, and audit reports for exploit and risk surface without performing code review.
  • Custody and signing architecture. Strong conceptual grasp of threshold signing, signature schemes, and key lifecycle. Able to design and challenge the operational architecture around signing, separation of duties, approval policy, key ceremony equivalents in MPC, and recovery, to a high standard.
  • Settlement and collateral architecture. Demonstrable experience reasoning about settlement, collateral, and off-exchange constructs, including trust boundaries between custodians, venues, and clients.
  • Identity and access architecture. Senior-level experience designing and governing identity across Entra ID, federated SSO, OAuth2 / OIDC, SAML, and modern authenticators. Comfortable with entitlement governance and third-party access design.
  • Cloud security. Working architectural understanding of AWS and Azure, including the ability to produce reference patterns and limited direct integration designs.
  • Architectural authority and judgement. Track record of holding sign-off on significant designs, taking defensible positions under uncertainty, and owning residual risk.
  • Change review and assurance. Comfortable reviewing the work of engineering peers, infrastructure changes, and vendor designs, and able to hold the line where it matters.
  • Communication. Able to operate credibly with engineers, senior business stakeholders, auditors, and regulators in the same week, without losing precision at any of them.

Desirable:

  • Familiarity with chain-of-trust constructs including verifiable builds, reproducible build pipelines, and hardware-backed code signing.
  • Awareness of the regulatory landscape relevant to digital asset custody and trading (for example, FCA, FINMA, FSRA / ADGM, MiCA).
  • Compliance familiarity across ISO 27001, SOC 2, and NIST CSF / 800-53, with the ability to map controls cleanly between them.
  • Enterprise architecture grounding (TOGAF, SABSA) where it complements rather than replaces technical depth.

Benefits:

  • Paid Time Off - A minimum of 35 days of paid time off per year, inclusive of annual leave and public holidays. Employees also receive one additional day of annual leave for each year of service.
  • Comprehensive Medical Insurance - Inclusive of dental, optical, audiology, and mental health coverage, with medical history disregarded.
  • Life Insurance.
  • Enhanced Pension Contributions - Includes an enhanced employer matching contribution.
  • 24/7 Employee Assistance Programme (EAP).

Copper is an equal-opportunity employer. We embrace diversity and equal opportunities in a serious way. We are committed to building a team that represents a variety of backgrounds, perspectives, and skills. The more inclusive we are, the better our work will be. It is in our differences that we will continue to grow and ensure Copper is transforming how institutional investors engage with digital assets. Copper is a Disability Confident Employer, please let us know if you have a disability. If you require us to provide any assistance during the recruitment process, then we would ask you to highlight this to us and we will be happy to accommodate.

Principal Security Architect employer: Copper.co

Copper is an exceptional employer that prioritises employee well-being and professional growth, offering a minimum of 35 days of paid time off, comprehensive medical insurance, and enhanced pension contributions. Our inclusive work culture fosters diversity and collaboration, ensuring that every team member's unique perspective contributes to our mission of transforming institutional engagement with digital assets. Located in a dynamic environment, we provide opportunities for meaningful impact and career advancement in the rapidly evolving field of security architecture.

Copper.co

Contact Details:

Copper.co Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Principal Security Architect

Get Involved in the Cybersecurity Community

Diving into the cybersecurity community is key for landing that full-time gig. Join forums like Reddit's r/cybersecurity or attend local meetups to connect with industry veterans and other job seekers. Networking is everything in this field—don’t just be a passive lurker!

Show Off Your Skills with Capture the Flag Competitions

Participate in Capture the Flag (CTF) competitions; these are not just a fun way to boost your skills but also a chance to showcase your talent to potential employers. Many companies, including Copper.co, love seeing candidates who actively engage in these challenges.

Tailor Your Online Presence

Make sure your LinkedIn and any professional profiles reflect your cybersecurity expertise. Share your projects, whether they’re personal or from a previous role, to catch the eye of hiring managers. This is how they’ll find your passion and commitment to the field!

Apply Directly Through Copper.co

Don’t forget to head straight to our website and check out any openings for cybersecurity roles at Copper.co. Applying directly can sometimes give you an edge, especially if you can mention that you've been following our work or engaging in the community.

We think you need these skills to ace Principal Security Architect

Security Architecture
Cryptography
Threshold Signing
Multi-Chain Architectural Literacy
Transaction Construction
Consensus Models
Identity and Access Management

Some tips for your application 🫡

Show off your technical skills:In cybersecurity, it's crucial to highlight your technical prowess. Make sure your CV showcases specific skills like network security, penetration testing, or threat analysis. If you have relevant certifications (like CEH or CISSP), pop those on the front page to grab attention!

Tailor your portfolio for the role:Even for a full-time role, a portfolio can set you apart. If you've worked on any cybersecurity projects—be it CTF challenges, security assessments, or research papers—include these in your application. This demonstrates not just your skills, but also your hands-on experience!

Use real-world examples:When writing your cover letter, don’t just stick to your qualifications. Share real-world examples of how you’ve tackled security issues or vulnerabilities. This gives the hiring team at Copper.co insight into your practical problem-solving abilities and makes your application memorable.

Demonstrate your passion for cybersecurity:Cybersecurity is an ever-evolving field, so show us that you’re always learning! Mention any recent courses, webinars, or industry events you’ve attended. This not only exhibits your enthusiasm but also signals to Copper.co that you’re committed to staying ahead in the game.

How to prepare for a job interview at Copper.co

Sharpen Your Technical Skills

For a role in cybersecurity, it’s essential to be up-to-date with the latest tools and techniques. Brush up on your knowledge of firewalls, intrusion detection systems, and vulnerability assessment tools. Be ready to discuss specific scenarios where you’ve applied these skills, as hands-on experience can really set us apart in interviews.

Prepare for Scenario-Based Questions

Expect the interviewers at Copper.co to throw in some hypothetical situations to see how you’d handle them. Think about common security breaches or incidents and be prepared to explain how you would respond. This not only shows your problem-solving skills but also your understanding of real-world cybersecurity challenges.

Highlight Your Certifications

Certifications like CompTIA Security+, CISSP, or CEH can give you a significant edge in a full-time role in cybersecurity. Make sure to mention these during your interview and be prepared to discuss what you learned through those certifications and how they relate to the position at Copper.co.

Show Your Passion for Cybersecurity

Since you’re going for a full-time gig, showing genuine enthusiasm for the field can make all the difference. Share any personal projects, blogs, or communities you’re part of that relate to cybersecurity. This not only showcases your passion but also your commitment to staying engaged in this ever-evolving field.