Principal Security Engineer

Principal Security Engineer

London Full-Time 112000 - 168000 £ / year (est.) No home office possible
Go Premium
K

At a Glance

  • Tasks: Lead security operations and protect sensitive data in a cutting-edge crypto environment.
  • Company: Join a pioneering cybersecurity firm focused on secure cloud solutions for crypto applications.
  • Benefits: Enjoy remote work flexibility, generous paid time off, and perks like gym memberships and tech equipment.
  • Why this job: Be part of a mission-driven team tackling real-world blockchain risks in a collaborative culture.
  • Qualifications: 10+ years in security engineering with expertise in incident response and API security required.
  • Other info: Work with industry leaders and contribute to innovative security solutions in the fast-paced crypto space.

The predicted salary is between 112000 - 168000 £ per year.

3 months ago Be among the first 25 applicants

About The Job Principal Security Engineer
Context
Our client is a cybersecurity company that builds custody SaaS protocol for web3 apps. Think of it as a developer tool that provides secure cloud for crypto. Their mission is to bring serenity to DeFi by eliminating new blockchain risks and making crypto transactions easier, faster, more affordable, and compliant with existing regulations.
From fintechs to large banks to e-commerce sites, our client gives financial institutions and businesses the freedom to own and transfer crypto on battle-designed security infrastructure. Their API is designed to offer a best-in-class developer experience allowing any platform to deploy custodial wallets in a matter of days, with streamlined feature delivery and frequent security upgrades.
Founded in 2020 in Paris, our client is incubated at Station F (awarded Future 40), accelerated by Techstars and recognized DeepTech by the French Ministry of Economy. Our company is fully remote with offices in Paris, Amsterdam, New York, London, Stockholm, Sofia, and other cities.
Job Description
You will contribute to one of the most ambitious technology projects in crypto today: building a trustless custody infrastructure for the trillion-dollar digital asset industry.
You will join an amazing team of leaders (CTO, VP of Research, CISO) and experts (Software Engineers, R&D Engineers, Security Engineers) in a highly challenging and collaborative environment.
We are looking for a Principal Security Engineer to run security operations within our company. You will have to demonstrate excellent surveillance and emergency response skills. You will need a strong commitment to security rules and knowledge of all hazards and threats to safety. Ultimately, you will work to ensure the security of our business information, employee data and client information throughout our entire network.
As Principal Security Engineer, you will detect insecure features and malicious activities within our networks and infrastructure. You will implement customized application security assessments for client-based asset risk, corporate policy compliance as well as conduct vulnerability assessment. You must have an advanced understanding of TCP/IP, common networking ports and protocols, traffic flow, system administration, OSI model, defense-in-depth and common security elements. Your focus is not only limited to assessing whether vulnerabilities exist but also how those risks could be mitigated. The ideal candidate loves security and possesses both deep and wide infosec expertise. You will make things more secure by protecting system boundaries, keeping computer systems and network devices hardened against attacks and securing highly sensitive data.
Mission
Your primary goal will be to create and preserve environments where employees, clients and assets are monitored, safe, and well-protected.
Example of a primary metric would be Defect Discovery Rate.
Your Day-to-day Projects Will Involve

  • Sharing the big picture to your team, defining the levels of priority within the product roadmap, and being accountable for the deadlines and the quality of production.
  • Acting as a powerhouse of ideas on all security and technical issues.
  • Determining security violations and inefficiencies by conducting periodic audits.
  • Keeping customers updated via performance and system status reports
  • Analyzing security systems, researching weaknesses, reporting possible threats or software issues, and finding ways to counter them on a daily basis.
  • Creating and maintaining artefacts in a protected repo established as a single source of truth.
  • Finding and removing outdated and vulnerable code and code libraries.
  • Building security tooling and automation for internal use that enable SecTeam to operate at high speed and at scale.
  • Detecting and responding to company-wide security incidents.
  • Running security forensics in the case of a cyber attack and/or a data leak.
  • Identifying and mitigating complex security vulnerabilities before an attacker exploits them.
  • Taking initiatives to curb known abusive activity, and identifying unknown abuse vectors.
  • Focusing on designing, researching, and executing attacks to challenge the blue team.
  • Reporting on the red team engagements providing in-depth analysis of the security issues.
  • Developing technical solutions and new security tools to help mitigate security vulnerabilities and automate repeatable tasks.
  • Writing comprehensive reports including assessment-based findings, outcomes and propositions for further system security enhancement.
  • Authoring and updating internal and external docs, and formally initiating and delivering requirements.
  • Authoring blogs posts and doing talks at security conferences on vulnerabilities discovered.
  • Facilitating cross-branch communication and know-how exchange between team members.
  • Handling communications with independent vulnerability researchers and designing appropriate mitigation strategies for reported vulnerabilities.
  • Implementing security best practices and new ideas to encourage innovation within your team.
  • Working closely with CISO to embed best-in-class information security processes within the corporate policies, processes, and internal workflows.
  • Making proposals across several teams on cross-functional security initiatives.
  • Acting as DRI and escalation point for teams facing extremely complex technical challenges.
  • Keeping abreast of the latest developments in crypto, DeFi and blockchain to feed the company\’s strategic orientations.
  • Continually researching current and emerging technologies and propose changes.

Requirements

  • 10+ years experience as a Principal Security Engineer, 2+ years direct experience with incident response, and 2+ years experience in anti-abuse processes.
  • Recognized security expert in multiple specialty areas, with cross-functional team experience
  • Ownership of significant sub-department objectives, goals and OKRs.
  • Engineering expert capabilities of challenging the reasoning of other engineers.
  • Experience in designing and securing APIs (RESTful, GraphQL, SWIFT).
  • In-depth understanding of coding languages, namely Rust, Go, Python, and/or Typescript.
  • Hands-on experience analyzing high volumes of logs, network data and attack artefacts.
  • Proficiency with antivirus, vulnerability scanning and information security software.
  • Detailed technical knowledge of database and operating system security.
  • Hands on experience in security systems, including firewalls, intrusion detection systems, anti-virus software, authentication systems, log management, content filtering, etc.
  • Ability to discover and patch SQLi, XSS, CSRF, SSRF, authentication and authorization flaws, and other web-based security vulnerabilities (OWASP Top 10 and beyond).
  • Experience with cloud platforms such as AWS, GCP, and setting up environments between them.
  • Thorough understanding of the latest security principles, techniques, and protocols.
  • Excellent knowledge of security procedures and relevant industry standards (ISO, SOC, etc.).
  • Experience testing secure, fault-tolerant, and resilient systems.
  • Founding-spirited with grit and guts to pursue complex worldwide ambitions.
  • Excellent analytical and problem-solving skills.
  • Excellent written and verbal communication skills.
  • Humble, respectful, and very professional to others.
  • Able to decide even in stressful, unstable situations.
  • Appetite for Cybersecurity, Fintech, Blockchain and/or Crypto industries.
  • (Bonus) Certifications such as CISSP, GSEC, CEH or CISM are appreciated.
  • (Bonus) Experience from national or international military/cyber defense bodies.
  • (Bonus) Proven track record working on developer tools and/or cybersecurity software.
  • (Bonus) Hands-on experience and willingness to contribute to open source projects.
  • (Bonus) Proven work experience in blockchain, DeFi and/or cybersecurity industries.
  • (Bonus) Extensive knowledge about the crypto custody industry and its use cases.
  • (Bonus) Having been to Chaos Communication Camp or Empire Hacking NYC

Benefits

  • Title: Principal Security Engineer
  • Salary: 140-300K / year (avg base range).
  • Equity: 0.4-0.6% ( 14.4-21.8M in case of 2B exit).
  • Bonus: Peer and spot bonuses after 8 months with us.
  • Location: Hybrid. You can either work in our offices, from home, or remote.
  • Paid time off: No less than 30 days per year, plus national holidays.
  • Employee benefits: Healthcare, life insurance, retirement plan, sponsored transportation, gym cards, food, Apple devices and home office equipment, tuition fee assistance, team retreats, and more.

Seniority level

  • Seniority level

    Mid-Senior level

Employment type

  • Employment type

    Full-time

Job function

  • Job function

    Information Technology

  • Industries

    IT Services and IT Consulting

Referrals increase your chances of interviewing at Kinsei Recruitment by 2x

Get notified about new Principal Security Engineer jobs in London, England, United Kingdom .

London, England, United Kingdom 1 week ago

London, England, United Kingdom £50,000 – £60,000 1 month ago

London, England, United Kingdom 1 month ago

London, England, United Kingdom 2 weeks ago

London, England, United Kingdom 2 months ago

London, England, United Kingdom 1 week ago

London, England, United Kingdom 1 week ago

Newsroom Front-End Developer (12 Month FTC/Secondment)

Isleworth, England, United Kingdom 1 week ago

London, England, United Kingdom 1 week ago

London, England, United Kingdom £30,000 – £40,000 1 month ago

London, England, United Kingdom 5 months ago

London, England, United Kingdom 1 week ago

London, England, United Kingdom 2 days ago

Software Engineer (Typescript, Node.js, React)

We’re unlocking community knowledge in a new way. Experts add insights directly into each article, started with the help of AI.

#J-18808-Ljbffr

Principal Security Engineer employer: Kinsei Recruitment

As a leading cybersecurity company based in Paris, our client offers an exceptional work environment that fosters innovation and collaboration among top-tier professionals. With a fully remote setup and generous benefits including 30 days of paid time off, healthcare, and opportunities for personal growth, employees are empowered to thrive both personally and professionally. Joining this dynamic team means contributing to groundbreaking projects in the crypto space while enjoying a supportive culture that values creativity and security excellence.
K

Contact Detail:

Kinsei Recruitment Recruiting Team

StudySmarter Expert Advice 🤫

We think this is how you could land Principal Security Engineer

✨Tip Number 1

Familiarise yourself with the latest trends in cybersecurity, especially in the context of blockchain and DeFi. This knowledge will not only help you during interviews but also demonstrate your genuine interest in the field.

✨Tip Number 2

Engage with the cybersecurity community by attending relevant conferences or webinars. Networking with professionals in the industry can provide valuable insights and potentially lead to referrals.

✨Tip Number 3

Showcase your hands-on experience with security tools and technologies that are relevant to the role. Being able to discuss specific projects or challenges you've tackled can set you apart from other candidates.

✨Tip Number 4

Prepare to discuss your approach to incident response and vulnerability management. Having a clear strategy and examples ready can demonstrate your expertise and readiness for the challenges of the role.

We think you need these skills to ace Principal Security Engineer

Incident Response
API Security Design
Vulnerability Assessment
Threat Modelling
Security Auditing
Network Security
TCP/IP Protocols
Traffic Flow Analysis
Operating System Security
Intrusion Detection Systems
Log Management
SQL Injection Prevention
Cross-Site Scripting (XSS) Mitigation
Cloud Security (AWS, GCP)
Security Best Practices Implementation
Analytical Skills
Problem-Solving Skills
Technical Writing
Communication Skills
Collaboration with Cross-Functional Teams

Some tips for your application 🫡

Tailor Your CV: Make sure your CV highlights relevant experience in cybersecurity, particularly in areas like incident response and API security. Use specific examples that demonstrate your expertise in the technologies mentioned in the job description.

Craft a Compelling Cover Letter: In your cover letter, express your passion for cybersecurity and the crypto industry. Mention how your skills align with the company's mission to enhance security in DeFi and provide specific instances where you've successfully mitigated security risks.

Showcase Technical Skills: Clearly outline your technical skills related to coding languages (like Rust, Go, Python, and Typescript) and security tools. Provide examples of projects or situations where you applied these skills effectively.

Highlight Continuous Learning: Mention any relevant certifications or ongoing education in cybersecurity, blockchain, or fintech. This shows your commitment to staying updated with the latest security principles and practices, which is crucial for this role.

How to prepare for a job interview at Kinsei Recruitment

✨Showcase Your Expertise

As a Principal Security Engineer, it's crucial to demonstrate your deep understanding of security principles and practices. Be prepared to discuss your experience with incident response, vulnerability assessments, and the specific technologies you've worked with, such as APIs and cloud platforms.

✨Prepare for Technical Questions

Expect technical questions that assess your knowledge of security vulnerabilities, coding languages, and network protocols. Brush up on topics like SQL injection, XSS, and the OWASP Top 10 to confidently tackle these questions during the interview.

✨Highlight Your Problem-Solving Skills

Security roles often require quick thinking and effective problem-solving. Prepare examples from your past experiences where you successfully identified and mitigated security threats or improved security processes, showcasing your analytical skills.

✨Demonstrate Team Collaboration

This role involves working closely with various teams, so be ready to discuss how you've collaborated with cross-functional teams in the past. Highlight your communication skills and ability to facilitate knowledge exchange, which are essential for fostering a secure environment.

Principal Security Engineer
Kinsei Recruitment
Go Premium

Land your dream job quicker with Premium

You’re marked as a top applicant with our partner companies
Individual CV and cover letter feedback including tailoring to specific job roles
Be among the first applications for new jobs with our AI application
1:1 support and career advice from our career coaches
Go Premium

Money-back if you don't land a job in 6-months

K
  • Principal Security Engineer

    London
    Full-Time
    112000 - 168000 £ / year (est.)

    Application deadline: 2027-08-18

  • K

    Kinsei Recruitment

Similar positions in other companies
UK’s top job board for Gen Z
discover-jobs-cta
Discover now
>