Senior Security Engineer, Digital Assets Platform, VP

Citi

Confirmed live 2 days ago High trust
Remote

Quick summary

Work type
Remote
Location
New York, NY
Salary
$142,320–$213,480 / yr
Posted
31 days ago
Freshness
Confirmed live 2 days ago

Market check

Salary context

Competitive pay

How this pay compares to similar roles

Similar $186k
This role $178k
$122k most similar roles pay here $234k

This role pays more than 52% of similar roles. Most pay $155,000–$216,000 — the shaded band above. At the midpoint, this role pays about $178k versus about $186k for comparable roles.

Based on 240 similar postings.

Employer

About Citi

Citi is one of the world’s most trusted financial institutions, proudly serving millions of customers across the United States.

Citi currently has 256 open roles on FindRole.

Listed pay typically runs $140,080–$210,120 across 238 roles with salary data.

Most-posted roles

View all roles at Citi

At a glance

TL;DR · Senior Security Engineer, Digital Assets Platform, VP

Senior Security Engineer – Digital Assets Platform - VP joins the Digital Assets Platform engineering team to build the security layer for institutional blockchain adoption. This hands-on role involves writing production Java code to develop security-critical backend services, including cryptographic libraries, key management APIs, and secure transaction pipelines. The engineer will manage the lifecycle of Hardware Security Modules using PKCS#11 and JCE, while architecting Multi-Party Computation protocols and threshold signature schemes for distributed key management. Key responsibilities include implementing symmetric and asymmetric encryption, managing certificate lifecycles, and enforcing zero-trust architecture. The role requires expertise in Java, advanced cryptography, and security tools like SAST/DAST. This position addresses the critical challenge of ensuring cryptographic integrity for transaction, wallet, and key lifecycle operations within a regulated infrastructure for institutional digital asset custody and management.

What you'll do

  • Develop and maintain security-critical backend services in Java, including cryptographic libraries and signing workflows.
  • Manage the integration and operational lifecycle of Hardware Security Modules (HSMs) using PKCS#11 and JCE.
  • Architect and implement Multi-Party Computation (MPC) protocols and threshold signature schemes for distributed key management.
  • Enforce cryptographic best practices such as symmetric/asymmetric encryption, digital signatures, and key derivation across the platform.
  • Implement secure design patterns including zero-trust architecture, secrets management, and mutual TLS.
  • Conduct threat modeling, security design reviews, and cryptographic risk assessments with internal risk teams.
  • Integrate SAST/DAST tooling into CI/CD pipelines to ensure security-by-design for all shipped services.
  • Act as the technical escalation point for security incidents and cryptographic design decisions.

What we're looking for

  • Bachelor's degree in Computer Science, Computer Engineering, Cybersecurity, or a related technical discipline.
  • Master's or PhD in Cryptography, Information Security, or Computer Science (preferred).
  • 7–10 years of experience in software engineering with a focus on application security, cryptography, or secure systems design.
  • Production-level proficiency in backend Java for building security-critical, enterprise-grade services.
  • Hands-on experience integrating Hardware Security Modules (HSMs) via PKCS#11, JCE/JCA, or vendor-specific APIs.
  • Practical understanding of Multi-Party Computation (MPC), threshold signature schemes (TSS), and distributed key management.
  • Deep knowledge of applied cryptography including symmetric/asymmetric encryption, digital signatures, and certificate management.
  • Experience with secure design patterns, threat modeling frameworks, and CI/CD security tooling.
  • Experience in digital asset custody, blockchain key management, or institutional crypto infrastructure (preferred).
  • Knowledge of financial services regulatory frameworks such as NIST SP 800-57, FIPS 140-2/3, or PCI-DSS (preferred).
  • Exposure to MPC libraries like MPC-CMP or tss-lib and formal security certifications like CISSP or OSCP (preferred).

More like this

Similar roles

Staff Security Engineer, Secure Digital Asset Operations

Ripple

New York, NY 134 days ago $200,000$250,000
Smart Contract Security Cryptography MPC HSM Python JavaScript Security Architecture Key Management Security Automation Security-by-Design Digital Asset Security Off-chain Transactions Vendor Integration
8+ yrs exp

Senior Platform Security Engineer

Datadog

Remote 44 days ago
Kubernetes AWS Azure GCP Go Python Rust Vault Istio Consul Envoy OWASP MITRE ATT&CK PASTA STRIDE CIS Cloud Security Application Security
Remote

Senior Cloud Platform Security Engineer

CoStar Group

Arlington, VA +1 74 days ago $115,000$203,000
AWS GCP Azure Kubernetes EKS Terraform CloudFormation Python Ansible PowerShell CI/CD IaC Wiz Snyk Datadog Prisma Cloud Orca OPA Gatekeeper Falco Security Hub GuardDuty SBOM
6+ yrs exp

Senior Software Engineer, Security Platform

Robinhood

Bellevue, WA +1 128 days ago $196,000$230,000
Python Go Java AWS Kubernetes PostgreSQL Kafka Spark Snowflake Distributed Systems Data Pipelines Encryption CCPA GDPR Authentication Authorization Tokenization Monitoring Auditing
5+ yrs exp Hybrid

Senior Security Engineer

Green Dot Corp

Los Angeles, CA 86 days ago $113,400$162,000
Azure Network Security Penetration Testing CI/CD DevSecOps Identity and Access Management (IAM) NIST CIS Benchmarks OWASP SSDLC Azure Firewall Network Security Groups Key Vault Firewalls
5+ yrs exp Hybrid

Senior Security Engineer

Green Dot Corp

Los Angeles, CA 86 days ago $113,400$162,000
Azure Network Security Penetration Testing CI/CD DevSecOps Identity and Access Management (IAM) NIST CIS Benchmarks OWASP SSDLC Azure Firewall Network Security Groups Key Vault Firewalls
5+ yrs exp Hybrid