
Security Architect
Blockstream
full-time
Posted on:
Location Type: Remote
Location: United States
Visit company websiteExplore more
About the role
- Define and drive security architecture across applications, services, and infrastructure.
- Partner with engineering teams to design and implement secure software systems, focusing on backend and data security.
- Conduct threat modeling, risk assessments, and security reviews for new and existing products.
- Develop and enforce secure coding practices, frameworks, and review processes.
- Collaborate with DevOps on cloud and container security, CI/CD hardening, and access controls.
- Evaluate and integrate security tools for code scanning, vulnerability management, and incident response.
- Guide and mentor engineers on best practices for secure application development.
- Stay ahead of emerging security trends, compliance standards, and attack vectors — particularly in fintech and blockchain domains.
Requirements
- 10+ years of experience in software engineering or security architecture roles.
- Strong full-stack background with deep backend security expertise (Python, Go, C/C++, Rust, or similar).
- Demonstrated experience designing and securing systems for enterprise fintech, banking, or blockchain environments.
- Knowledge of cryptography, authentication, and key management.
- Hands-on experience with cloud security (AWS, GCP, or similar).
- Familiarity with threat modeling, secure SDLC, and modern application security frameworks (OWASP, NIST, ISO 27001).
- Excellent communication skills — able to clearly articulate risks and solutions to both technical and non-technical stakeholders.
Benefits
- Stay Safe from Job Scams
- Communication from Blockstream will only come from an @blockstream.com email address.
- Never ask for sensitive information or purchase equipment during the hiring process.
Applicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard skills
security architecturebackend securityPythonGoC/C++Rustcryptographyauthenticationkey managementcloud security
Soft skills
communicationmentoringcollaborationrisk assessmentthreat modelingsecure coding practicesproblem-solvingarticulating risksbest practices guidancestakeholder engagement