×
Register Here to Apply for Jobs or Post Jobs. X

Senior Security Engineer – Digital Assets Platform - VP

Job in New York, New York County, New York, 10261, USA
Listing for: Citigroup Inc.
Full Time position
Listed on 2026-08-15
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security & Data Protection, Blockchain / Web3
Salary/Wage Range or Industry Benchmark: 142320 - 213480 USD Yearly USD 142320.00 213480.00 YEAR
Job Description & How to Apply Below
Location: New York

About the Role
Discover your future at Citi

Working at Citi is far more than just a job. A career with us means joining a team of more than 230,000 dedicated people from around the globe. At Citi, you'll have the opportunity to grow your career, give back to your community and make a real impact.

Job Overview

Citi's Integrated Digital Assets Platform (CIDAP) is at the vanguard of institutional blockchain adoption — and security is its foundation. As digital assets move from innovation to regulated infrastructure, the cryptographic integrity of every transaction, wallet, and key lifecycle operation becomes mission-critical. We are building the security layer that the world's most sophisticated financial institution can trust.

We are seeking a Senior Security Engineer (VP) to join our New York-based Digital Assets Platform engineering team. This is a hands‑on, Java‑focused backend engineering role for a security‑minded engineer who understands both the craft of secure software development and the cryptographic primitives that underpin digital asset custody, signing, and key management.

You will sit inside the core engineering team — writing production code every day — while being the resident authority on cryptographic design patterns, HSM integration, MPC protocols, and security architecture. Your work will directly protect billions of dollars of digital asset infrastructure used by institutional clients worldwide.

Key Responsibilities
  • Design, develop, and maintain security‑critical backend services in Java— including cryptographic libraries, key management APIs, signing workflows, and secure transaction pipelines — within Citi's Digital Assets Platform.
  • Own the integration and operational lifecycle of Hardware Security Modules (HSMs)— including vendor evaluation, API integration (PKCS#11, JCE), key generation, rotation, and policy enforcement.
  • Architect and implement Multi‑Party Computation (MPC) protocols and threshold signature schemes (TSS) for distributed key management and institutional‑grade wallet signing operations.
  • Apply and enforce cryptographic best practices across the platform — including symmetric and asymmetric encryption (AES‑GCM, RSA, ECC), digital signatures (ECDSA, EdDSA), hashing, and key derivation (HKDF, PBKDF2).
  • Define and implement secure design patterns for distributed systems — including zero‑trust architecture, secrets management, mutual TLS, certificate lifecycle management, and secure enclave usage.
  • Collaborate with Citi's Cybersecurity, Risk, and Architecture teams to conduct threat modelling, security design reviews, and cryptographic risk assessments for new platform capabilities.
  • Champion security‑by‑design across the engineering team — conducting code reviews with a security lens, embedding SAST/DAST tooling into CI/CD pipelines, and raising the security posture of every service shipped.
  • Engage with external HSM vendors, MPC protocol libraries, and standards bodies to stay ahead of the cryptographic landscape and inform Citi's technology roadmap.
  • Act as a technical escalation point for security incidents, vulnerability triage, and cryptographic design decisions across the Digital Assets Platform.
Qualifications Required
  • 7–10 years of experience in software engineering with a significant focus on application security, cryptography, or secure systems design
  • Strong, production‑level proficiency in backend Java— including experience building security‑critical, enterprise‑grade services
  • Hands‑on experience integrating Hardware Security Modules (HSMs) via PKCS#11, JCE/JCA, or vendor‑specific APIs
  • Practical understanding of Multi‑Party Computation (MPC) protocols, threshold signature schemes (TSS), or distributed key management architectures
  • Deep knowledge of applied cryptography— symmetric/asymmetric encryption, digital signatures, key exchange protocols, certificate management (PKI/X.509), and secure hashing
  • Familiarity with secure design patterns— zero‑trust, least‑privilege, secrets management, mTLS, and secure enclave technologies
  • Experience with threat modelling frameworks (STRIDE, PASTA, or equivalent) and security design review processes
  • Understanding of CI/CD security tooling—…
Position Requirements
10+ Years work experience
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary