Senior Security Engineer
Listed on 2026-03-13
-
IT/Tech
Cybersecurity, Blockchain / Web3
At BNY, our culture allows us to run our company better and enables you to grow and succeed. As a leading global financial services company at the heart of the global financial system, we influence nearly 20% of the world’s investible assets. Every day, our teams harness cutting‑edge AI and breakthrough technologies to collaborate with clients, driving transformative solutions that redefine industries and uplift communities worldwide.
Recognized as a top destination for innovators and champions of inclusion, BNY is where bold ideas meet advanced technology and exceptional talent. Together, we power the future of finance – and this is what #LifeAtBNY is all about. Join us and be part of something extraordinary.
Job SummaryWe are building the secure, scalable infrastructure that powers the future of institutional digital finance. As part of BNY’s Digital Assets and Cybersecurity organization, this role will help architect and develop next‑generation digital asset custody and wallet solutions used by global institutional clients.
This position focuses on secure cryptographic engineering, blockchain integration, and resilient infrastructure design. The team is building a highly sensitive, net‑new solution from the ground up, requiring deep expertise in secure software development, MPC frameworks, hardware security, and distributed systems.
This is a highly specialized role operating within a discreet and strategic initiative. The individual will collaborate closely with cryptographers and a team of 6 engineers, with opportunity to influence architecture and technical direction.
Location:
NYC in office preferred with a 4 day hybrid schedule. (remote flexibility on the East Coast)
- Security Engineering & Threat Modeling: Lead comprehensive threat modeling exercises to identify and mitigate vulnerabilities (e.g., MPC round manipulation, malicious clients, MITM risks). Conduct crypto‑focused code reviews and design security validation tests.
- Cryptographic Engineering & Protocol Design: Implement and audit cryptographic mechanisms including key exchange, signature schemes, and secure multiparty computation (MPC). Ensure resistance to side‑channel attacks and common cryptographic pitfalls.
- Blockchain & Wallet Infrastructure Development: Design and build secure digital asset custody and wallet infrastructure. Integrate with blockchain nodes and APIs, construct and parse transaction formats (e.g., Bitcoin UTXO, Ethereum RLP), and manage transaction assembly and broadcast.
- Secure Systems Architecture: Architect secure storage for encrypted key shares and audit logs. Develop networking components (sockets, RPC frameworks), concurrency controls, and orchestrate communication between signing parties.
- Hardware & Trusted Execution Environments: Leverage hardware security modules (HSMs) and Trusted Execution Environments such as Intel SGX, including remote attestation capabilities.
- Cloud & Container Security: Ensure secure deployment practices within cloud environments and containerized infrastructure, preventing misconfigurations and enforcing zero‑trust principles.
- Expertise in secure software development with strong proficiency in C/C++, Go, or Rust
- Deep knowledge of applied cryptography and cryptographic protocol implementation
- Hands‑on experience with MPC frameworks or cryptographic custody solutions
- Strong threat modeling and vulnerability assessment skills
- Experience auditing or implementing key exchange and digital signature protocols
- Familiarity with OpenSSL or MPC‑specific cryptographic libraries
- Experience integrating with blockchain nodes and APIs
- Strong understanding of secure storage, networking protocols, and concurrency
- Experience with Trusted Execution Environments (e.g., Intel SGX) and HSMs
- Bachelor’s or Master’s degree in Computer Science, Cybersecurity, Cryptography, or related field
- Direct experience building digital asset custody platforms or digital wallets
- Institutional blockchain infrastructure experience
- Experience securing distributed systems in financial services
- Familiarity with zero‑trust architecture models
- Exposure to academic cryptography…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).