Blockchain - Lead Security Engineer

JPMorgan Chase JPMorgan Chase · Banking · Seattle, WA +1 · Corporate Sector

Lead Security Engineer role focused on designing, building, and operating an enterprise-grade Digital Asset Custody and Wallet Orchestration Platform. This involves integrating with wallet infra, implementing secure key management (MPC), building programmable transaction policies, supporting multi-chain capabilities, managing the transaction lifecycle, designing event-driven architectures, building secure APIs, integrating with compliance systems, and ensuring robust observability and scalability on AWS. Requires strong software engineering, blockchain, and security expertise.

What you'd actually do

  1. Design, architect, and develop a production-grade digital asset custody & wallet orchestration platform by integrating with wallet infra platforms leveraging their APIs and SDKs for wallet provisioning, key management, and transaction orchestration
  2. Implement secure key management workflows using Multi-Party Computation (MPC) and distributed key generation, ensuring no single point of failure
  3. Build and configure programmable transaction policy engines, including multi-approval workflows, spending thresholds, velocity limits and role-based access controls
  4. Develop multi-chain wallet capabilities supporting blockchain networks such as Ethereum, Bitcoin, Solana, and Polygon through unified API abstractions
  5. Manage the full blockchain transaction lifecycle, including transaction construction, fee estimation, payload signing, broadcast, confirmation tracking, and idempotent retry logic for failed or stuck transactions

Skills

Required

  • Java/J2EE
  • Python
  • Spring Boot
  • Flask
  • FastAPI
  • blockchain fundamentals
  • transaction models
  • consensus mechanisms
  • smart contract interaction
  • EVM-based
  • non-EVM
  • gas and fee management
  • block finality
  • cryptographic primitives
  • protocols
  • digital asset custody
  • Multi-Party Computation (MPC)
  • threshold signatures (TSS)
  • distributed key generation (DKG)
  • elliptic curve cryptography
  • ECDSA
  • EdDSA
  • HD wallet derivation paths
  • BIP-32
  • BIP-44
  • policy engines
  • rule-based authorization frameworks
  • financial transaction workflows
  • multi-signature schemes
  • approval chains
  • configurable spending controls
  • AWS
  • EC2
  • EKS
  • Lambda
  • S3
  • RDS
  • IAM
  • SQS
  • SNS
  • API Gateway
  • KMS
  • Terraform
  • CloudFormation
  • infrastructure-as-code
  • Docker
  • Kubernetes
  • deployment pipelines
  • auto-scaling configurations
  • RESTful APIs
  • OAuth 2.0
  • JWT
  • TLS/mTLS
  • certificate management
  • API security best practices
  • event-driven architectures
  • webhook processing
  • asynchronous messaging patterns
  • relational databases
  • Oracle
  • PostgreSQL
  • NoSQL databases
  • DynamoDB
  • MongoDB
  • Redis
  • schema design
  • query optimization
  • data consistency patterns
  • financial systems
  • observability
  • monitoring tools
  • Datadog
  • Dynatrace
  • Splunk
  • Grafana
  • Prometheus
  • distributed tracing
  • log aggregation
  • performance monitoring
  • agile development methodologies
  • CI/CD pipelines
  • Jenkins
  • GitHub Actions
  • Spinnaker
  • DevOps practices

Nice to have

  • AI-assisted development tools
  • GitHub Copilot
  • Claude Code

What the JD emphasized

  • enterprise-grade Digital Asset Custody and Wallet Orchestration Platform
  • institutional blockchain infrastructure
  • secure, scalable, and compliant wallet services
  • distributed systems engineering, cryptographic security, and financial services technology
  • secure key management
  • programmable transaction policies
  • seamless multi-chain wallet capabilities
  • hands-on engineering role
  • blockchain protocols
  • enterprise security practices
  • production-grade digital asset custody & wallet orchestration platform
  • secure key management workflows
  • programmable transaction policy engines
  • multi-chain wallet capabilities
  • full blockchain transaction lifecycle
  • secure RESTful APIs and microservices
  • compliance and risk systems
  • robust observability
  • high availability, disaster recovery, and horizontal scalability
  • regulatory and business requirements
  • 7+ years of software development experience
  • at least 2 years working with blockchain technologies or digital asset platforms
  • Strong proficiency in Java/J2EE and/or Python
  • hands-on experience building production microservices
  • Solid understanding of blockchain fundamentals
  • Working knowledge of cryptographic primitives and protocols relevant to digital asset custody
  • Experience designing and implementing policy engines or rule-based authorization frameworks for financial transaction workflows
  • Proficiency with cloud infrastructure on AWS
  • Strong experience with containerization and orchestration using Docker and Kubernetes
  • Experience designing and consuming RESTful APIs
  • Familiarity with event-driven architectures
  • Experience with relational (Oracle, PostgreSQL) and NoSQL (DynamoDB, MongoDB, Redis) databases
  • Proficiency with observability and monitoring tools
  • Solid understanding of agile development methodologies, CI/CD pipelines
  • Experience building or operating digital asset custody solutions in a regulated financial institution