Taurus SA

Senior Product Security Engineer / Architect [Lausanne]

Taurus SA
Apply
2 months ago
Lausanne, SwitzerlandSenior

Responsibilities

  • Own product security for Taurus-PROTECT, Taurus-CAPITAL, Taurus-EXPLORER, Taurus-NETWORK, and applicable financial services products.
  • Contribute to security architecture for HSMs, confidential computing, MPC, and cryptographic systems.
  • Review application code, cryptographic workflows, smart contracts, HSM integrations, and enclave-based components.
  • Threat-model new features and review architectural designs before release.
  • Lead and review penetration tests, reproduce findings, and validate remediation plans.
  • Build and own automated security guardrails across CI/CD pipelines, software supply chains, Kubernetes environments, and deployment platforms.
  • Partner with product engineering teams to design and ship security fixes.
  • Review authorization models, privilege management, identity integrations, and operational access controls.
  • Support incident response, vulnerability management, security investigations, client audits, RFPs, security workshops, and regulatory discussions.
  • Translate regulatory and compliance requirements into practical technical controls and monitor security trends for product impact.

Requirements

  • Master’s or PhD in computer science, IT security engineering, or cryptography, or equivalent practical experience.
  • At least 7 years of experience in application security, product security, offensive security, or security engineering.
  • Background in security-critical environments such as financial services, payments, identity, custody, embedded systems, or regulated platforms.
  • Strong security code review experience in at least two of Go, C/C++, TypeScript, and Python.
  • Experience with threat modeling, secure design reviews, penetration testing, business logic flaws, authorization issues, cryptographic misuse, and complex attack paths.
  • Strong applied-cryptography foundation covering PKI, TLS, X.509, AES, RSA, ECDSA, EdDSA, key management, key ceremonies, secure key storage, and signing workflows.
  • Experience with HSM technologies and PKCS#11 environments.
  • Strong Kubernetes and container security experience, plus familiarity with cloud IAM, workload identity, secrets management, and policy-as-code.
  • Experience with one or more of Thales/Luna HSM, AWS CloudHSM, Azure Managed HSM, Intel SGX, AMD SEV-SNP, AWS Nitro Enclaves, and Azure Confidential Computing.
  • Fluent written and spoken English and the ability to explain complex security topics clearly to engineers, auditors, regulators, clients, and prospect CISOs.
  • Blockchain and smart contract security, MPC and threshold signature systems, fuzzing, secure software testing, compliance frameworks, public security research, CVEs, bug bounties, open-source security contributions, and customer due diligence experience are strong pluses.

Benefits

  • Opportunity to work at the intersection of digital assets and finance with an experienced team and world-renowned experts.
  • Fast-paced learning environment, entrepreneurial culture, team spirit, and significant growth opportunities.
  • State-of-the-art technology and IT infrastructure.
  • Hybrid remote work and flexible working hours.
  • Fun team events.
  • Target start date is Q1 2027; early applications are welcome, and applications through agencies are not considered.
Taurus SA

About Taurus SA

51-200 employees
Contact me