28 days ago
Base Salary
$142k - $213k/yr
Responsibilities
- Design, develop, and maintain Java security-critical backend services, cryptographic libraries, key management APIs, signing workflows, and secure transaction pipelines.
- Own HSM vendor evaluation, API integration, key generation, rotation, operational lifecycle, and policy enforcement.
- Architect and implement MPC protocols, threshold signature schemes, and distributed key management for institutional wallet signing.
- Apply encryption, digital signatures, hashing, key derivation, PKI, certificate management, zero-trust, secrets management, mutual TLS, and secure enclave patterns.
- Conduct threat modeling, security design reviews, cryptographic risk assessments, security-focused code reviews, vulnerability triage, and incident escalation.
- Embed SAST, DAST, dependency scanning, and secrets scanning into CI/CD pipelines and collaborate with cybersecurity, risk, architecture, vendors, and standards bodies.
Requirements
- 7–10 years of software engineering experience with significant application security, cryptography, or secure systems design experience.
- Production-level proficiency building enterprise-grade backend services in Java.
- Hands-on experience integrating HSMs through PKCS#11, JCE/JCA, or vendor-specific APIs.
- Practical understanding of MPC protocols, threshold signature schemes, or distributed key management architectures.
- Deep knowledge of applied cryptography, including encryption, digital signatures, key exchange, PKI/X.509, certificate management, and secure hashing.
- Experience with secure design patterns, threat-modeling frameworks such as STRIDE or PASTA, and security design reviews.
- Understanding of SAST, DAST, dependency scanning, secrets scanning, distributed systems, microservices, OAuth 2.0, JWT, and secure inter-service communication.
- Bachelor's degree in Computer Science, Computer Engineering, Cybersecurity, or a related technical discipline.
- Preferred qualifications include digital asset custody or blockchain infrastructure experience, smart contract security knowledge, familiarity with NIST SP 800-57, FIPS 140-2/3, PCI-DSS, MPC-CMP, tss-lib, penetration testing, red-team exercises, or certifications such as CISSP, CSSP, CEH, or OSCP.
- A master's or PhD in Cryptography, Information Security, or Computer Science is advantageous.
Benefits
- Primary location is New York, New York, United States, with a full-time work schedule.
- Medical, dental, and vision coverage; 401(k); life, accident, and disability insurance; and wellness programs.
- Paid vacation, sick leave, and holidays.
- Eligible employees may receive discretionary and formulaic incentive and retention awards.
Tech Stack
About Citi
Citi's mission is to serve as a trusted partner to our clients by responsibly providing financial services that enable growth and economic progress. Our core activities are safeguarding assets, lending money, making payments and accessing the capital markets on behalf of our clients. We have over 200 years of experience helping our clients meet the world's toughest challenges and embrace its greatest opportunities. We are Citi, the global bank – an institution connecting millions of people across hundreds of countries and cities. For information on Citi’s commitment to privacy, visit on.citi/privacy.
