Security APAC Hybrid / Remote
Crypto Asset Custody & Security Engineer (DORAAligned)
Help reinvent global finance with secure, resilient digital asset infrastructure. At Reap, you'll be the security backbone behind our custody operations-shaping how private keys are protected, how wallets operate at scale, and how our ICT controls meet DORA with confidence. You'll blend handson security engineering with governance craft, raising the bar on operational resilience across our products and platforms.
Security at Reap
Reap builds financial connectivity for a multirail world-traditional finance, stablecoins, and realtime payments. Security is foundational to that mission. We're looking for a pragmatic engineer who can turn regulation into robust systems, and complex threats into clear controls. You'll partner with Engineering, Risk, and Operations to keep value moving safely, globally, and 24/7.
What you'll doCustody security engineering
- Operate and harden custody environments across hot, warm, and cold storage.
- Own key lifecycle controls: secure creation, rotation, backup, recovery, and destruction, aligned to DORA secure ICT operations (Art. 9).
- Support and evolve multisig flows, HSMs, and offline signing patterns.
- Monitor wallet transaction flows and signals for anomalies, abuse, and drift.
- Establish secure configuration baselines, hardening guides, and change controls for custody systems.
Access, SSO, and lifecycle
- Enforce strict segregation of duties and RBAC in line with DORA principles (Art. 6).
- Administer SSO integrations and joinermoverleaver lifecycle for custody participants.
- Drive MFA everywhere it matters, leastprivilege defaults, and periodic access reviews.
ICT governance and DORA compliance
- Coauthor policies, standards, and procedures for custody security and change management (Art. 5).
- Keep control inventories, evidence, and auditready documentation current.
- Run or support risk assessments for keys, wallets, and asset movement (Art. 8).
- Contribute to oversight of thirdparty custody providers and critical vendors (Art. 30).
Incident response and resilience
- Tune monitoring for custody alerts: wallet anomalies, access violations, and key events.
- Triage, escalate, and document incidents in accordance with DORA (Art. 17-19).
- Maintain DR procedures for custody systems and key backups (Art. 28) with tested RTO/RPO.
- Design and run resilience scenarios: key loss, wallet malfunction, chain instability.
Crossfunctional impact
- Partner with Product, Platform, Data, and Compliance to land controls that scale.
- Turn regulatory expectations into clear, testable engineering outcomes.
- Communicate risk and tradeoffs crisply to technical and nontechnical stakeholders.
About youEssential
- Handson experience in crypto custody, blockchain operations, or digital asset security.
- Deep understanding of custody risks: key compromise, misuse of signing authority, replay and chain instability.
- Practical knowledge of SSO, IAM/RBAC, MFA enforcement, and SoD in highsensitivity environments.
- Familiar with ICT governance and risk management under DORA (Art. 5-9) and operational resilience and incident obligations (Art. 17-20, 28-30).
- Strong documentation discipline and an evidencefirst mindset.
Nice to have
- Experience in a regulated financial or digital asset institution.
- Exposure to institutional custody platforms and enterprise KMS/HSMs.
- Audit readiness and control testing background, e.g., SOC 2 or ISO 27001.
- Relevant security or blockchain certifications or equivalent demonstrated expertise.
How you work
- Systems thinker with a builder's bias-able to ship secure defaults and iterate.
- Clear communicator who can translate regulation into engineering patterns.
- High integrity and reliability in sensitive custody domains.
What you'll work with
- Multisig wallets, HSMs, hardware wallets, and offline signing setups.
- Secure key ceremonies, tamperevident backup, and recovery playbooks.
- Monitoring and analytics across wallet activity, access, and infra posture.
- Change management, evidence collection, and control automation.
What this role offers
- Direct impact on DORAaligned custody controls and operational resilience.
- A frontrow seat at the intersection of security engineering and governance.
- Influence over security architecture and custody operating models.
- Growth paths into governance, architecture, or custody security leadership.
Benefits you'll enjoy
- A vibrant, inclusive work culture.
- Annual leave to relax and recharge, plus public holidays.
- Health insurance budget.
- Be part of a fastgrowing global team.
- Flexible remote work options.
- Home office equipment budget.
- Your own Corporate Reap Card-no more outofpocket spending.
About Reap
Reap is a leading global payment technology provider that enables financial connectivity and access for businesses worldwide. By merging traditional finance with digital assets, bridging disparate economies, and connecting key financial players, we are transforming the financial landscape into a more interconnected and interoperable space for efficient money movement.
With stablecoinenabled corporate cards, payout solutions, and expense management tools, we streamline financial operations and empower businesses to scale. Our APIs enable businesses to embed finance into their own products and services, from issuing Visa cards to facilitating crossborder payments.
Reap is supported by a strong network of investors, including Acorn Pacific Ventures, Arcadia Funds, HashKey Capital, Hustle Fund, Fresco Capital, Abacus Ventures, and Payment Asia.
Founded in 2018
Coworkers 300+