Project Eleven Logo

Project Eleven

Senior Security Engineer

Posted Yesterday
Be an Early Applicant
Remote
Hiring Remotely in United Kingdom
Senior level
Remote
Hiring Remotely in United Kingdom
Senior level
Lead security engineering for an institutional product: threat modeling, secure architecture, appsec, AWS hardening, key management (HSMs/TEEs), supply-chain and reproducible builds, incident response, and compliance technical controls. Hands-on coding and infrastructure work alongside engineering.
The summary above was generated by AI
About Project Eleven

Project Eleven is an applied lab of builders and technologists working at the intersection of quantum computing and cryptography. We build impactful solutions that push the digital-asset ecosystem to a more secure future. Our focus is post-quantum migration: upgrading wallets, identity, and settlement rails to quantum-safe primitives without breaking UX, composability, and developer workflows.

Our mission is to future-proof digital assets and preserve self-sovereignty in a post-quantum world. We do that by building the canonical tooling and products teams can adopt: crypto-agile infrastructure, reference implementations, and integrations that fit real constraints like latency, cost, compatibility, key rotation, and recovery.

We work with leading ecosystems to make this migration real through products we build, audits, testnets, and cutting edge research. The vision we are have is clear: a proven upgrade path, production-ready tooling and users retaining control of their assets and identity, before CRQC exists.

The role

We're hiring a Senior Security Engineer to own the security engineering of our institutional product and platform. This is a hands-on, build-it-yourself role: you'll threat model our systems, design and implement secure architecture, harden our AWS infrastructure, own security of key management (including HSMs and TEEs), secure our supply chain and build pipeline, and run incident response. You'll work directly in our codebase and infrastructure alongside engineering with security as a key focus.

This role is a full-time, fully remote position in Europe (GMT to GMT+2).

What you'll be responsible for
  • Threat modelling & secure architecture: lead threat modelling for new and existing systems, and shape the architecture of our institutional product so security is designed in, not bolted on

  • Application security: build out our AppSec program: secure code review, secure SDLC, dependency and vulnerability scanning, security testing in CI

  • Infrastructure hardening & AWS security: harden our cloud infrastructure and deployment pipeline; own AWS security posture (IAM, network segmentation, secrets, logging/detection)

  • Key management, HSMs & TEEs: design, develop, and operate our key management architecture, including HSM-backed signing and TEE-based isolation for sensitive operations

  • Reproducible builds & supply chain security: implement reproducible/verifiable builds and harden our software supply chain (dependency provenance, build integrity, artifact signing)

  • Security reviews: review designs, code, and cryptographic protocols/integrations across our backend systems, partnering closely with engineering rather than gating them

  • Incident response: build and run our incident response capability: runbooks, on-call rotation, postmortem culture

  • Compliance support: collaborate with the team driving our compliance program (SOC 2 Type II as the first milestone), owning the technical controls and evidence without owning the program itself

What you bring
  • 5+ years in security engineering with hands-on ownership of building and securing production systems

  • Strong software engineering ability. You can read, write, and review production code and infrastructure-as-code, not just point out issues in it

  • Strong applied cryptography knowledge: key management, signing protocols, secure key handling at rest and in use

  • Hands-on experience hardening cloud infrastructure (AWS) and modern deployment platforms

  • Real threat modelling experience and the ability to make pragmatic risk tradeoffs in a fast-moving startup environment

  • Experience with secure architecture and design review for distributed or backend systems

  • Strong English communication, including the ability to explain security engineering clearly to engineers, customers, and auditors

What we'd love to see
  • Direct experience with HSMs, TEEs (SGX/SEV/TrustZone/Nitro), and/or MPC/threshold signing in production

  • Experience implementing reproducible builds or software supply chain security (SLSA, sigstore, artifact provenance)

  • Background in institutional digital-asset infrastructure: custody platforms, exchanges, HSM-backed systems, or regulated financial infrastructure

  • Familiarity with post-quantum cryptography and the operational implications of migrating cryptographic primitives

  • Experience running incident response for a security-critical product

  • Prior experience as the first security engineer at a startup, or building a security function from scratch

  • Offensive security background (red team, pentesting, vulnerability research) as a complement to defensive work

  • Open-source contributions to security tooling, cryptography, or related infrastructure

  • Exposure to SOC 2, ISO 27001, or equivalent compliance frameworks (nice to have, not the core of the role)

Equal Opportunity

We are committed to equal employment opportunity and believe that diverse teams build better products. All qualified applicants will receive consideration without regard to any protected characteristic under applicable law.

Similar Jobs

Yesterday
In-Office or Remote
United Kingdom
Senior level
Senior level
Blockchain
Lead and own the information security program and security engineering at NEAR Foundation. Drive SOC 2 Type 2 and ISO 27001 readiness, run logging/monitoring/incident response, manage vulnerability and third-party risk, harden identity/access/endpoint stacks, automate security and compliance across SaaS, and advise on tooling and cloud security (AWS/GCP).
Top Skills: AWSBashEdrEntraGCPGoGoogle WorkspaceIamIso 27001LoggingMdmMfaMonitoringOktaPythonSIEMSoc IiSso
Yesterday
In-Office or Remote
United Kingdom
Senior level
Senior level
Big Data • Healthtech • Software • Biotech
Lead security engineering across web apps, APIs, cloud (AWS/OCI), Kubernetes, and on-prem systems. Build CI/CD security, secure genomic and PHI/PII pipelines (HIPAA), run monitoring and incident response, prepare for HIPAA/SOC2/ISO27001 audits, perform pentesting/vulnerability discovery, improve logging/SIEM, and drive remediation with engineering and DevOps while raising company-wide security awareness.
Top Skills: AWSBurp SuiteCi/CdCloudflareCloudtrailCodeqlContainersDockerFalcoGitGitGoogle WorkspaceIamKubernetesLog AggregationMetasploitNetwork PoliciesOciOwasp ZapRbacSecrets ManagementSemgrepSIEMTerraform
Yesterday
In-Office or Remote
UK
Senior level
Senior level
Information Technology
Design and implement secure cloud-based solutions and DevSecOps practices. Automate security tooling in CI pipelines, perform threat modelling and vulnerability management, support penetration testing, review security outputs, convert findings into actionable work, verify secure architectures, and coach junior team members.
Top Skills: .NetAnsibleArm TemplatesAWSAzureBashCi (Continuous Integration)Cis BenchmarksContainer SecurityCryptographyDastDevsecopsDynamic AnalysisGitJavaJavaScriptPenetration TestingPowershellPythonSastSecret ScanningStatic AnalysisTerraformThreat ModellingVulnerability ManagementWeb Application Security

What you need to know about the Belfast Tech Scene

If asked to name the birthplace of the RMS Titanic, you might not say Belfast. Similarly, if asked to name Europe's leading destination for foreign direct investment in new software development, Belfast might not come to mind. Yet, both are true. The city has emerged as a tech powerhouse, recently ranked among the best in the U.K. for tech careers — especially for software developers. It also leads the U.K. with the highest percentage of software development jobs advertised.

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account