Demo

Head of Security Engineering (AWS/KMS)

Keyrock
Jersey, NJ Full Time
POSTED ON 4/19/2026
AVAILABLE BEFORE 6/13/2026
About Keyrock

Since our beginnings in 2017, we've grown to be a leading change-maker in the digital asset space, renowned for our partnerships and innovation.

Today, we rock with over 180 team members around the world. Our diverse team hails from 42 nationalities, with backgrounds ranging from DeFi natives to PhDs. Predominantly remote, we have hubs in London, Brussels, Singapore and Paris, and host regular online and offline hangouts to keep the crew tight.

We are trading on more than 80 exchanges, and working with a wide array of asset issuers. As a well-established market maker, our distinctive expertise led us to expand rapidly. Today, our services span market making, options trading, high-frequency trading, OTC, and DeFi trading desks.

But we’re more than a service provider. We’re an initiator. We're pioneers in adopting the Rust Development language for our algorithmic trading, and champions of its use in the industry. We support the growth of Web3 startups through our Accelerator Program. We upgrade ecosystems by injecting liquidity into promising DeFi, RWA, and NFT protocols. And we push the industry's progress with our research and governance initiatives.

At Keyrock, we're not just envisioning the future of digital assets. We're actively building it.

The role

As Leader of Security Engineering, you will set the technical direction and execution for Keyrock’s security engineering program—building secure-by-design cloud foundations, developer "paved roads," and cryptographic/key-management controls appropriate for a high-availability trading environment.

This is a hands-on leadership role. Deep knowledge of AWS and AWS Key Management Service (KMS)—including key policies, grants, cross-account patterns, and rotation—is essential.

What You’ll Do

Security engineering leadership

  • Lead and grow a high-performing security engineering team (cloud, platform, application security), setting roadmap, standards, and measurable outcomes.
  • Establish engineering patterns that balance speed and control (secure defaults, automation-first, self-service guardrails).

AWS cloud security architecture

  • Own cloud security architecture for AWS: landing zone patterns, multi-account strategy, network segmentation, identity and access design, logging/telemetry baselines, and infrastructure hardening.
  • Build preventative controls using infrastructure-as-code and policy-as-code; drive adoption across engineering teams.

Encryption and key management (KMS is core)

  • Own the enterprise encryption program in AWS, including KMS key policy design and governance (least privilege, separation of duties, break-glass, auditable admin/use roles).
  • Define safe grant usage patterns and operational best practices for AWS services and applications.
  • Own key lifecycle management: rotation strategy, aliasing/migration patterns, and recovery considerations.
  • Design cross-account and multi-account access patterns and controls aligned to Keyrock’s cloud operating model.

Secure SDLC and product security

  • Embed security into the SDLC: threat modeling, secure coding guidance, code scanning, dependency controls, build-time checks, and release gates.
  • Partner with Platform Engineering to harden runtime environments (containers, Linux, CI/CD runners, secrets management, service-to-service authentication).

Operational partnership (without owning SecOps)

  • Partner with Security Operations to ensure engineering-driven outcomes: high-signal detections, incident response tooling readiness, forensic logging, and secure configurations that reduce blast radius.

Required

What we’re looking for

  • 8 years in security engineering (cloud, platform, and/or product security), with 3 years leading teams or leading org-wide technical programs.
  • Expert AWS security experience in production environments (multi-account, high availability).
  • Deep AWS KMS expertise: key policies, grants, rotation, and cross-account usage patterns.
  • Strong working knowledge of IAM, identity design, and least-privilege access controls in cloud environments.
  • Proven ability to build security automation (infrastructure-as-code, CI/CD integration, policy enforcement, developer enablement).
  • Clear communication skills: can write standards/runbooks and influence senior engineers and executives.

Nice to have

  • Experience in trading, fintech, crypto, or other 24x7 and/or low-latency production environments.
  • Experience building paved-road platforms (golden pipelines, secure templates, internal developer platforms).
  • Familiarity with cloud security tooling ecosystems (CSPM/CIEM, vulnerability management, SAST/DAST, secrets tooling).

Why Keyrock

  • Work on security challenges unique to digital-asset liquidity and trading across venues.
  • Build durable security capabilities for a high-impact, high-availability business.

Salary.com Estimation for Head of Security Engineering (AWS/KMS) in Jersey, NJ
$96,720 to $119,937
If your compensation planning software is too rigid to deploy winning incentive strategies, it’s time to find an adaptable solution. Compensation Planning
Enhance your organization's compensation strategy with salary data sets that HR and team managers can use to pay your staff right. Surveys & Data Sets

What is the career path for a Head of Security Engineering (AWS/KMS)?

Sign up to receive alerts about other jobs on the Head of Security Engineering (AWS/KMS) career path by checking the boxes next to the positions that interest you.
Income Estimation: 
$99,793 - $130,112
Income Estimation: 
$125,027 - $157,872
Income Estimation: 
$87,093 - $107,335
Income Estimation: 
$111,725 - $147,313
Income Estimation: 
$112,673 - $137,290
Income Estimation: 
$140,233 - $181,029
Income Estimation: 
$161,209 - $233,553
Employees: Get a Salary Increase
View Core, Job Family, and Industry Job Skills and Competency Data for more than 15,000 Job Titles Skills Library

Job openings at Keyrock

  • Keyrock Jersey, NJ
  • About Keyrock Since our beginnings in 2017, we've grown to be a leading change-maker in the digital asset space, renowned for our partnerships and innovati... more
  • 17 Days Ago

  • Keyrock York, NY
  • About Keyrock Since our beginnings in 2017, we've grown to be a leading change-maker in the digital asset space, renowned for our partnerships and innovati... more
  • 2 Days Ago

  • Keyrock York, NY
  • About Keyrock Since our beginnings in 2017, we've grown to be a leading change-maker in the digital asset space, renowned for our partnerships and innovati... more
  • 2 Days Ago

  • Keyrock Jersey, NJ
  • About Keyrock Since our beginnings in 2017, we've grown to be a leading change-maker in the digital asset space, renowned for our partnerships and innovati... more
  • 4 Days Ago


Not the job you're looking for? Here are some other Head of Security Engineering (AWS/KMS) jobs in the Jersey, NJ area that may be a better fit.

  • Harmonic Security San Francisco, CA
  • About Harmonic Security Harmonic Security lets teams adopt AI tools safely by protecting sensitive data in real time with minimal effort. It gives enterpri... more
  • 7 Days Ago

  • Hammer Head Security Fremont, CA
  • ABOUT US: It's not just about what WE look for in an employee, it's about what YOU look for in an employer.Hammer Head Security is a family owned and milit... more
  • 1 Month Ago

AI Assistant is available now!

Feel free to start your new journey!