Taurus SA

Senior Product Security Engineer / Architect [Lausanne]

Taurus SA  •  Lausanne, CH (Hybrid)  •  2 hours ago
Apply
AI can make mistakes so check important info. Chat history is never stored.

Job Description

Do you want to be part of a new entrepreneurial adventure and help build the next global FinTech, then we might just have the job for you.

Taurus is a FINMA-regulated securities firm, headquartered in Geneva, Switzerland, and providing digital asset trading and financial services to its clients. It is also a world-leading provider of digital asset infrastructure solutions to banks, corporations and private companies. Using blockchain technology, Taurus platform covers cryptocurrencies, tokenized securities, tokenized assets (such as NFTs), digital currencies, and stable coins.

We are looking for ambitious and driven individuals to support our fast global growth.

Tasks

A deeply hands-on, individual-contributor role where you'll raise the security bar of the product itself. You're the security partner engineers want in the room: someone who can open a diff, understand the attack surface, build the automation that enforces the fix, and ship it the same day. Much of that surface is cryptographic (keys, signing, HSMs, and the trust boundary around them), so that's where you'll have the most impact.

Responsibilities

  • Own product security for all applicable digital asset products: Taurus-PROTECT, Taurus-CAPITAL, Taurus-EXPLORER and Taurus-NETWORK. Contribute to financial services product security.

  • Contribute to security architecture for HSMs, confidential computing, MPC, and cryptographic systems

  • Perform security reviews of application code, cryptographic workflows, smart contracts, HSM integrations, and enclave-based components

  • Model threats of new features and review architectural designs before release

  • Lead and review penetration tests, reproduce findings, and validate remediation plans

  • Build and own the automation that enforces security guardrails — across CI/CD pipelines, software supply chains, Kubernetes environments, and deployment platforms

  • Pair with product engineering teams to design and ship fixes, not just file findings

  • Review authorization models, privilege management, identity integrations, and operational access controls

  • Support incident response, vulnerability management, and security investigations

  • Support client audits, RFPs, security workshops, and regulatory discussions

  • Translate regulatory and compliance requirements into practical technical controls

  • Monitor security news and trends; identify potential impact on products and ensure timely application of corrective actions

Requirements

Experience

  • Master or PhD in computer sciences, IT security engineering or cryptography
  • 7+ years in application security, product security, offensive security, or security engineering
  • Background in security-critical environments — financial services, payments, identity, custody, embedded systems, or regulated platforms
  • Fluent written and spoken English

Key Requirements

Application & product security:

  • Strong security code review experience in at least two of: Go, C/C++, TypeScript, Python
  • Threat modeling, secure design reviews, and penetration testing
  • Ability to identify business logic flaws, authorization issues, cryptographic misuse, and complex attack paths

Cryptography & key management:

  • Strong applied-cryptography foundation: PKI, TLS, X.509; AES, RSA, ECDSA, EdDSA; key management and key ceremonies; secure key storage and signing workflows
  • Experience with HSM technologies and PKCS#11 environments

Infrastructure & cloud security:

  • Strong Kubernetes and container security experience
  • Familiarity with cloud IAM, workload identity, secrets management, and policy-as-code
  • A builder’s mindset — you implement security controls, not only review them

Secure hardware & confidential computing:

  • Experience with one or more of: Thales / Luna HSM, AWS CloudHSM, Azure Managed HSM, Intel SGX, AMD SEV-SNP, AWS Nitro Enclaves, Azure Confidential Computing

Client & communication skills:

  • Comfortable engaging security teams, auditors, regulators, enterprise clients, and prospect CISOs
  • Able to explain complex security topics clearly and pragmatically

A strong plus

  • Blockchain and smart contract security
  • MPC and threshold signature systems
  • Fuzzing and secure software testing
  • Security compliance and regulatory frameworks (FINMA, DORA, MiCA, ISO 27001, SOC 2, FIPS 140-3)
  • Public security research, CVEs, bug bounty experience, or open-source security contributions
  • Experience supporting RFPs, security questionnaires, and customer due diligence
  • Degree in Computer Science, Security, or equivalent practical experience

Benefits

  • An opportunity to work at the intersection of digital assets and finance
  • A skilled and experienced team, including world-renowned experts
  • A fast-paced learning environment, entrepreneurial spirit and team spirit
  • A great moment to join as the company grows and expands
  • State-of-the-art technology and IT infrastructure
  • Hybrid remote work and flexible working hours
  • Fun team events

As the company evolves in a dynamic and innovative environment, its DNA is based on merit. As such, there will be significant growth opportunities for candidates with an open and deliver-oriented mindset. We are an equal opportunity employer.

Note

Please note: we're opening this position with a target start date of Q1 2027, so early applications are very welcome.

We will not consider applications via agencies.

taurushq[.]com

Taurus SA

About Taurus SA

Taurus is the #1 independent player and a global-leader in enterprise-grade digital asset infrastructure with roots in Switzerland.

1️⃣ Market leadership: Taurus has >50% market share in its home market in Switzerland, the most competitive in the world. Globally, Taurus is entrusted by the full spectrum of financial institutions - systemic banks, investment banks, crypto banks, private banks, universal banks - financial market infrastructure providers and core banking systems. In production.

2️⃣ Product leadership: Taurus has developed the most advanced and most complete digital asset platform in the industry which goes “way beyond” crypto-currency custody. No one else besides Taurus, is able to empower financial institutions to issue/onboard, manage, and book “any type” of tokenised securities and digital currencies. On any standard. With the same platform.

3️⃣ Technology leadership: Taurus masters the full technology stack and 70% of our staff is made of engineers. We believe this is a core capability and a strong hedge against tech disruptions in an industry that is young and moving fast. The products our clients use are 100% built by Taurus and are at the forefront of what exists in the market with several patent-pending inventions. Anticipating protocol upgrades, adding "complex" new protocols, new signature curves or strengthening HSM-security, operating nodes+indexing is totally controlled by our engineering teams. This makes us future-proof, execute fast and a long-term, partner to our clients.

Taurus is growing fast and always looking for talents. Contact us at https://www.taurusgroup.ch

For other business enquiries: contact@taurusgroup.ch

Industry
Finance & Insurance
Company Size
51-200 employees
Headquarters
Geneva, CH
Year Founded
2018
Social Media