This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
At Charles Schwab, you're empowered to make an impact on your career. Here, innovative thought meets creative problem solving, helping us "challenge the status quo" and transform the finance industry together. We believe in the importance of in-office collaboration and fully intend for the selected candidate for this role to work on site in the specified location(s). We are hiring a Lead Engineer focusing on security and custody architecture to serve as the technical authority for Crypto Custody engineering, with deep ownership of key management, custody security architecture, and risk posture across Schwab's digital asset platforms. This is a hands-on, high-impact individual contributor role. The Lead Engineer sets technical direction, defines custody architecture, and owns critical design decisions across HSMs, MPC, key storage, policy enforcement, disaster recovery, and incident response. This role requires strong engineering judgment in high-risk, high-trust environments, and the ability to operate with autonomy while influencing teams, architects, security, and leadership.
Job Responsibility:
Design, implement, and evolve institutional-grade key management architectures, including HSMs, MPC, secure key generation, storage, rotation, signing, and recovery
Define trade-offs and architectural patterns across hot wallet, warm wallet, and cold storage models
Ensure cryptographic designs align with regulatory, security, and audit expectations
Partner with Cybersecurity and Risk to embed defense-in-depth and zero-trust principles
Lead the design of the Custody Policy Engine governing authorization, approvals, limits, segregation of duties, transaction controls, exception handling, policy versioning, auditability, enforceability
Translate business, legal, and risk requirements into technical controls
Serve as a trusted technical advisor on custody governance topics
Own custody-specific disaster recovery strategies including key recovery, quorum loss scenarios, and chain events
Author incident response and recovery runbooks
Partner with Operations, Security, and SRE
Lead post-incident technical analysis, root cause reviews, and long-term remediation strategies
Act as custody architecture authority ensuring consistency across wallets, blockchains, environments, and platforms
Identify architectural and operational risks early and propose mitigation strategies
Ensure custody designs scale across assets, chains, and future tokenized products
Influence enterprise standards
Leverage GenAI and agentic AI tools to accelerate architecture design, threat modeling, documentation, testing, and reviews
Set expectations for AI-assisted engineering rigor
Partner with engineering teams to raise architecture, code, and documentation quality
Requirements:
10+ years of software engineering experience, with deep specialization in security-sensitive or cryptographic systems
Strong hands-on experience with HSMs, MPC frameworks, and secure key management systems
Experience with Web3 Security tooling such as Slither, Mythril, Foundry Fuzzing
Experience with common cryptography implementation languages such as C, C++, Rust, Go
Experience with collaborating with security auditors, Ex: Trail of bits, halborn
Proven ability to design systems where failure has material risk implications
Strong grounding in distributed systems, secure architectures, and fault-tolerant design
Track record of acting as a technical authority without formal people management
Nice to have:
Experience with crypto custody, digital asset platforms, or blockchain infrastructure
Prior ownership of incident response, DR design, or security runbooks
Ability to articulate risk-based trade-offs clearly to technical and non-technical stakeholders
Systems thinker who connects technology, security, policy, and operations
Comfortable challenging assumptions and raising concerns early in high-stakes environments
Experience applying AI tools to complex engineering workflows
What we offer:
401(k) with company match and Employee stock purchase plan
Paid time for vacation, volunteering, and 28-day sabbatical after every 5 years of service for eligible positions