
Senior Product Security Engineer
Blockchain.com12 days ago
Paris, FranceSenior
Responsibilities
- Own and improve the secure development lifecycle, including SAST, SCA, DAST, SARIF ingestion, pull request standards, CI/CD security automation, and vulnerability triage.
- Lead threat modeling and architecture reviews for authentication, payment, custody, reconciliation, and other sensitive financial flows.
- Conduct manual and automated security code reviews of Java and Kotlin backend pull requests and provide remediation guidance.
- Build and maintain product-level test harnesses, fuzzing and property tests, and CI checks for business-critical flows.
- Oversee bug bounty triage and remediation strategy and convert external findings into architectural hardening initiatives.
- Define application security standards, reference architectures, secure coding baselines, security metrics, and risk reports.
- Research and integrate AI and LLM utilities into the secure development lifecycle and security automation.
- Define application runtime security signals and work with SecOps on logging, alerting, and incident response support.
- Coach junior product security engineers and security champions and assist with hiring and capability planning.
Requirements
- At least 4 years of security engineering experience, including at least 3 years focused on application or product security, or equivalent.
- Experience with web, mobile, cloud, and infrastructure penetration testing and red teaming.
- Proven experience shipping security automation using CodeQL/GHAS, Snyk, or similar tools, with strong familiarity with SARIF and ASPM workflows.
- Expertise auditing and proposing fixes in Kotlin/Java, TypeScript/JavaScript, and Python, plus familiarity with Kubernetes deployments.
- Strong threat modeling and security architecture experience for authentication, authorization, cryptography, payments, and other high-stakes financial flows.
- Experience building CI checks, test harnesses, and lightweight fuzzing or property tests.
- Ability to negotiate risk-based remediation timelines with engineering and product leadership.
- Fintech, trading, OTC, custody, signing, payment reconciliation, smart contract security, or on-chain/off-chain integration experience is preferred.
- Experience with AI-assisted security tooling, LLM-based patch generation, vulnerability detection agents, GRC frameworks, policy-as-code, DefectDojo, or Dependabot orchestration is preferred.
- Security research, CVEs, open-source security tooling contributions, and credentials such as OSCP, OSWE, or CISSP are preferred.
Benefits
- Unlimited vacation policy.
- Unlimited books policy and access to a company library.
- Apple equipment.
- Full-time employment with meaningful equity; no base salary amount is stated.
- Role based in the Paris office with mandatory in-office presence four days per week.
- Work from anywhere in the world for up to 20 days per year.