
Senior Product Security Engineer
Blockchain.com12 days ago
London, United KingdomSenior
Responsibilities
- Own security gates and integrate security into the design and release processes for Consumer, OTC, and MRE product lines.
- Operate and improve the secure software development lifecycle, including SAST, SCA, DAST, SARIF ingestion, pull-request standards, CI/CD security automation, and vulnerability triage.
- Research, architect, and safely integrate AI utilities and LLM agents into the secure development lifecycle.
- Lead STRIDE and attack-tree threat modeling and approve security architecture for authentication, payment, custody, reconciliation, and other sensitive flows.
- Create and maintain application security standards, reference architectures, security policies, and secure coding baselines.
- Lead technical triage and remediation strategy for the Bug Bounty program.
- Conduct manual and automated security code reviews, especially for Java and Kotlin backend pull requests, and mentor engineers on secure coding.
- Build security debt reporting, negotiate remediation timelines, and align risk-based remediation with product and engineering roadmaps.
- Define application runtime signals and work with SecOps on logs, alerts, and detection telemetry.
- Build and maintain test harnesses, fuzzing and property tests, and CI checks for business-critical flows.
- Provide product security expertise for incident response, forensic runbooks, payment and settlement incident reproduction, containment, and remediation.
- Own product security metrics and communicate risk reports to security and engineering leadership.
- Coach junior product security engineers and security champions and support hiring and capability planning.
Requirements
- At least 4 years of total security engineering experience, including at least 3 years focused on application or product security, or equivalent experience.
- Experience with web, mobile, cloud, and infrastructure penetration testing and red teaming, including phishing.
- Experience shipping security automation with CodeQL/GHAS, Snyk, or similar tools, with strong familiarity with SARIF and ASPM workflows.
- Expert ability to audit and recommend fixes in Kotlin/Java, TypeScript/JavaScript, and Python, plus familiarity with Kubernetes-based deployments.
- Strong threat modeling and architecture review experience for high-stakes financial flows involving authentication, authorization, cryptography, and payments.
- Experience building CI checks, test harnesses, and lightweight fuzzing or property tests.
- Ability to negotiate security remediation with engineering directors and product owners while balancing security and delivery velocity.
- Fintech, trading, OTC product security, custody, or signing-pattern experience is preferred.
- Experience designing or deploying AI-assisted security tooling, LLM-based patch generation, or vulnerability detection agents is preferred.
- Experience with GRC frameworks, developer-facing security policies, policy-as-code gateway integrations, CVEs, security research, or security-tooling contributions is preferred.
- OSCP, OSWE, CISSP, or equivalent credentials are preferred.
- Experience with on-chain/off-chain integration, payment reconciliation, smart contract security, DefectDojo, Dependabot orchestration, or GRC/gateway integrations is preferred.
Benefits
- Full-time employment with salary based on experience and meaningful equity.
- London office role with mandatory in-office attendance four days per week.
- Work from anywhere in the world for up to 20 days per year.
- ClassPass.
- Unlimited vacation policy.
- Apple equipment.
- Flexible work culture and career-growth opportunities at a global technology company.