# Senior Product Security Engineer

[Blockchain](https://gurify.com/jobs?q=Blockchain) · London · Posted 2 months ago

Senior

[Security](https://gurify.com/jobs/security)

[Apply on the original posting → (opens in a new tab)](https://job-boards.greenhouse.io/blockchain/jobs/8026964)

## Job description

Blockchain is connecting the world to the future of finance. As the most trusted and fastest-growing global crypto company, it helps millions of people worldwide safely access cryptocurrency. Since its inception in 2011, Blockchain has earned the trust of over 90 million wallet holders and more than 40 million verified users, facilitating over $1 trillion in crypto transactions.

You will operate the Product Security programe for Blockchain.com’s internally-developed products across Consumer, OTC and MRE lines. This is a senior, hands-on role: you’ll design and run the secure development lifecycle, lead threat modeling and architecture review, own the security debt lifecycle for product engineering teams, and architect the automated pipelines that protect billions in transaction volume. You will embed with product and engineering teams, convert technical findings into business-prioritized remediation, and lift developer capabilities so security is delivered by code and process.

### WHAT YOU WILL DO

- Strategic Security Partnership: Act as a senior security engineer for the different product lines like Consumer, OTC. You will own the security gates for major feature releases and ensure security is integrated from the design phase.

- Secure SDLC Operator: Operate and improve the secure development lifecycle. This includes orchestrating SAST/SCA/DAST, streamlining SARIF ingestion, PR review standards, CI/CD security automation, and vulnerability triage workflows.

- AI-Driven SDLC Innovation: Research, architect, and safely embed cutting-edge AI utilities and Large Language Model (LLM) agents directly into our secure development lifecycle.

- Threat Modelling & Architecture Reviews: Lead STRIDE/attack-tree threat models for sensitive flows including authentication, payment, custody, reconciliation and sign off on security architecture for critical designs.

- Product Security Governance & Standards: Translate technical risks and regulatory demands into clear security policies. You will own the creation and upkeep of our Application Security Standards, reference architectures, and compliance-driven secure coding baselines.

- Bug Bounty Leadership: Oversee the technical triage and remediation strategy for our Bug Bounty program. You will turn external researcher findings into internal architectural hardening projects.

- Release Reviews: Perform deep-dive manual code reviews of security-sensitive Pull Requests, mentor engineers on secure coding patterns, and provide pragmatic remediation guidance.

- Advanced Code Auditing: Conduct deep-dive manual and automated code reviews on highly sensitive Java and Kotlin backend Pull Requests.

- Security Debt & Remediation Negotiation: Produce data-driven Security Debt packs and negotiate remediation into engineering roadmaps. You will negotiate remediation timelines with Product Owners and Engineering leadership, backed by risk-based data.

- Detection & Telemetry Integration: Define application runtime signals (business-logic anomalies, auth anomalies, reconciliation mismatches) and work with SecOps to instrument logs and alerts.

- Testing & Automation: Build and maintain product-level test harnesses, fuzzing/property tests and CI checks to prevent regressions for business-critical flows.

- Incident Response Support: Provide product-level Incident Response expertise like test forensic runbooks, support reproduction of payment/settlement incidents, and advise on containment/remediation whenever needed.

- Metrics & Risk Visibility: Define and own the Product Security metrics (e.g., MTTR for critical vulnerabilities, security debt burn-down, and defect density). You will translate these KPIs into high-level risk reports for the Head of Security and Engineering leadership to drive data-backed resourcing decisions.

- People & Process: Coach junior product security engineers and security champions. You will assist the Product Security Lead to define hiring standards and capability plans.

### WHAT YOU WILL NEED

### Must-Haves

- 4+ years total security engineering experience with at least 3+ years focused specially in application/product security or equivalent.

- Experience with Web, Mobile, Cloud, Infrastructure Pentests and Red Teaming (e.g., phishing)

- Proven track record of shipping security automation using CodeQL/GHAS, Snyk, or similar. You should be intimately familiar with the SARIF ecosystem and ASPM workflows.

- Expert-level ability to audit and propose fixes in Kotlin/Java, TypeScript/JS, Python, and familiarity with containerised deployments (Kubernetes).

- Strong threat modeling experience and pragmatic architecture guidance for high-stakes financial flows (AuthN/AuthZ, Cryptography, Payments).

- Experience building CI checks, test harnesses and lightweight fuzzing/property tests.

- Excellent stakeholder skills — able to negotiate remediation with Engineering Directors and Product owners, balancing security requirements with business velocity.

### Nice-to-haves

- Prior fintech/Trading/OTC product security experience or familiarity with custody/signing patterns.

- Practical experience designing or deploying AI-assisted security tooling, leveraging LLMs for automated software patch generation, or evaluating vulnerability detection agents within enterprise developer pipelines.

- Prior experience operating alongside GRC frameworks, authoring developer-facing security policies from scratch, and building automated policy-as-code gateway integrations.

- Public track record of CVEs, security research, or open-source contributions to security tooling.

- Advanced credentials such as OSCP, OSWE, CISSP or equivalent.

- Experience with on-chain/off-chain integration, payment reconciliation, or smart contract security.

- Familiarity with vulnerability management platforms (DefectDojo, Dependabot orchestration) and GRC/Gateway integrations.

- Prior contributions to security automation and developer tooling (open source or internal).

### COMPENSATION & PERKS

- Full-time salary based on experience and meaningful equity in an industry-leading company

- This is a role based in our London office, with a mandatory in-office presence four days per week.

- Work from Anywhere Policy: You can work remotely from anywhere in the world for up to 20 days per year.

- ClassPass

- Unlimited vacation policy; work hard and take time when you need it

- Apple equipment

- The opportunity to be a key player and build your career at a rapidly expanding, global technology company in an emerging field

- Flexible work culture

Blockchain is committed to diversity and inclusion in the workplace and is proud to be an equal opportunity employer. We prohibit discrimination and harassment of any kind based on race, religion, color, national origin, gender, gender expression, sex, sexual orientation, age, marital status, veteran status, disability status or any other characteristic protected by law. This policy applies to all employment practices within our organization, including hiring, recruiting, promotion, termination, layoff, recall, leave of absence, and apprenticeship. Blockchain makes hiring decisions based solely on qualifications, merit, and business needs at the time.

You may contact our Data Protection Officer by email at dpo@blockchain.com. Your personal data will be processed for the purposes of managing Controller’s recruitment related activities, which include setting up and conducting interviews and tests for applicants, evaluating and assessing the results thereto, and as is otherwise needed in the recruitment and hiring processes. Such processing is legally permissible under Art. 6(1)(f) of Regulation (EU) 2016/679 (General Data Protection Regulation) as necessary for the purposes of the legitimate interests pursued by the Controller, which are the solicitation, evaluation, and selection of applicants for employment.

Your personal data will be shared with Greenhouse Software, Inc., a cloud services provider located in the United States of America and engaged by Controller to help manage its recruitment and hiring process on Controller’s behalf. Accordingly, if you are located outside of the United States, your personal data will be transferred to the United States once you submit it through this site. Because the European Union Commission has determined that United States data privacy laws do not ensure an adequate level of protection for personal data collected from EU data subjects, the transfer will be subject to appropriate additional safeguards under the standard contractual clauses.

Your personal data will be retained by Controller as long as Controller determines it is necessary to evaluate your application for employment. Under the GDPR, you have the right to request access to your personal data, to request that your personal data be rectified or erased, and to request that processing of your personal data be restricted. You also have the right to data portability. In addition, you may lodge a complaint with an EU supervisory authority.

**Live in Blockchain’s hiring system.** Read from the company's own applicant tracking system, not reposted from a job board — so it's a real, open requisition rather than an ad that outlived the role.

We remove it as soon as it disappears at source.

## More jobs like this

- CO [Security Engineer](https://gurify.com/job/security-engineer-at-conduct-354c5d006329) Conduct · London, United Kingdom · last week
- HA [Senior Security Engineer, Detection and Response](https://gurify.com/job/senior-security-engineer-detection-and-response-at-hackerone-45f09130ce13) Hackerone · London · last week
- CO [Senior Cloud Native Security Engineer](https://gurify.com/job/senior-cloud-native-security-engineer-at-controlplane-1a80f4fea92c) Controlplane · London · 4 days ago
- AN [Senior Product Security Engineer](https://gurify.com/job/senior-product-security-engineer-at-andurilindustries-74aa38d8eb35) Andurilindustries · London, United Kingdom · 6 weeks ago
- AN [Senior Product Security Engineer](https://gurify.com/job/senior-product-security-engineer-at-andurilindustries-c2faf3dcb01a) Andurilindustries · London, United Kingdom · 6 weeks ago
- MO [Senior Developer Experience Security Engineer](https://gurify.com/job/senior-developer-experience-security-engineer-at-motorway-8088847ce3c6) Motorway · London · 3 weeks ago

```json
{"@context":"https://schema.org/","@type":"JobPosting","title":"Senior Product Security Engineer","description":"\u003Cp\u003EBlockchain is connecting the world to the future of finance. As the most trusted and fastest-growing global crypto company, it helps millions of people worldwide safely access cryptocurrency. Since its inception in 2011, Blockchain has earned the trust of over 90 million wallet holders and more than 40 million verified users, facilitating over $1 trillion in crypto transactions.\u003C/p\u003E\u003Cp\u003EYou will operate the Product Security programe for Blockchain.com\u2019s internally-developed products across Consumer, OTC and MRE lines. This is a senior, hands-on role: you\u2019ll design and run the secure development lifecycle, lead threat modeling and architecture review, own the security debt lifecycle for product engineering teams, and architect the automated pipelines that protect billions in transaction volume. You will embed with product and engineering teams, convert technical findings into business-prioritized remediation, and lift developer capabilities so security is delivered by code and process.\u003C/p\u003E\u003Ch3\u003EWHAT YOU WILL DO\u003C/h3\u003E\u003Cul\u003E\u003Cli\u003EStrategic Security Partnership: Act as a senior security engineer for the different product lines like Consumer, OTC. You will own the security gates for major feature releases and ensure security is integrated from the design phase.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003ESecure SDLC Operator: Operate and improve the secure development lifecycle. This includes orchestrating SAST/SCA/DAST, streamlining SARIF ingestion, PR review standards, CI/CD security automation, and vulnerability triage workflows.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EAI-Driven SDLC Innovation: Research, architect, and safely embed cutting-edge AI utilities and Large Language Model (LLM) agents directly into our secure development lifecycle.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EThreat Modelling \u0026amp; Architecture Reviews: Lead STRIDE/attack-tree threat models for sensitive flows including authentication, payment, custody, reconciliation and sign off on security architecture for critical designs.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EProduct Security Governance \u0026amp; Standards: Translate technical risks and regulatory demands into clear security policies. You will own the creation and upkeep of our Application Security Standards, reference architectures, and compliance-driven secure coding baselines.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EBug Bounty Leadership: Oversee the technical triage and remediation strategy for our Bug Bounty program. You will turn external researcher findings into internal architectural hardening projects.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003ERelease Reviews: Perform deep-dive manual code reviews of security-sensitive Pull Requests, mentor engineers on secure coding patterns, and provide pragmatic remediation guidance.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EAdvanced Code Auditing: Conduct deep-dive manual and automated code reviews on highly sensitive Java and Kotlin backend Pull Requests.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003ESecurity Debt \u0026amp; Remediation Negotiation: Produce data-driven Security Debt packs and negotiate remediation into engineering roadmaps. You will negotiate remediation timelines with Product Owners and Engineering leadership, backed by risk-based data.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EDetection \u0026amp; Telemetry Integration: Define application runtime signals (business-logic anomalies, auth anomalies, reconciliation mismatches) and work with SecOps to instrument logs and alerts.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003ETesting \u0026amp; Automation: Build and maintain product-level test harnesses, fuzzing/property tests and CI checks to prevent regressions for business-critical flows.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EIncident Response Support: Provide product-level Incident Response expertise like test forensic runbooks, support reproduction of payment/settlement incidents, and advise on containment/remediation whenever needed.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EMetrics \u0026amp; Risk Visibility: Define and own the Product Security metrics (e.g., MTTR for critical vulnerabilities, security debt burn-down, and defect density). You will translate these KPIs into high-level risk reports for the Head of Security and Engineering leadership to drive data-backed resourcing decisions.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EPeople \u0026amp; Process: Coach junior product security engineers and security champions. You will assist the Product Security Lead to define hiring standards and capability plans.\u003C/li\u003E\u003C/ul\u003E\u003Ch3\u003EWHAT YOU WILL NEED\u003C/h3\u003E\u003Ch3\u003EMust-Haves\u003C/h3\u003E\u003Cul\u003E\u003Cli\u003E4\u002B years total security engineering experience with at least 3\u002B years focused specially in application/product security or equivalent.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EExperience with Web, Mobile, Cloud, Infrastructure Pentests and Red Teaming (e.g., phishing)\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EProven track record of shipping security automation using CodeQL/GHAS, Snyk, or similar. You should be intimately familiar with the SARIF ecosystem and ASPM workflows.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EExpert-level ability to audit and propose fixes in Kotlin/Java, TypeScript/JS, Python, and familiarity with containerised deployments (Kubernetes).\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EStrong threat modeling experience and pragmatic architecture guidance for high-stakes financial flows (AuthN/AuthZ, Cryptography, Payments).\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EExperience building CI checks, test harnesses and lightweight fuzzing/property tests.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EExcellent stakeholder skills \u2014 able to negotiate remediation with Engineering Directors and Product owners, balancing security requirements with business velocity.\u003C/li\u003E\u003C/ul\u003E\u003Ch3\u003ENice-to-haves\u003C/h3\u003E\u003Cul\u003E\u003Cli\u003EPrior fintech/Trading/OTC product security experience or familiarity with custody/signing patterns.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EPractical experience designing or deploying AI-assisted security tooling, leveraging LLMs for automated software patch generation, or evaluating vulnerability detection agents within enterprise developer pipelines.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EPrior experience operating alongside GRC frameworks, authoring developer-facing security policies from scratch, and building automated policy-as-code gateway integrations.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EPublic track record of CVEs, security research, or open-source contributions to security tooling.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EAdvanced credentials such as OSCP, OSWE, CISSP or equivalent.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EExperience with on-chain/off-chain integration, payment reconciliation, or smart contract security.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EFamiliarity with vulnerability management platforms (DefectDojo, Dependabot orchestration) and GRC/Gateway integrations.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EPrior contributions to security automation and developer tooling (open source or internal).\u003C/li\u003E\u003C/ul\u003E\u003Ch3\u003ECOMPENSATION \u0026amp; PERKS\u003C/h3\u003E\u003Cul\u003E\u003Cli\u003EFull-time salary based on experience and meaningful equity in an industry-leading company\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EThis is a role based in our London office, with a mandatory in-office presence four days per week.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EWork from Anywhere Policy: You can work remotely from anywhere in the world for up to 20 days per year.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EClassPass\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EUnlimited vacation policy; work hard and take time when you need it\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EApple equipment\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EThe opportunity to be a key player and build your career at a rapidly expanding, global technology company in an emerging field\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EFlexible work culture\u003C/li\u003E\u003C/ul\u003E\u003Cp\u003EBlockchain is committed to diversity and inclusion in the workplace and is proud to be an equal opportunity employer. We prohibit discrimination and harassment of any kind based on race, religion, color, national origin, gender, gender expression, sex, sexual orientation, age, marital status, veteran status, disability status or any other characteristic protected by law. This policy applies to all employment practices within our organization, including hiring, recruiting, promotion, termination, layoff, recall, leave of absence, and apprenticeship. Blockchain makes hiring decisions based solely on qualifications, merit, and business needs at the time.\u003C/p\u003E\u003Cp\u003EYou may contact our Data Protection Officer by email at dpo@blockchain.com. Your personal data will be processed for the purposes of managing Controller\u2019s recruitment related activities, which include setting up and conducting interviews and tests for applicants, evaluating and assessing the results thereto, and as is otherwise needed in the recruitment and hiring processes. Such processing is legally permissible under Art. 6(1)(f) of Regulation (EU) 2016/679 (General Data Protection Regulation) as necessary for the purposes of the legitimate interests pursued by the Controller, which are the solicitation, evaluation, and selection of applicants for employment.\u003C/p\u003E\u003Cp\u003EYour personal data will be shared with Greenhouse Software, Inc., a cloud services provider located in the United States of America and engaged by Controller to help manage its recruitment and hiring process on Controller\u2019s behalf. Accordingly, if you are located outside of the United States, your personal data will be transferred to the United States once you submit it through this site. Because the European Union Commission has determined that United States data privacy laws do not ensure an adequate level of protection for personal data collected from EU data subjects, the transfer will be subject to appropriate additional safeguards under the standard contractual clauses.\u003C/p\u003E\u003Cp\u003EYour personal data will be retained by Controller as long as Controller determines it is necessary to evaluate your application for employment. Under the GDPR, you have the right to request access to your personal data, to request that your personal data be rectified or erased, and to request that processing of your personal data be restricted. You also have the right to data portability. In addition, you may lodge a complaint with an EU supervisory authority.\u003C/p\u003E","identifier":{"@type":"PropertyValue","name":"Gurify","value":"senior-product-security-engineer-at-blockchain-8a7514d3975a"},"url":"https://gurify.com/job/senior-product-security-engineer-at-blockchain-8a7514d3975a","datePosted":"2026-06-24","validThrough":"2026-11-02T23:59:59Z","hiringOrganization":{"@type":"Organization","name":"Blockchain","sameAs":"https://job-boards.greenhouse.io/blockchain"},"directApply":false,"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressCountry":"GB","addressLocality":"London"}}}
```

```json
{"@context":"https://schema.org/","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Jobs","item":"https://gurify.com/jobs"},{"@type":"ListItem","position":2,"name":"United Kingdom","item":"https://gurify.com/jobs/united-kingdom"},{"@type":"ListItem","position":3,"name":"Senior Product Security Engineer","item":"https://gurify.com/job/senior-product-security-engineer-at-blockchain-8a7514d3975a"}]}
```
