Security Engineer (Institutional Trading)
Blockchain.com · London, United Kingdom
About The Role
Join our team as a Security Engineer embedded with the Institutional Trading and Financial Operations (FinOps) team. In this high-visibility role, you will focus on the secure operation of off-chain trading processes and infrastructure, supporting risk assessments, operating controls, and automation to detect operational anomalies. You will partner with various teams to map out trading systems and data flows, conduct deep-dive assessments, and act as the primary security liaison for Senior Management and third-party vendors. Additionally, you will implement and maintain monitoring for FinOps-specific security signals, support secrets and key-management hygiene, assist product security in triage of findings, participate in incident exercises, and document controls.
- Act as the primary security liaison for Senior Management and third-party vendors, translating complex technical gaps into actionable business risk summaries.
- Conduct deep-dive assessments mapping critical assets and workflows to identify structural vulnerabilities, defining the Target State and drafting the strategic Risk Treatment Plans.
- Implement and maintain monitoring for FinOps-specific security signals, integrating these signals into our SIEM/SOAR for real-time response.
- Exceptional ability to translate "Technical Debt" into Business Risk for C-suite stakeholders (CFO, CTO, Head of Trading)
- Ability to raise, read and audit Pull Requests in at least one language used in our stack (TypeScript, Java/Kotlin, Python)
- Proven expertise in Threat Modeling. Ability to perform structured reviews (e.g., STRIDE) of complex data flows and operational processes
- Experience with observability and detection tooling (SIEM, logs, metrics) and ability to write basic detection rules
- Practical experience with KMS/HSM, secrets management platforms (Vault, 1Password, AWS/GCP KMS), IAM patterns and least-privilege
- Experience conducting technical due diligence and scoping for third-party security integrations
- 5+ years in security engineering, platform security, or application security experience
- Familiarity with trading systems or financial operations (market-making, execution, settlement) or close collaboration background with trading/quant teams
- Exposure to blockchain on-chain concepts (wallets, addresses, transactions) but no requirement to audit contracts
- Familiarity with SOC operations, and post-incident forensic analysis
- Any relevant industry certification
- Familiarity with SOC2, ISO 27001, or financial audit requirements
This is an external listing. JobSpring does not represent or verify the employer. Report this listing
JobSpring