Skip to content
← Back to job listings

Senior Product Security Engineer

Blockchain.com · London, United Kingdom

External listingfull-timeabout 1 month ago

About The Role

Join as a Senior Product Security Engineer, where you will lead the Product Security program for our internally-developed products. This hands-on role involves designing and running the secure development lifecycle, leading threat modeling and architecture reviews, and owning the security debt lifecycle for product engineering teams. You will also embed with product and engineering teams, convert technical findings into business-prioritized remediation, and lift developer capabilities. Additionally, you will oversee the Bug Bounty program, perform deep-dive manual code reviews, and define application runtime signals. This is a remote-first position with meaningful equity, unlimited vacation, and various other benefits. - Operar el programa de seguridad del producto para los productos desarrollados internamente de , liderar la modelización de amenazas y la revisión de la arquitectura. - Diseñar y ejecutar el ciclo de vida de desarrollo seguro, liderar la automatización de la seguridad y la integración de herramientas de seguridad en el ciclo de vida de desarrollo. - Actuar como ingeniero de seguridad senior para las diferentes líneas de productos, ser responsable de las puertas de seguridad para los lanzamientos de características importantes. - Experience building CI checks, test harnesses and lightweight fuzzing/property tests - 4+ years total security engineering experience with at least 3+ years focused specially in application/product security or equivalent - Strong threat modeling experience and pragmatic architecture guidance for high-stakes financial flows (AuthN/AuthZ, Cryptography, Payments) - Proven track record of shipping security automation using CodeQL/GHAS, Snyk, or similar. You should be intimately familiar with the SARIF ecosystem and ASPM workflows - Expert-level ability to audit and propose fixes in Kotlin/Java, TypeScript/JS, Python, and familiarity with containerised deployments (Kubernetes) - Experience with Web, Mobile, Cloud, Infrastructure Pentests and Red Teaming (e.g., phishing) - Excellent stakeholder skills — able to negotiate remediation with Engineering Directors and Product owners, balancing security requirements with business velocity - Prior fintech/Trading/OTC product security experience or familiarity with custody/signing patterns - Practical experience designing or deploying AI-assisted security tooling, leveraging LLMs for automated software patch generation, or evaluating vulnerability detection agents within enterprise developer pipelines - Prior experience operating alongside GRC frameworks, authoring developer-facing security policies from scratch, and building automated policy-as-code gateway integrations - Public track record of CVEs, security research, or open-source contributions to security tooling - Advanced credentials such as OSCP, OSWE, CISSP or equivalent - Familiarity with vulnerability management platforms (DefectDojo, Dependabot orchestration) and GRC/Gateway integrations - Experience with on-chain/off-chain integration, payment reconciliation, or smart contract security - Prior contributions to security automation and developer tooling (open source or internal)

This is an external listing. JobSpring does not represent or verify the employer. Report this listing