Product Security Engineer
What security roles in crypto pay
64 salaries · our own dataMost security roles in crypto pay between $145k and $268k, with a median of $202k.
As a Product Security Engineer at Blockchain, you operate the Product Security programme for the company's internally-developed products across Consumer, OTC, and MRE lines. This is a senior, hands-on role: you design and run the secure development lifecycle, lead threat modeling and architecture review, own the security debt lifecycle for product engineering teams, and architect the automated pipelines that protect billions in transaction volume. You embed with product and engineering teams, convert technical findings into business-prioritized remediation, and lift developer capabilities so security is delivered by code and process.
What you'll do
- Act as a senior security engineer for product lines like Consumer and OTC, owning the security gates for major feature releases and ensuring security is integrated from the design phase
- Operate and improve the secure development lifecycle, including orchestrating SAST/SCA/DAST, streamlining SARIF ingestion, PR review standards, CI/CD security automation, and vulnerability triage workflows
- Research, architect, and safely embed cutting-edge AI utilities and Large Language Model (LLM) agents directly into the secure development lifecycle
- Lead STRIDE and attack-tree threat models for sensitive flows including authentication, payment, custody, and reconciliation, and sign off on security architecture for critical designs
- Translate technical risks and regulatory demands into clear security policies, owning the creation and upkeep of Application Security Standards, reference architectures, and compliance-driven secure coding baselines
- Oversee the technical triage and remediation strategy for the Bug Bounty programme, turning external researcher findings into internal architectural hardening projects
- Perform deep-dive manual code reviews of security-sensitive Pull Requests, mentor engineers on secure coding patterns, and provide pragmatic remediation guidance
- Conduct deep-dive manual and automated code reviews on highly sensitive Java and Kotlin backend Pull Requests
- Produce data-driven Security Debt packs and negotiate remediation into engineering roadmaps, backed by risk-based data and aligned with Product Owners and Engineering leadership
- Define application runtime signals such as business-logic anomalies, auth anomalies, and reconciliation mismatches, and work with SecOps to instrument logs and alerts
- Build and maintain product-level test harnesses, fuzzing and property tests, and CI checks to prevent regressions for business-critical flows
- Provide product-level Incident Response expertise including test forensic runbooks, support for reproduction of payment and settlement incidents, and advice on containment and remediation
- Define and own Product Security metrics such as MTTR for critical vulnerabilities, security debt burn-down, and defect density, translating these KPIs into high-level risk reports for the Head of Security and Engineering leadership
- Coach junior product security engineers and security champions, and assist the Product Security Lead to define hiring standards and capability plans
What you bring
- 4+ years total security engineering experience with at least 3+ years focused on application or product security, or equivalent
- Experience with Web, Mobile, Cloud, and Infrastructure Pentests and Red Teaming, such as phishing campaigns
- Proven track record of shipping security automation using CodeQL/GHAS, Snyk, or similar tools, with intimate familiarity with the SARIF ecosystem and ASPM workflows
- Expert-level ability to audit and propose fixes in Kotlin and Java, TypeScript and JavaScript, Python, and familiarity with containerised deployments such as Kubernetes
- Strong threat modeling experience and pragmatic architecture guidance for high-stakes financial flows including AuthN/AuthZ, Cryptography, and Payments
- Experience building CI checks, test harnesses, and lightweight fuzzing or property tests
- Excellent stakeholder skills: able to negotiate remediation with Engineering Directors and Product Owners while balancing security requirements with business velocity
Nice to have
- Prior fintech, Trading, or OTC product security experience or familiarity with custody and signing patterns
- Practical experience designing or deploying AI-assisted security tooling, leveraging LLMs for automated software patch generation, or evaluating vulnerability detection agents within enterprise developer pipelines
- Prior experience operating alongside GRC frameworks, authoring developer-facing security policies from scratch, and building automated policy-as-code gateway integrations
- Public track record of CVEs, security research, or open-source contributions to security tooling
- Advanced credentials such as OSCP, OSWE, or CISSP or equivalent
- Experience with on-chain and off-chain integration, payment reconciliation, or smart contract security
- Familiarity with vulnerability management platforms such as DefectDojo and Dependabot orchestration, and GRC/Gateway integrations
- Prior contributions to security automation and developer tooling, whether open source or internal
What we offer
- Full-time salary based on experience and meaningful equity in an industry-leading company
- Role based in the London office with mandatory in-office presence four days per week
- Work from Anywhere Policy allowing remote work from anywhere in the world for up to 20 days per year
- ClassPass membership
- Unlimited vacation policy
- Apple equipment
- Flexible work culture
About Blockchain
Blockchain is connecting the world to the future of finance. As a global crypto company trusted by over 90 million wallet holders and more than 40 million verified users, it facilitates over $1 trillion in crypto transactions and helps millions of people safely access cryptocurrency.
