Senior Product Security Engineer
Blockchain
You will operate the Product Security programe for Blockchain.com’s internally-developed products across Consumer, OTC and MRE lines. This is a senior, hands-on role: you’ll design and run the secure development lifecycle, lead threat modeling and architecture review, own the security debt lifecycle for product engineering teams, and architect the automated pipelines that protect billions in transaction volume. You will embed with product and engineering teams, convert technical findings into business-prioritized remediation, and lift developer capabilities so security is delivered by code and process.
WHAT YOU WILL DO- Strategic Security Partnership: Act as a senior security engineer for the different product lines like Consumer, OTC. You will own the security gates for major feature releases and ensure security is integrated from the design phase.
- Secure SDLC Operator: Operate and improve the secure development lifecycle. This includes orchestrating SAST/SCA/DAST, streamlining SARIF ingestion, PR review standards, CI/CD security automation, and vulnerability triage workflows.
- AI-Driven SDLC Innovation: Research, architect, and safely embed cutting-edge AI utilities and Large Language Model (LLM) agents directly into our secure development lifecycle.
- Threat Modelling & Architecture Reviews: Lead STRIDE/attack-tree threat models for sensitive flows including authentication, payment, custody, reconciliation and sign off on security architecture for critical designs.
- Product Security Governance & Standards: Translate technical risks and regulatory demands into clear security policies. You will own the creation and upkeep of our Application Security Standards, reference architectures, and compliance-driven secure coding baselines.
- Bug Bounty Leadership: Oversee the technical triage and remediation strategy for our Bug Bounty program. You will turn external researcher findings into internal architectural hardening projects.
- Release Reviews: Perform deep-dive manual code reviews of security-sensitive Pull Requests, mentor engineers on secure coding patterns, and provide pragmatic remediation guidance.
- Advanced Code Auditing: Conduct deep-dive manual and automated code reviews on highly sensitive Java and Kotlin backend Pull Requests.
- Security Debt & Remediation Negotiation: Produce data-driven Security Debt packs and negotiate remediation into engineering roadmaps. You will negotiate remediation timelines with Product Owners and Engineering leadership, backed by risk-based data.
- Detection & Telemetry Integration: Define application runtime signals (business-logic anomalies, auth anomalies, reconciliation mismatches) and work with SecOps to instrument logs and alerts.
- Testing & Automation: Build and maintain product-level test harnesses, fuzzing/property tests and CI checks to prevent regressions for business-critical flows.
- Incident Response Support : Provide product-level Incident Response expertise like test forensic runbooks, support reproduction of payment/settlement incidents, and advise on containment/remediation whenever needed.
- Metrics & Risk Visibility: Define and own the Product Security metrics (e.g., MTTR for critical vulnerabilities, security debt burn-down, and defect density). You will translate these KPIs into high-level risk reports for the Head of Security and Engineering leadership to drive data-backed resourcing decisions.
- People & Process: Coach junior product security engineers and security champions. You will assist the Product Security Lead to define hiring standards and capability plans.
- 4+ years total security engineering experience with at least 3+ years focused specially in application/product security or equivalent.
- Experience with Web, Mobile, Cloud, Infrastructure Pentests and Red Teaming (e.g., phishing)
- Proven track record of shipping security automation using CodeQL/GHAS, Snyk, or similar. You should be intimately familiar with the SARIF ecosystem and ASPM workflows.
- Expert-level ability to audit and propose fixes in Kotlin/Java, TypeScript/JS, Python, and familiarity with containerised deployments (Kubernetes).
- Strong threat modeling experience and pragmatic architecture guidance for high-stakes financial flows (AuthN/AuthZ, Cryptography, Payments).
- Experience building CI checks, test harnesses and lightweight fuzzing/property tests.
- Excellent stakeholder skills — able to negotiate remediation with Engineering Directors and Product owners, balancing security requirements with business velocity.
- Prior fintech/Trading/OTC product security experience or familiarity with custody/signing patterns.
- Practical experience designing or deploying AI-assisted security tooling, leveraging LLMs for automated software patch generation, or evaluating vulnerability detection agents within enterprise developer pipelines.
- Prior experience operating alongside GRC frameworks, authoring developer-facing security policies from scratch, and building automated policy-as-code gateway integrations.
- Public track record of CVEs, security research, or open-source contributions to security tooling.
- Advanced credentials such as OSCP, OSWE, CISSP or equivalent.
- Experience with on-chain/off-chain integration, payment reconciliation, or smart contract security.
- Familiarity with vulnerability management platforms (DefectDojo, Dependabot orchestration) and GRC/Gateway integrations.
- Prior contributions to security automation and developer tooling (open source or internal).
- Unlimited vacation policy; work hard and take time when you need it.
- Unlimited books policy; order the technical resources you need or simply pick something up from our company library.
- Apple equipment.
- Full-time salary based on experience and meaningful equity in an industry-leading company.
- Role based in our Paris office, with a mandatory in-office presence four days per week
- Work from Anywhere Policy: You can work remotely from anywhere in the world for up to 20 days per year.
- ...full infrastructure: issuing, operating, and distributing the products ourselves. Two years after launch, we serve thousands of organizations... ...Responsibilities We are looking for a fullstack software engineer to join Spiko’s 8-people tech team. Typical tasks for a...SeniorFull timeWork at officeRemote work2 days per week
- ...of the world’s crypto assets secured through our Ledger devices. With... ...developing a variety of products and services to enable individuals... ...—and enriches them, so our engineers can focus on what matters... ...What you’ll be doing: As a Senior Security Operations Engineer...SeniorRemote jobFull time
- ...transactions. You’ll be the hands-on security engineer embedded with the Institutional Trading... ...Act as the primary security liaison for Senior Management and third-party vendors. You... ...prevent credential leakage. Assist product security in triage of SAST/SCA findings...SuggestedFull timeContract workApprenticeshipWork at officeRemote workWorldwide
$100k - $120k
Job Description Job Description Avir Health Group is searching for a qualified Nurse Practitioner (Skilled Nursing) to join our family! This position is focused in a Skilled Nursing Facility (SNF) setting, where you would serve as a clinical leader, working collaboratively...SeniorTemporary workFlexible hours- ...of the world’s crypto assets secured through our Ledger devices. With... ...developing a variety of products and services to enable individuals... ...—and enriches them, so our engineers can focus on what matters... ...foster the technical growth of senior and junior engineers, and act...SuggestedRemote jobFull time
- ...needs, and guide them through the design process-offering "good, better, best" options, samples to take home, and expert advice on products, services, and installation. Kitchen Designers use design tools and showroom resources to educate customers, set clear...Local area
- ...About the role We are seeking a creative and highly motivated Senior Translational Scientist to join Bioptimus’ R&D team and... ...Collaborate with leading hospitals, biobanks, researchers, and engineers across the globe. And benefit from: A collaborative and mission...SeniorFull timeRemote workFlexible hours
- ...trillion in crypto transactions. We are looking for a Senior Infrastructure Security Engineer with a proven track record in keeping systems safe.... ...our entire stack, from supporting our consumer-facing products and our institutional offerings to ensuring that we are...Full timeApprenticeshipWork at officeRemote workWorldwide
€75k - €95k per year
...full infrastructure: issuing, operating, and distributing the products ourselves. Two years after launch, we serve thousands of... ...talk. We are looking for a Founding Infrastructure & Security Engineer to join Spiko's 8-people engineering team. You will be the first...Full timeWork at officeRemote work2 days per week- ...3 days a week. Sorare is seeking a Senior Software Engineer to join the iOS team. We craft officially... ...from inception to launch Work with product managers, designers, and backend... ...assisted workflows) Care deeply about security, performance, and maintainability Help...SeniorFull timeWork at officeWorldwide3 days per week
- Who We Are Boston Consulting Group partners with leaders in business and society to tackle their most important challenges and capture their greatest opportunities. BCG was the pioneer in business strategy when it was founded in 1963. Today, we help clients with total...Full timePrivate practiceLocal area
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Senior Product Security Engineer. Be the first to apply!


