Staff Security Engineer, Product Security

Chainalysis Inc.

Greater London

On-site

GBP 80,000 - 100,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Chainalysis Inc. in Greater London is seeking a Staff Product Security Engineer to lead security efforts across their SaaS platform. You will partner with engineering on security processes, run reviews, and handle bug reporting workflows to ensure robust application security.

The ideal candidate will have at least 8 years of experience in application security, strong coding skills, particularly in Java, and experience with penetration testing and CI/CD automation. Join Chainalysis to enhance security for financial investigations on a global scale.

Qualifications

  • 8+ years of application security engineering experience.
  • Strong production coding ability in Java, TypeScript/JavaScript, Python, or Go.
  • Building security automation into CI/CD pipelines.

Responsibilities

  • Lead Product Security across Chainalysis' SaaS offerings.
  • Own Unified Security Review process for new product launches.
  • Drive Security Engineering Risk Management Framework.

Skills

Application security engineering
Deep code review
Penetration testing
Threat modeling
CI/CD pipelines
Web application vulnerabilities

Tools

AWS
Kubernetes
Terraform
GitHub

Job description

About the Team

Product Security at Chainalysis keeps our SaaS platform — used by governments, banks, and crypto exchanges to investigate financial crime — secure by design. We partner directly with product and platform engineering on threat modeling, design reviews, penetration testing, and remediation of findings across our AWS and Kubernetes estate.

As a Staff Product Security Engineer, you'll be the technical lead for product security across one or more product areas. You'll run security reviews for new launches and AI tooling, perform hands‑on pentests, ship code and fixes directly into product repos, own our Vulnerability Disclosure Program, and drive SOC2 and risk‑framework work across R&D. You'll participate in a shared on‑call rotation for production security incidents.

In this role, you’ll:
  • Lead Product Security across Chainalysis' SaaS offerings, partnering with product and platform engineering teams on design, code, and remediation
  • Own Unified Security Review process for new product launches, vendor evaluations, and AI tooling — including custom penetration tests scoped to each review
  • Drive Security Engineering Risk Management Framework, for consistent risk classification and remediation tracking across product
  • Lead the Vulnerability Disclosure Program and security bug reporting workflow, from researcher intake through fix
  • Drive SOC2 and compliance‑related security remediation across product engineering, partnering with R&D leads on architectural fixes
  • Provide security review and guardrails for internal AI platforms and coding agents (LLM gateways, prompt/response controls, agent permissioning)
  • Participate in a shared on‑call rotation for high‑severity production security incidents
We’re looking for candidates who have:
  • 8+ years of application security engineering experience
  • Strong production coding ability in at least one of Java (preferred), TypeScript/JavaScript, Python, or Go — enough to perform deep code review, write proof‑of‑concept exploits, and contribute fixes directly into product repos
  • Building security automation into CI/CD pipelines
  • Hands‑on penetration testing of production SaaS applications, including custom tests scoped to new product launches
  • Threat modeling, secure design reviews, and static/dynamic code analysis across the SDLC
  • Identifying and remediating common web application vulnerabilities (OWASP Top 10)
  • Experience securing internal AI/LLM platforms and coding agents (model gateways, prompt/response controls, agent permissioning)
Nice to have experience:
  • Experience in Web3, Blockchain or Digital Assets
  • Experience building AI workflows, agents, and guardrailing
Technologies we use:
  • Cloud and containers: AWS, GCP, Kubernetes (EKS/GKE)
  • Infrastructure‑as‑Code: Terraform
  • Security tooling: Wiz, SonarCloud, Burp, Cloudflare
  • CI/CD and source control: GitHub, GitHub Actions, Artifactory and related build/deploy tooling
  • Languages and scripting: Java, JavaScript, Python, Go
  • AI Coding Agents, Tooling, Systems
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Staff Product Security Engineer: Lead Threat Modeling & AI
Staff Product Security Engineer: Lead Threat Modeling & AI

Chainalysis Inc. • Greater London

On-site
GBP 80,000 - 100,000
Security Lead
Security Lead

Taktile • Greater London

On-site
GBP 110,000 - 190,000
Equity
Self-development budget
Home office setup
+1
Engineering Manager, Platform
Engineering Manager, Platform

Chainalysis • United Kingdom

On-site
GBP 80,000 - 120,000
Software Engineer II, Foundation
Software Engineer II, Foundation

chainalysis-careers • Greater London

On-site
GBP 70,000 - 110,000
Software Engineer II, Foundation
Software Engineer II, Foundation

Chainalysis • Greater London

On-site
GBP 65,000 - 110,000
Product Security Engineer
Product Security Engineer

Action1 Corporation • United Kingdom

Hybrid
GBP 60,000 - 85,000
Fully remote work environment
Opportunity to work on a real security product
Close collaboration with teams
+1
Product Security Engineer - Software Security Enablement
Product Security Engineer - Software Security Enablement

Bloomberg • Greater London

On-site
GBP 90,000 - 120,000
Security Engineer
Security Engineer

Copello • Uxbridge

Hybrid
GBP 85,000 - 120,000
Backend Engineer: Crypto Risk & Data APIs
Backend Engineer: Crypto Risk & Data APIs

jobs.frontdoordefense.com - Jobboard • Greater London

On-site
Head of Application Security
Head of Application Security

Harvey Nash • Greater London

On-site
GBP 120,000 - 180,000
Expenses covered for London visits