The blockchain data platform
Staff Security Engineer – Product Security
Location
United Kingdom
Posted
6 days ago
Salary
0
Seniority
Lead
Job Description
Staff Security Engineer – Product Security
Chainalysis Inc.
• Lead Product Security across Chainalysis' SaaS offerings • Own Unified Security Review process for new product launches, vendor evaluations, and AI tooling • Drive Security Engineering Risk Management Framework • Lead the Vulnerability Disclosure Program and security bug reporting workflow • Drive SOC2 and compliance-related security remediation • Provide security review and guardrails for internal AI platforms and coding agents • Participate in a shared on-call rotation for high-severity production security incidents
Job Requirements
- 8+ years of application security engineering experience
- Strong production coding ability in at least one of Java (preferred), TypeScript/JavaScript, Python, or Go
- Building security automation into CI/CD pipelines
- Hands-on penetration testing of production SaaS applications
- Threat modeling, secure design reviews, and static/dynamic code analysis across the SDLC
- Identifying and remediating common web application vulnerabilities (OWASP Top 10)
- Experience securing internal AI/LLM platforms and coding agents
Benefits
- Diversity and inclusion initiatives
- Accommodation for disabilities
- Professional development opportunities
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
Senior Security Architect – Active Directory
GuidePoint SecurityWe help organizations make smarter cybersecurity decisions that minimize risk.
• Responsible for implementation and enhancement of Active Directory solutions • Gather and Document technical requirements and design • Act as subject matter expert for client discussions
• Support cybersecurity compliance and risk management efforts within the HACS program. • Help maintain system authorization. • Develop security documentation. • Ensure systems meet federal cybersecurity standards.
Security Engineer III – Ransomware Governance
AstreyaAstreya provides IT support services with a special focus on increasing productivity and employee satisfaction for its business clients. The company was founded
• Support the maturation and day‑to‑day operationalization of the ransomware recovery governance program through hands‑on process execution, documentation updates, and technical validation activities. • Apply and enforce ransomware recovery maintenance policies by performing configuration checks, control verification, and operational compliance reviews. • Coordinate and execute testing for protected applications, including technical recovery validation, dependency mapping, and test result analysis. • Design and implement the application review and onboarding workflow, including technical assessments, readiness evaluations, and control implementation support. • Develop and document the decision authority framework by gathering requirements, validating operational roles, and ensuring alignment with technical processes. • Partner with incident response teams to build and refine the ransomware incident response plan, leading technical exercises, simulations, and tabletop scenarios. • Contribute technical insights to future‑state technology assessments, tool evaluations, and ransomware resilience capability improvements. • Review and enhance existing: Security policies and standards; Backup and recovery strategies; Risk management processes
• Build, operationalize, and scale the security engineering practices that protect the benefits platform • Work across application security, cloud security, security architecture, supply chain security, detection engineering, and vulnerability management • Partner deeply with the teams building web and mobile applications, backend services, system integrations, card and banking workflows, infrastructure as code, and data platforms • Turn risk reduction into scalable guardrails, automated controls, and clear engineering guidance • Help define secure AI tooling usage, LLM and code-assistant governance, and data protection practices for AI-enabled development workflows • Balance ideal security outcomes with engineering velocity and business priorities




