wagey.ggwagey.gg
38,923  jobs38,923  jobs
Browse Tech JobsCompaniesFeaturesPricingFAQs
Log InGet Started Free
Jobs(38,923)/Security Engineer Role(522)/Blockchain.com (22) - Senior Product Security Engineer
Pro members applied to this job 36 hours before you saw itGet Pro ›
Blockchain.com

Blockchain.com - Senior Product Security Engineer

London+ Equity3d ago
In OfficeSeniorEMEAFintechPaymentsSecurity EngineerSenior Product ManagerJavaKotlinTypeScriptPythonKubernetesCoachingPerformance ReviewsReportingGovernance

Responsibilities

• Strategic Security Partnership: Act as a senior security engineer for the different product lines like Consumer, OTC. You will own the security gates for major feature releases and ensure security is integrated from the design phase. • Strategic Security Partnership: • Secure SDLC Operator: Operate and improve the secure development lifecycle. This includes orchestrating SAST/SCA/DAST, streamlining SARIF ingestion, PR review standards, CI/CD security automation, and vulnerability triage workflows. • Secure SDLC Operator: • AI-Driven SDLC Innovation: Research, architect, and safely embed cutting-edge AI utilities and Large Language Model (LLM) agents directly into our secure development lifecycle. • AI-Driven SDLC Innovation: • Threat Modelling & Architecture Reviews: Lead STRIDE/attack-tree threat models for sensitive flows including authentication, payment, custody, reconciliation and sign off on security architecture for critical designs. • Threat Modelling & Architecture Reviews: • Product Security Governance & Standards: Translate technical risks and regulatory demands into clear security policies. You will own the creation and upkeep of our Application Security Standards, reference architectures, and compliance-driven secure coding baselines. • Product Security Governance & Standards: • Bug Bounty Leadership: Oversee the technical triage and remediation strategy for our Bug Bounty program. You will turn external researcher findings into internal architectural hardening projects. • Bug Bounty Leadership: • Release Reviews: Perform deep-dive manual code reviews of security-sensitive Pull Requests, mentor engineers on secure coding patterns, and provide pragmatic remediation guidance. • Release Reviews: • Advanced Code Auditing: Conduct deep-dive manual and automated code reviews on highly sensitive Java and Kotlin backend Pull Requests. • Advanced Code Auditing: • Security Debt & Remediation Negotiation: Produce data-driven Security Debt packs and negotiate remediation into engineering roadmaps. You will negotiate remediation timelines with Product Owners and Engineering leadership, backed by risk-based data. • Security Debt & Remediation Negotiation: • Detection & Telemetry Integration: Define application runtime signals (business-logic anomalies, auth anomalies, reconciliation mismatches) and work with SecOps to instrument logs and alerts. • Detection & Telemetry Integration: • Testing & Automation: Build and maintain product-level test harnesses, fuzzing/property tests and CI checks to prevent regressions for business-critical flows. • Testing & Automation: • Incident Response Support: Provide product-level Incident Response expertise like test forensic runbooks, support reproduction of payment/settlement incidents, and advise on containment/remediation whenever needed. • Incident Response Support • Metrics & Risk Visibility: Define and own the Product Security metrics (e.g., MTTR for critical vulnerabilities, security debt burn-down, and defect density). You will translate these KPIs into high-level risk reports for the Head of Security and Engineering leadership to drive data-backed resourcing decisions. • Metrics & Risk Visibility: • People & Process: Coach junior product security engineers and security champions. You will assist the Product Security Lead to define hiring standards and capability plans. • People & Process: • Must-Haves • 4+ years total security engineering experience with at least 3+ years focused specially in application/product security or equivalent. • Experience with Web, Mobile, Cloud, Infrastructure Pentests and Red Teaming (e.g., phishing) • Proven track record of shipping security automation using CodeQL/GHAS, Snyk, or similar. You should be intimately familiar with the SARIF ecosystem and ASPM workflows. • Expert-level ability to audit and propose fixes in Kotlin/Java, TypeScript/JS, Python, and familiarity with containerised deployments (Kubernetes). • Strong threat modeling experience and pragmatic architecture guidance for high-stakes financial flows (AuthN/AuthZ, Cryptography, Payments). • Experience building CI checks, test harnesses and lightweight fuzzing/property tests. • Excellent stakeholder skills — able to negotiate remediation with Engineering Directors and Product owners, balancing security requirements with business velocity. • Nice-to-haves • Prior fintech/Trading/OTC product security experience or familiarity with custody/signing patterns. • Practical experience designing or deploying AI-assisted security tooling, leveraging LLMs for automated software patch generation, or evaluating vulnerability detection agents within enterprise developer pipelines. • Prior experience operating alongside GRC frameworks, authoring developer-facing security policies from scratch, and building automated policy-as-code gateway integrations. • Public track record of CVEs, security research, or open-source contributions to security tooling. • Advanced credentials such as OSCP, OSWE, CISSP or equivalent. • Experience with on-chain/off-chain integration, payment reconciliation, or smart contract security. • Familiarity with vulnerability management platforms (DefectDojo, Dependabot orchestration) and GRC/Gateway integrations. • Prior contributions to security automation and developer tooling (open source or internal).

Benefits

• Full-time salary based on experience and meaningful equity in an industry-leading company • This is a role based in our London office, with a mandatory in-office presence four days per week. • Work from Anywhere Policy: You can work remotely from anywhere in the world for up to 20 days per year. • Unlimited vacation policy; work hard and take time when you need it • Apple equipment • The opportunity to be a key player and build your career at a rapidly expanding, global technology company in an emerging field • Flexible work culture

Apply in one click

Upload My Resume

Drop here or click to browse · Tap to choose · PDF, DOCX, DOC, RTF, TXT

Apply in One Click
Apply in One Click

Similar roles

ChainguardChainguard - Senior Product Security Engineer1w ago
·Remote - United Kingdom·Equity
RemoteEMEASeniorCloud ComputingLogisticsSecurity EngineerSenior Product ManagerGoPythonKubernetesGCPAWSTektonPhoenix
9fin9fin - Senior Product Security Engineer2w ago
·London·$302k - $302k/year + Equity
In OfficeEMEASeniorCloud ComputingSecurity EngineerSenior Product ManagerAWSPythonPostgreSQL
Cherry Technologies, Inc.Cherry Technologies, Inc. - Senior Product Security Engineer1mo ago
·Remote - United States·Equity
RemoteNASeniorFintechPaymentsSecurity EngineerSenior Product ManagerPerformance ReviewsAWSPhoenix
fundingcirclefundingcircle - Senior Security Engineer4mo ago
·London, United Kingdom - Hybrid
In OfficeEMEASeniorFintechCybersecuritySecurity EngineerPythonAWSJenkinsKubernetes
finallyfinally - Senior Product Engineer1mo ago
·Remote - United States
RemoteNASeniorFintechPaymentsSenior Product ManagerReactPythonTypeScriptReportingClaude
light-inclight-inc - Bank Connectivity Engineer1w ago
·London·Equity
In OfficeEMEAMidBankingFintechSecurity EngineerProduct MarketingKotlinJavaPythonGoAWSDockerKubernetesDACH
Diligent CorporationDiligent Corporation - Senior Product Manager1w ago
·London, England, United Kingdom - Hybrid
In OfficeEMEASeniorFintechSenior Product ManagerB2BGovernance
TinesTines - Senior Product Security Engineer3w ago
·Remote - USA·$453k+/year + Equity
RemoteNASeniorCloud ComputingArtificial IntelligenceSecurity EngineerSenior Product ManagerRubyRustTypeScriptReportingAWS
TRM LabsTRM Labs - Senior Product Security Engineer3mo ago
·San Fracisco , California , United States·$215k - $230k/year + Equity
In OfficeNASeniorCryptocurrencyCloud ComputingSoftwareSecurity EngineerSenior Product ManagerReactAWSPythonReportingGCP

Browse more by category

Show 522 moreSecurity EngineerShow 712 moreSenior Product ManagerShow 1,848 moreJavaShow 433 moreKotlinShow 2,517 moreTypeScriptShow 6,338 morePythonShow 1,928 moreKubernetesShow 2,984 moreCoachingShow 419 morePerformance ReviewsShow 8,590 moreReporting
Privacy·Terms··Contact·FAQ·Wagey on X