Senior Product Security Engineer - Blockchain at Blockchain · Web3Vacancy
Jobs Companies Talent Pool For recruiters Blog About Contact
Find Talent Post a Vacancy
2,400+ jobs from 680+ companies · Updated daily

Web3 Jobs & Crypto Jobs Where crypto teams hire. Where builders get found.

The #1 crypto-native job board for web3 jobs, crypto jobs & blockchain vacancies. Every role in the ecosystem — dev, design, marketing & more. Remote-first at top protocols, DAOs & companies.

Analysing Your CV...
Extracting your experience, skills, and details...
Web3 candidate
Web3 candidate
Web3 candidate
Web3 candidate
Web3 candidate
5,000+ web3 builders · 680+ companies hiring
Hiring in web3?
Post a vacancy. Reach the largest crypto-native talent pool — live in 24h.
Browse Talent Pool →
5,000+ vetted builders · open to work
Rather search yourself?
Browse the talent pool — filter crypto-native candidates and reach out direct.
Web3 talent
Web3 talent
Web3 talent
Web3 talent
Web3 talent
500+Open Jobs
680+Companies
$180kAvg Salary
94%Remote Roles
Category
Role Type

Latest Crypto Job Vacancies

10 jobs found

Senior Product Security Engineer - Blockchain

Remote
Join Talent Pool
About this role

Join Blockchain as a Senior Product Security Engineer to enhance security across their product lines, ensuring safe development practices and leading security initiatives.

Description

Senior Product Security Engineer - Blockchain

Company: Blockchain

Location: London, GB (Remote)

Employment Type: Full-time

About the Company

Blockchain is connecting the world to the future of finance. As the most trusted and fastest-growing global crypto company, it helps millions of people worldwide safely access cryptocurrency. Since its inception in 2011, Blockchain has earned the trust of over 90 million wallet holders and more than 40 million verified users, facilitating over $1 trillion in crypto transactions.

About the Role

You will operate the Product Security programme for Blockchain.com's internally-developed products across Consumer, OTC and MRE lines. This is a senior, hands-on role where you'll design and run the secure development lifecycle, lead threat modeling and architecture review, own the security debt lifecycle for product engineering teams, and architect the automated pipelines that protect billions in transaction volume. You will embed with product and engineering teams, convert technical findings into business-prioritized remediation, and lift developer capabilities so security is delivered by code and process.

What You'll Do

  • Act as a senior security engineer for different product lines like Consumer and OTC, owning the security gates for major feature releases and ensuring security is integrated from the design phase
  • Operate and improve the secure development lifecycle, including orchestrating SAST/SCA/DAST, streamlining SARIF ingestion, PR review standards, CI/CD security automation, and vulnerability triage workflows
  • Research, architect, and safely embed cutting-edge AI utilities and Large Language Model (LLM) agents directly into the secure development lifecycle
  • Lead STRIDE/attack-tree threat models for sensitive flows including authentication, payment, custody, reconciliation and sign off on security architecture for critical designs
  • Translate technical risks and regulatory demands into clear security policies, owning the creation and upkeep of Application Security Standards, reference architectures, and compliance-driven secure coding baselines
  • Oversee the technical triage and remediation strategy for the Bug Bounty program, turning external researcher findings into internal architectural hardening projects
  • Perform deep-dive manual code reviews of security-sensitive Pull Requests, mentor engineers on secure coding patterns, and provide pragmatic remediation guidance
  • Conduct deep-dive manual and automated code reviews on highly sensitive Java and Kotlin backend Pull Requests
  • Produce data-driven Security Debt packs and negotiate remediation into engineering roadmaps with Product Owners and Engineering leadership
  • Define application runtime signals (business-logic anomalies, auth anomalies, reconciliation mismatches) and work with SecOps to instrument logs and alerts
  • Build and maintain product-level test harnesses, fuzzing/property tests and CI checks to prevent regressions for business-critical flows
  • Provide product-level Incident Response expertise including test forensic runbooks, support reproduction of payment/settlement incidents, and advise on containment/remediation
  • Define and own Product Security metrics (e.g., MTTR for critical vulnerabilities, security debt burn-down, and defect density), translating these KPIs into high-level risk reports for leadership
  • Coach junior product security engineers and security champions, assisting in defining hiring standards and capability plans

Requirements

Must-Haves

  • 4+ years total security engineering experience with at least 3+ years focused specially in application/product security or equivalent
  • Experience with Web, Mobile, Cloud, Infrastructure Pentests and Red Teaming (e.g., phishing)
  • Proven track record of shipping security automation using CodeQL/GHAS, Snyk, or similar, with intimate familiarity with the SARIF ecosystem and ASPM workflows
  • Expert-level ability to audit and propose fixes in Kotlin/Java, TypeScript/JS, Python, and familiarity with containerised deployments (Kubernetes)
  • Strong threat modeling experience and pragmatic architecture guidance for high-stakes financial flows (AuthN/AuthZ, Cryptography, Payments)
  • Experience building CI checks, test harnesses and lightweight fuzzing/property tests
  • Excellent stakeholder skills — able to negotiate remediation with Engineering Directors and Product owners, balancing security requirements with business velocity

Nice-to-Haves

  • Prior fintech/Trading/OTC product security experience or familiarity with custody/signing patterns
  • Practical experience designing or deploying AI-assisted security tooling, leveraging LLMs for automated software patch generation, or evaluating vulnerability detection agents within enterprise developer pipelines
  • Prior experience operating alongside GRC frameworks, authoring developer-facing security policies from scratch, and building automated policy-as-code gateway integrations
  • Public track record of CVEs, security research, or open-source contributions to security tooling
  • Advanced credentials such as OSCP, OSWE, CISSP or equivalent
  • Experience with on-chain/off-chain integration, payment reconciliation, or smart contract security
  • Familiarity with vulnerability management platforms (DefectDojo, Dependabot orchestration) and GRC/Gateway integrations
  • Prior contributions to security automation and developer tooling (open source or internal)

Compensation & Benefits

  • Full-time salary based on experience and meaningful equity in an industry-leading company
  • Mandatory in-office presence four days per week at London office
  • Work from Anywhere Policy: You can work remotely from anywhere in the world for up to 20 days per year
  • ClassPass
  • Unlimited vacation policy
  • Apple equipment
  • Opportunity to be a key player and build your career at a rapidly expanding, global technology company in an emerging field
  • Flexible work culture
Conditions & Benefits

COMPENSATION & PERKS

  • Full-time salary based on experience and meaningful equity in an industry-leading company.
  • This is a role based in our London office, with a mandatory in-office presence four days per week.
  • Work from Anywhere Policy: You can work remotely from anywhere in the world for up to 20 days per year.
  • ClassPass - Unlimited vacation policy; work hard and take time when you need it.
  • Apple equipment.
  • The opportunity to be a key player and build your career at a rapidly expanding, global technology company in an emerging field.
  • Flexible work culture.
Job Details
LocationRemote
AI Score★★★★★★★★☆☆ 8/10
PostedJun 25, 2026 (2h ago)
Tags & Skills
cryptofintechsecurityweb3Otherremote
Tech Stack
security engineeringapplication securityKotlinJavaTypeScriptPythonKubernetesAIthreat modelingCI/CDvulnerability management
Don't just browse — get discovered
Drop your CV — AI builds your profile
Drag & drop or click · PDF only · 60 seconds
Upload CV
3-5d avg. to first message · 320+ hires made
No applications — teams find and message you directly
★★★★★Alex K. @ Aave

3 DeFi teams messaged me in 5 days

★★★★★Sarah M. @ Arbitrum

AI profile matched me perfectly

★★★★★James L. @ OpenZeppelin

2 interviews in my first week

★★★★★Maria V. @ Chainlink

Hired in 9 days, no cold apps

★★★★★Tom W. @ Polygon

Best web3 board, period

★★★★★Alex K. @ Aave

3 DeFi teams messaged me in 5 days

★★★★★Sarah M. @ Arbitrum

AI profile matched me perfectly

★★★★★James L. @ OpenZeppelin

2 interviews in my first week

★★★★★Maria V. @ Chainlink

Hired in 9 days, no cold apps

★★★★★Tom W. @ Polygon

Best web3 board, period

★★★★★David R. @ Solana

CV to offer in 11 days

★★★★★Nina T. @ MakerDAO

DAO found me, not the other way

★★★★★Chris P. @ Uniswap

Passive search actually works here

★★★★★Lena K. @ dYdX

Got 5 messages in first week

★★★★★Omar S. @ Optimism

Only board I recommend now

★★★★★David R. @ Solana

CV to offer in 11 days

★★★★★Nina T. @ MakerDAO

DAO found me, not the other way

★★★★★Chris P. @ Uniswap

Passive search actually works here

★★★★★Lena K. @ dYdX

Got 5 messages in first week

★★★★★Omar S. @ Optimism

Only board I recommend now

"Best talent pool in web3. We filled 3 senior Solidity roles in under 2 weeks — candidates were pre-vetted and ready."
Jessica H. Head of Talent · Aave
"We stopped posting on LinkedIn. Web3Vacancy talent pool is where the real crypto-native builders are."
Daniel M. VP Engineering · Arbitrum

Similar Web3 Jobs

Browse Crypto Job Vacancies

The #1 Web3 Job Board for Crypto Jobs & Blockchain Careers

Web3Vacancy is the leading web3 job board for blockchain developers, DeFi engineers, smart contract auditors, NFT product managers, DAO operators, ZK researchers, and Web3 growth leads. We aggregate 2,400+ remote-first crypto jobs from top protocols, decentralized exchanges, layer-2 networks, AI-blockchain startups, and Web3 studios worldwide. Whether you are hiring or looking for your next blockchain job, Web3Vacancy is the go-to job board for the decentralized economy.

Find web3 jobs across every skill level and specialization. Solidity developers, Rust engineers, Move programmers, ZK circuit engineers, tokenomics designers, crypto legal counsel, Web3 community managers, and blockchain data analysts all find their next role here. New crypto job listings are added daily across Ethereum, Solana, Polygon, Arbitrum, Base, Cosmos, Sui, Aptos, and every emerging blockchain ecosystem.

Looking to start a web3 career? Explore our guides on web3 salaries, blockchain interview questions, and the top web3 companies hiring in 2026. New to blockchain? Start with our What Is Web3 guide and learn web3 development from scratch. Employers can post a web3 job or browse our web3 talent pool to hire blockchain developers directly.