Staff Security Engineer, Product Security

Chainalysis
United Kingdom
Last week
Job Type
Permanent
Work Pattern
Full-time
Work Location
Remote
Seniority
Senior
Education
Degree
Posted
20 May 2026 (Last week)

Benefits

Vulnerability Disclosure Program SOC2 Compliance On-call Rotation

About Chainalysis

Blockchain technology is powering a growing wave of innovation. Businesses and governments around the world are using blockchains to make banking more efficient, connect with their customers, and investigate criminal cases. As adoption of blockchain technology grows, more and more organizations seek access to all this ecosystem has to offer. That’s where Chainalysis comes in. We provide complete knowledge of what’s happening on blockchains through our data, services, and solutions. With Chainalysis, organizations can navigate blockchains safely and with confidence.

About the Team

Product Security at Chainalysis keeps our SaaS platform — used by governments, banks, and crypto exchanges to investigate financial crime — secure by design. We partner directly with product and platform engineering on threat modeling, design reviews, penetration testing, and remediation of findings across our AWS and Kubernetes estate.

As a Staff Product Security Engineer, you'll be the technical lead for product security across one or more product areas. You'll run security reviews for new launches and AI tooling, perform hands-on pentests, ship code and fixes directly into product repos, own our Vulnerability Disclosure Program, and drive SOC2 and risk-framework work across R&D. You'll participate in a shared on-call rotation for production security incidents.

In this role, you’ll:

  • Lead Product Security across Chainalysis' SaaS offerings, partnering with product and platform engineering teams on design, code, and remediation

  • Own Unified Security Review process for new product launches, vendor evaluations, and AI tooling — including custom penetration tests scoped to each review

  • Drive Security Engineering Risk Management Framework, for consistent risk classification and remediation tracking across product

  • Lead the Vulnerability Disclosure Program and security bug reporting workflow, from researcher intake through fix

  • Drive SOC2 and compliance-related security remediation across product engineering, partnering with R&D leads on architectural fixes

  • Provide security review and guardrails for internal AI platforms and coding agents (LLM gateways, prompt/response controls, agent permissioning)

  • Participate in a shared on-call rotation for high-severity production security incidents

We’re looking for candidates who have:

  • 8+ years of application security engineering experience

  • Strong production coding ability in at least one of Java (preferred), TypeScript/JavaScript, Python, or Go — enough to perform deep code review, write proof-of-concept exploits, and contribute fixes directly into product repos

  • Building security automation into CI/CD pipelines

  • Hands-on penetration testing of production SaaS applications, including custom tests scoped to new product launches

  • Threat modeling, secure design reviews, and static/dynamic code analysis across the SDLC

  • Identifying and remediating common web application vulnerabilities (OWASP Top 10)

  • Experience securing internal AI/LLM platforms and coding agents (model gateways, prompt/response controls, agent permissioning)

Nice to have experience:

  • Experience in Web3, Blockchain or Digital Assets

  • Experience building AI workflows, agents, and guardrailing

Technologies we use:

  • Cloud and containers: AWS, GCP, Kubernetes (EKS/GKE)

  • Infrastructure-as-Code: Terraform

  • Security tooling: Wiz, SonarCloud, Burp, Cloudflare

  • CI/CD and source control: GitHub, GitHub Actions, Artifactory and related build/deploy tooling

  • Languages and scripting: Java, JavaScript, Python, Go

  • AI Coding Agents, Tooling, Systems

About Chainalysis

Blockchain technology is powering a growing wave of innovation. Businesses and governments around the world are using blockchains to make banking more efficient, connect with their customers, and investigate criminal cases. As adoption of blockchain technology grows, more and more organizations seek access to all this ecosystem has to offer. That’s where Chainalysis comes in. We provide complete knowledge of what’s happening on blockchains through our data, services, and solutions. With Chainalysis, organizations can navigate blockchains safely and with confidence.

You belong here.

At Chainalysis, we believe that diversity of experience and thought makes us stronger. With both customers and employees around the world, we are committed to ensuring our team reflects the unique communities around us. We’re ensuring we keep learning by committing to continually revisit and reevaluate our diversity culture.

We encourage applicants across any race, ethnicity, gender/gender expression, age, spirituality, ability, experience and more. If you need any accommodations to make our interview process more accessible to you due to a disability, don't hesitate to let us know. You can learn more here. We can’t wait to meet you.

Related Jobs

View all jobs

Staff React Native Engineer - Pro

Kraken London, United Kingdom, United Kingdom
Remote

Staff Security Architect

Kraken London, United Kingdom, United Kingdom
Remote

Staff Product Designer - Consumer

Kraken London, United Kingdom, United Kingdom
Remote

Industry Insights

Discover insightful articles, industry insights, expert tips, and curated resources.

Where to Advertise Blockchain Jobs in the UK (2026 Guide)

Where to advertise blockchain jobs UK in 2026: the specialist boards, communities and channels that reach Web3, smart contract and protocol engineers. The candidate pool is global in outlook but concentrated in specific communities — protocol engineers, smart contract developers, DeFi specialists and Web3 product leaders who move between roles through networks and community channels as much as traditional job boards. General job boards reach a broad audience but lack the specificity that blockchain professionals expect. Specialist platforms, crypto-native communities and targeted outreach each serve a different part of the market. This guide, published by BlockchainJobs.uk, covers where to advertise blockchain roles in the UK in 2026, how the main platforms compare, what employers should expect to pay, and what the data says about hiring across different role types.

Blockchain Jobs UK 2026: What to Expect Over the Next 3 Years

Blockchain Jobs UK 2026: roles, salaries and the Web3, DeFi and tokenisation hiring trends shaping UK blockchain careers over the next three years. Blockchain is creating jobs in places nobody predicted three years ago. What began as infrastructure for cryptocurrency is now embedded in financial services, supply chain management, digital identity, healthcare records, and the emerging architecture of tokenised assets. The roles being hired for today bear little resemblance to the developer-heavy, crypto-native job adverts that defined the sector's early years. For job seekers, this is both the complexity and the opportunity of building a blockchain career in 2026. The sector has matured beyond its speculative phase and into serious institutional adoption — and that shift has fundamentally changed what employers are looking for, where the jobs are, and which skills command a premium. The candidates who will thrive over the next three years aren't necessarily those who got in earliest or who can recite the Bitcoin whitepaper from memory. They're the ones who understand where enterprise blockchain, decentralised finance, digital assets regulation, and Web3 infrastructure are heading — and who are building their skills accordingly. This article breaks down what the UK blockchain jobs market is likely to look like through to 2028 — covering the titles emerging right now, the technologies driving employer demand, the skills that will matter most, and how to position your career ahead of the next wave rather than behind it.