Senior Product Security Engineer @Blockchain

    11 days ago·Blockchain is hiring a Senior Product Security Engineer·📍 France

    Overview

    The role involves operating the Product Security program for Blockchain.com’s internally-developed products across Consumer, OTC, and MRE lines. This senior, hands-on position focuses on designing and managing the secure development lifecycle, leading threat modeling, and architecting automated pipelines to enhance security in product engineering.

    Key Responsibilities

    • Act as a senior security engineer for multiple product lines, ensuring security integration from the design phase.
    • Operate and improve the secure development lifecycle, including SAST/SCA/DAST orchestration and CI/CD security automation.
    • Research and embed AI utilities and LLM agents into the secure development lifecycle.
    • Lead threat modeling and architecture reviews for sensitive processes like authentication and payment flows.
    • Translate risks and regulatory demands into security policies and maintain Application Security Standards.
    • Oversee the technical triage and remediation strategy for the Bug Bounty program.
    • Conduct manual code reviews of security-sensitive Pull Requests and mentor engineers on secure coding practices.
    • Negotiate security debt and remediation timelines with Product Owners and Engineering leadership.
    • Define application runtime signals and work with SecOps on logging and alerts.
    • Build and maintain product-level test harnesses, fuzzing tests, and CI checks.
    • Provide product-level Incident Response expertise and support.
    • Define and manage Product Security metrics for reporting to leadership.
    • Coach junior security engineers and assist in defining hiring standards.

    Requirements

    Must-Haves

    • 4+ years of security engineering experience, with at least 3+ years in application/product security.
    • Experience with web, mobile, cloud, and infrastructure pentests.
    • Proven ability to implement security automation using tools like CodeQL/GHAS or Snyk.
    • Expertise in auditing Kotlin/Java, TypeScript/JS, Python, and familiarity with Kubernetes.
    • Strong threat modeling experience, particularly in high-stakes financial flows.
    • Experience building CI checks and test harnesses.
    • Excellent stakeholder negotiation skills.

    Nice-to-Haves

    • Prior fintech or trading security experience.
    • Experience designing AI-assisted security tooling.
    • Familiarity with GRC frameworks and authoring security policies.
    • Public track record of CVEs or contributions to security tooling.
    • Advanced security credentials like OSCP, OSWE, or CISSP.
    • Knowledge of smart contract security and payment reconciliation.

    Benefits

    • Unlimited vacation policy.
    • Unlimited books policy.
    • Provision of Apple equipment.
    • Full-time salary based on experience and equity options.
    • Mandatory in-office presence four days per week with a work-from-anywhere policy for up to 20 days per year.

    Location

    Role based in Paris office with mandatory in-office presence four days per week; remote work from anywhere for up to 20 days per year.

    How to Apply

    Please apply through the designated application process on the company’s careers page.

    Deadline

    No specific deadline mentioned.

    Get jobs in your inbox

    Join over 10,000 subscribers receiving our weekly newsletter.