Frequently asked questions
Is this job still open?
GMI Jobs is currently showing this Senior Product Security Engineer role at Blockchain.com as an active listing from employer-controlled hiring sources. Always confirm final availability on the employer application page before applying.
How do I apply for this role?
Use the application link on this page to apply directly with Blockchain.com. GMI Jobs keeps the canonical job page, company context, and market links together so candidates can compare before leaving the site.
What should I compare before applying?
Compare the role location London, any listed pay signal, company profile, related crypto jobs, and salary context before applying. Listed pay signals are not guaranteed offers; confirm compensation with the employer.
Job Description
<div class="content-intro"><p><strong>Blockchain</strong> is connecting the world to the future of finance. As the most trusted and fastest-growing global crypto company, it helps millions of people worldwide safely access cryptocurrency. Since its inception in 2011, Blockchain has earned the trust of over 90 million wallet holders and more than 40 million verified users, facilitating over $1 trillion in crypto transactions.</p></div><p>You will operate the Product Security programe for Blockchain.com’s internally-developed products across Consumer, OTC and MRE lines. This is a senior, hands-on role: you’ll design and run the secure development lifecycle, lead threat modeling and architecture review, own the security debt lifecycle for product engineering teams, and architect the automated pipelines that protect billions in transaction volume. You will embed with product and engineering teams, convert technical findings into business-prioritized remediation, and lift developer capabilities so security is delivered by code and process.</p> <p><strong>WHAT YOU WILL DO</strong></p> <ul> <li><strong>Strategic Security Partnership:</strong> Act as a senior security engineer for the different product lines like Consumer, OTC. You will own the security gates for major feature releases and ensure security is integrated from the design phase.</li> <li><strong>Secure SDLC Operator:</strong> Operate and improve the secure development lifecycle. This includes orchestrating SAST/SCA/DAST, streamlining SARIF ingestion, PR review standards, CI/CD security automation, and vulnerability triage workflows.</li> <li><strong>AI-Driven SDLC Innovation:</strong> Research, architect, and safely embed cutting-edge AI utilities and Large Language Model (LLM) agents directly into our secure development lifecycle.</li> <li><strong>Threat Modelling &amp; Architecture Reviews:</strong> Lead STRIDE/attack-tree threat models for sensitive flows including authentication, payment, custody, reconciliation and sign off on security architecture for critical designs.</li> <li><strong>Product Security Governance &amp; Standards:</strong> Translate technical risks and regulatory demands into clear security policies. You will own the creation and upkeep of our Application Security Standards, reference architectures, and compliance-driven secure coding baselines.</li> <li><strong>Bug Bounty Leadership:</strong> Oversee the technical triage and remediation strategy for our Bug Bounty program. You will turn external researcher findings into internal architectural hardening projects.</li> <li><strong>Release Reviews:</strong> Perform deep-dive manual code reviews of security-sensitive Pull Requests, mentor engineers on secure coding patt