Staff Security Engineer, Product Security

Remote Full-time
About Chainalysis
Blockchain technology is powering a growing wave of innovation. Businesses and governments around the world are using blockchains to make banking more efficient, connect with their customers, and investigate criminal cases. As adoption of blockchain technology grows, more and more organizations seek access to all this ecosystem has to offer. That’s where Chainalysis comes in. We provide complete knowledge of what’s happening on blockchains through our data, services, and solutions. With Chainalysis, organizations can navigate blockchains safely and with confidence.

About the Team
Product Security at Chainalysis keeps our SaaS platform — used by governments, banks, and crypto exchanges to investigate financial crime — secure by design. We partner directly with product and platform engineering on threat modeling, design reviews, penetration testing, and remediation of findings across our AWS and Kubernetes estate.

As a Staff Product Security Engineer, you'll be the technical lead for product security across one or more product areas. You'll run security reviews for new launches and AI tooling, perform hands-on pentests, ship code and fixes directly into product repos, own our Vulnerability Disclosure Program, and drive SOC2 and risk-framework work across R&D. You'll participate in a shared on-call rotation for production security incidents.

In this role, you’ll:
Lead Product Security across Chainalysis' SaaS offerings, partnering with product and platform engineering teams on design, code, and remediation

Own Unified Security Review process for new product launches, vendor evaluations, and AI tooling — including custom penetration tests scoped to each review

Drive Security Engineering Risk Management Framework, for consistent risk classification and remediation tracking across product

Lead the Vulnerability Disclosure Program and security bug reporting workflow, from researcher intake through fix

Drive SOC2 and compliance-related security remediation across product engineering, partnering with R&D leads on architectural fixes

Provide security review and guardrails for internal AI platforms and coding agents (LLM gateways, prompt/response controls, agent permissioning)

Participate in a shared on-call rotation for high-severity production security incidents

We’re looking for candidates who have:
8+ years of application security engineering experience

Strong production coding ability in at least one of Java (preferred), TypeScript/JavaScript, Python, or Go — enough to perform deep code review, write proof-of-concept exploits, and contribute fixes directly into product repos

Building security automation into CI/CD pipelines

Hands-on penetration testing of production SaaS applications, including custom tests scoped to new product launches

Threat modeling, secure design reviews, and static/dynamic code analysis across the SDLC

Identifying and remediating common web application vulnerabilities (OWASP Top 10)

Experience securing internal AI/LLM platforms and coding agents (model gateways, prompt/response controls, agent permissioning)

Nice to have experience:
Experience in Web3, Blockchain or Digital Assets

Experience building AI workflows, agents, and guardrailing

Technologies we use:
Cloud and containers: AWS, GCP, Kubernetes (EKS/GKE)

Infrastructure-as-Code: Terraform

Security tooling: Wiz, SonarCloud, Burp, Cloudflare

CI/CD and source control: GitHub, GitHub Actions, Artifactory and related build/deploy tooling

Languages and scripting: Java, JavaScript, Python, Go

AI Coding Agents, Tooling, Systems

About Chainalysis
Blockchain technology is powering a growing wave of innovation. Businesses and governments around the world are using blockchains to make banking more efficient, connect with their customers, and investigate criminal cases. As adoption of blockchain technology grows, more and more organizations seek access to all this ecosystem has to offer. That’s where Chainalysis comes in. We provide complete knowledge of what’s happening on blockchains through our data, services, and solutions. With Chainalysis, organizations can navigate blockchains safely and with confidence.

You belong here.
At Chainalysis, we believe that diversity of experience and thought makes us stronger. With both customers and employees around the world, we are committed to ensuring our team reflects the unique communities around us. We’re ensuring we keep learning by committing to continually revisit and reevaluate our diversity culture.
We encourage applicants across any race, ethnicity, gender/gender expression, age, spirituality, ability, experience and more. If you need any accommodations to make our interview process more accessible to you due to a disability, don't hesitate to let us know. You can learn more here. We can’t wait to meet you.

Apply To This Job
Apply Now →

Similar Jobs

Experienced Registered Behavior Technician for In-Home ABA Therapy - Atlanta, GA

Remote

Immediate Hiring: Experienced Registered Behavioral Technician (RBT) for Clinic-Based ABA Therapy Services

Remote

Experienced Registered Behavioral Technician (RBT) - ABA Therapy for Children with Autism Spectrum Disorder

Remote

Experienced Registered Nurse - Telehealth: Providing Remote Care Coordination and Patient Support

Remote

Experienced Substitute Teacher for Riverside County Schools - Join Scoot Education's Innovative Team

Remote

Experienced Substitute Teacher for San Bernardino County - Flexible Schedules & Competitive Pay

Remote

Experienced School Year Instructional Coach for High-Dosage Tutoring Programs in Edgewater Park, NJ

Remote

Experienced School Year Tutor for K-8 Students in Math and Literacy - Mickleton, NJ

Remote

Experienced Secondary Social Studies Teacher for Kansas - Flexible Hybrid Remote Arrangement

Remote

USPS Office Helper

Remote

Operations Assistant

Remote

B2B Business Developer, North America (f/m/d)

Remote

[Remote] Director, Business Development

Remote

**Experienced Data Entry Specialist – Remote Work Opportunity with arenaflex**

Remote

Entry-Level Tester (Remote)

Remote

**Job Title:** Psychic Tarot Chat Operators – Remote Positions at blithequark

Remote

Pediatric Radiologist 100 Peds in Vegas $650K+ Dream Gig

Remote

**Experienced Online Customer Service Specialist for Resorts - Remote Opportunity**

Remote

Associate Brand Manager, Expansion

Remote

Information Management Analyst, Data Enablement

Remote
← Back