Staff Application Security Engineer in London

Staff Application Security Engineer in London

London Full-Time Home office (partial)
B

At a Glance

  • Tasks: Lead the charge in building a robust application security program from scratch.
  • Company: Join Bitwise, a pioneering firm at the forefront of the crypto revolution.
  • Benefits: Enjoy competitive salary, equity options, unlimited PTO, and comprehensive health benefits.
  • Other info: Be part of a dynamic team with excellent growth opportunities and a vibrant culture.
  • Why this job: Make a real impact in the booming crypto space while shaping security practices.
  • Qualifications: 7+ years in application security with hands-on experience in SAST and DAST tools.

It’s rare that a new asset class is born. Nevertheless, we’re witnessing exactly that with the rise of crypto. Over just the last few years, since Bitwise was founded, crypto has evolved from an embryonic $50B market to a growing $3T+ juggernaut. This is an exciting moment for Bitwise as a firm. For eight years, we have established a track record of excellence managing a broad suite of index and active solutions across ETFs, separately managed accounts, private funds, institutional staking, and hedge fund strategies. This year, we crossed $15B in client assets and are growing quickly. Thousands of financial advisors, family offices, and institutional investors partner with Bitwise to understand and access the opportunities in crypto. We are known for providing unparalleled client support through expert research and commentary, a nationwide client team of crypto specialists, and deep access to the crypto ecosystem. Currently, Bitwise is a close-knit team of 100+ global professionals. Think of us as a mix of an asset manager and a tech start‑up. We’re backed by some of the most accomplished investors in venture capital and veterans of the financial services world. We love working together, we love what we do, and we’re excited about what’s ahead.

About The Role

Our engineering organization is growing, and with that growth comes an expanding application and infrastructure footprint that requires dedicated application security ownership. This role exists to build that function from the ground up. As our first dedicated Staff Application Security Engineer, you will own the design and implementation of our application security program, from SAST and DAST tooling to secure SDLC practices, threat modeling, dependency security, and penetration testing coordination. You will work directly with engineering teams across a cloud‑based environment securing both customer‑facing products and internal systems. You will be reporting directly to the Head of Security and will have the autonomy and organizational support to build an application security program that is practical, scalable, and aligned to the risk profile of a company operating in the digital asset space.

Primary Responsibilities

  • Static & Dynamic Application Security Testing (SAST / DAST)
    • Own the full implementation of SAST tooling across all codebases and CI/CD pipelines
    • Own the full implementation of DAST tooling across all customer‑facing and internal applications
    • Establish baseline findings, prioritize remediation, and work directly with engineering to resolve issues
    • Maintain and tune tooling over time as the codebase and attack surface evolve
  • Secure SDLC & Code Integrity
    • Define and enforce a secure software development lifecycle across engineering teams
    • Establish secure release processes including code signing and build integrity verification
    • Develop and maintain security standards, guidelines, and secure coding practices
    • Integrate security checkpoints throughout the development pipeline without creating unnecessary friction for engineering
  • Threat Modeling
    • Lead threat modeling exercises for new infrastructure designs, features, and system changes
    • Ensure all customer‑facing and internal applications are fully documented and threat modeled
    • Maintain a living inventory of the company’s attack surface and ensure it reflects current architecture
    • Apply blockchain‑specific threat modeling to smart contracts, bridge infrastructure, and custody‑adjacent systems, including multi‑sig signing flows and on‑chain/off‑chain trust boundaries
  • Dependency & Supply Chain Security
    • Implement and manage dependency scanning across all projects
    • Enforce version pinning policies to reduce exposure from uncontrolled dependency updates
    • Deploy and manage supply chain security tooling (e.g., Socket.dev or equivalent) to monitor for malicious or compromised dependencies
    • Establish a process for ongoing dependency review and remediation
  • Penetration Testing
    • Define and maintain a penetration testing program covering all surface areas — applications, APIs, internal tooling, and infrastructure
    • Scope, schedule, and manage third‑party penetration testing engagements
    • Track findings through to remediation and validate fixes
  • Secrets Management
    • Design and implement a secrets management program across cloud infrastructure and engineering workflows
    • Eliminate hardcoded credentials and secrets from codebases
    • Establish policies and tooling for secrets rotation, access control, and audit logging
  • Fuzzing & Attack Surface Coverage
    • Implement fuzz testing across applicable components, particularly APIs and input‑handling logic
    • Ensure coverage gaps in the attack surface are identified, documented, and addressed systematically

Role Requirements

  • 7+ years of experience in application security or a closely related discipline
  • Demonstrated experience building or significantly maturing an application security program
  • Deep hands‑on experience with SAST and DAST tooling implementation and management
  • Strong knowledge of secure SDLC practices and CI/CD pipeline security integration
  • Experience with dependency scanning and software supply chain security
  • Proficiency in threat modeling methodologies (STRIDE, PASTA, or equivalent)
  • Experience managing or coordinating third‑party penetration testing engagements
  • Solid understanding of secrets management solutions (e.g., HashiCorp Vault, AWS Secrets Manager, or equivalent)
  • Strong written and verbal communication skills — able to document findings and present risk clearly to both technical and non‑technical audiences
  • Demonstrated experience securing blockchain‑connected systems, including smart contract security review, multi‑sig wallet architectures, and cross‑chain bridge protocols
  • Working familiarity with common DeFi attack surfaces

What We Offer

  • Compensation: $185,000 to $260,000 + Equity
  • Equity compensation as a component of all offers
  • Health insurance, including dental and vision plans
  • Health, Dependent Care and Commuter Flexible Spending Accounts
  • Paid Parental Leave
  • Life insurance; short‑and long‑term disability plans
  • Company‑funded 401(k) plan, no matching required
  • Unlimited PTO
  • 10 paid company‑wide holidays
  • Company‑wide winter break for most roles
  • Office spaces in San Francisco, New York, and London
  • Meals and snacks provided in office
  • Paid company cell phone or stipend
  • Bitwise “Buddy” Program (30‑day new‑hire success program)
  • Annual anniversary gifts
  • Company‑wide events including annual holiday party
  • Internal Women of Bitwise (WOB) group with fun events

Our Values

  • Create “a ha” moments
  • Move fast, with informed rationale
  • Ask “What would the client want?”
  • Show gratitude

Your Interview Process

  • Recruiter Interview
  • Hiring Manager Interview
  • Work Sample
  • Meeting the Team
  • Executive/Founders Interview
  • References
  • Offer!

Bitwise is an equal opportunity employer. We are committed to building a team of people with a variety of backgrounds, perspectives, and skills. It is the policy of Bitwise to ensure equal opportunity. All candidates are considered without regard to race, color, religion, national origin, age, sex, sexual orientation, gender identity, marital status, ancestry, physical or mental disability, veteran status, or any other legally protected characteristics. Pursuant to the San Francisco Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records. Please note that we do not sponsor visas for persons without work authorization in the United States. This role is for full‑time employees only (no B2B or contractors). Thank you!

The Pay Range For This Role Is

  • 185,000 - 260,000 USD per year (Remote)
  • 185,000 - 260,000 USD per year (NYC Office)
  • 185,000 - 260,000 USD per year (SF Office)
  • 185,000 - 260,000 USD per year (London Office)

Staff Application Security Engineer in London employer: Bitwise Asset Management

Bitwise is an exceptional employer, offering a dynamic work environment that blends the agility of a tech start-up with the stability of an established asset manager. Employees benefit from competitive compensation, unlimited PTO, and a strong focus on professional growth through initiatives like the Bitwise 'Buddy' Program and internal groups such as Women of Bitwise. With offices in major cities like San Francisco, New York, and London, team members enjoy a collaborative culture that values diverse perspectives and fosters innovation in the rapidly evolving crypto landscape.

B

Contact Detail:

Bitwise Asset Management Recruiting Team

StudySmarter Expert Advice🤫

We think this is how you could land Staff Application Security Engineer in London

Tip Number 1

Network like a pro! Reach out to folks in the crypto and application security space on LinkedIn. Join relevant groups, attend meetups, and don’t be shy about asking for informational interviews. You never know who might have the inside scoop on job openings!

Tip Number 2

Show off your skills! Create a portfolio that highlights your experience with SAST, DAST, and secure SDLC practices. Include case studies or projects where you’ve made a real impact. This will help you stand out when chatting with potential employers.

Tip Number 3

Prepare for those interviews! Research Bitwise and understand their approach to application security. Be ready to discuss how you can build and scale their security program. Practise common interview questions and think of examples that showcase your expertise.

Tip Number 4

Apply through our website! It’s the best way to ensure your application gets seen by the right people. Plus, it shows you’re genuinely interested in joining the team at Bitwise. Don’t miss out on this opportunity!

We think you need these skills to ace Staff Application Security Engineer in London

SAST Tooling Implementation
DAST Tooling Implementation
Secure Software Development Lifecycle (SDLC)
Threat Modeling Methodologies (STRIDE, PASTA)
Dependency Scanning
Software Supply Chain Security
Penetration Testing Coordination

Some tips for your application 🫡

Tailor Your Application:Make sure to customise your application to highlight how your skills and experiences align with the role of Staff Application Security Engineer. We want to see how you can contribute to our mission in the crypto space!

Showcase Your Experience:Don’t hold back on sharing your hands-on experience with SAST, DAST, and secure SDLC practices. We love seeing concrete examples of how you've built or matured application security programs in the past.

Be Clear and Concise:When writing your application, keep it clear and to the point. We appreciate well-structured responses that get straight to the heart of your qualifications and how they relate to our needs.

Apply Through Our Website:We encourage you to apply directly through our website. It’s the best way for us to receive your application and ensures you’re considered for this exciting opportunity at Bitwise!

How to prepare for a job interview at Bitwise Asset Management

Know Your Stuff

Make sure you brush up on your application security knowledge, especially around SAST and DAST tooling. Be ready to discuss your hands-on experience and how you've implemented these tools in past roles. This will show that you’re not just familiar with the concepts but have practical experience too.

Showcase Your Problem-Solving Skills

Prepare to talk about specific challenges you've faced in application security and how you tackled them. Use examples that highlight your ability to lead threat modelling exercises or manage penetration testing engagements. This will demonstrate your critical thinking and problem-solving skills.

Understand the Company’s Needs

Research Bitwise and its approach to crypto and application security. Familiarise yourself with their products and the unique challenges they face in the digital asset space. Tailor your answers to show how your skills can directly benefit their operations and align with their values.

Communicate Clearly

Practice explaining complex security concepts in simple terms. You’ll need to communicate effectively with both technical and non-technical audiences. Being able to document findings and present risks clearly is crucial, so think of ways to convey your ideas succinctly during the interview.