At a Glance
- Tasks: Secure off-chain trading processes and infrastructure for our institutional business.
- Company: Join a leading global crypto company transforming finance.
- Benefits: Competitive salary, flexible work options, and opportunities for growth.
- Other info: Diverse and inclusive workplace committed to equal opportunities.
- Why this job: Make a real impact in the fast-paced world of cryptocurrency security.
- Qualifications: 5+ years in security engineering with expertise in threat modelling.
The predicted salary is between 80000 - 100000 £ per year.
Blockchain is connecting the world to the future of finance. As the most trusted and fastest-growing global crypto company, it helps millions of people worldwide safely access cryptocurrency. Since its inception in 2011, Blockchain has earned the trust of over 90 million wallet holders and more than 40 million verified users, facilitating over $1 trillion in crypto transactions.
You’ll be the hands-on security engineer embedded with the Institutional Trading and Financial Operations (FinOps) team. Your focus is the secure operation of off-chain trading processes and infrastructure that empowers our institutional business: integrations, signing flows, key custody interfaces, middle-office workflows, order routing and settle pipelines that handle significant capital. You will support risk assessments, operating controls, automation to detect operational anomalies and remediation coordination. This is a high-visibility role where you will focus on operational security engineering - ensuring that the tools and processes our traders use are resilient against both external threats and internal errors. This role does not require smart-contract auditing.
WHAT YOU WILL DO
- Partner with Trading, Middle Office and Quant (Institutional FinOps) teams to map out inventory trading systems, data flows, third-party integrations and custody/settlement touchpoints.
- Conduct deep-dive assessments mapping critical assets and workflows to identify structural vulnerabilities.
- You will be responsible for defining the Target State and drafting the strategic Risk Treatment Plans (RTP) required to meet institutional-grade standards (e.g., CCSS, NIST, DORA).
- Act as the primary security liaison for Senior Management and third-party vendors.
- You will translate complex technical gaps into actionable business risk summaries, drive vendor evaluations for core security infrastructure, and manage the project lifecycle for high-impact posture uplifts.
- Implement and maintain monitoring for FinOps-specific security signals such as abnormal order patterns, signature misuse, unusual settlements.
- You will integrate these signals into our SIEM/SOAR for real-time response.
- Support secrets and key-management hygiene.
- You will ensure app/service keys are stored in KMS/Vault, scoped to least privilege and rotated automatically to prevent credential leakage.
- Assist product security in triage of SAST/SCA findings for FinOps-related repositories.
- You will help implement CI checks and remediation playbooks.
- Participate in incident exercises, post-incident reviews and remediation tracking for trading incidents.
- Document controls and produce concise risk summaries for FinOps leads and the Security.
WHAT YOU WILL NEED
- 5+ years in security engineering, platform security, or application security experience.
- Proven expertise in Threat Modeling.
- Ability to perform structured reviews (e.g., STRIDE) of complex data flows and operational processes.
- Experience with observability and detection tooling (SIEM, logs, metrics) and ability to write basic detection rules.
- Practical experience with KMS/HSM, secrets management platforms (Vault, 1Password, AWS/GCP KMS), IAM patterns and least-privilege.
- Exceptional ability to translate 'Technical Debt' into Business Risk for C-suite stakeholders (CFO, CTO, Head of Trading).
- Ability to raise, read and audit Pull Requests in at least one language used in our stack (TypeScript, Java/Kotlin, Python).
- Experience conducting technical due diligence and scoping for third-party security integrations.
NICE TO HAVE
- Familiarity with trading systems or financial operations (market-making, execution, settlement) or close collaboration background with trading/quant teams.
- Exposure to blockchain on-chain concepts (wallets, addresses, transactions) but no requirement to audit contracts.
- Familiarity with SOC operations, and post-incident forensic analysis.
- Familiarity with SOC2, ISO 27001, or financial audit requirements.
- Any relevant industry certification.
Blockchain is committed to diversity and inclusion in the workplace and is proud to be an equal opportunity employer. We prohibit discrimination and harassment of any kind based on race, religion, color, national origin, gender, gender expression, sex, sexual orientation, age, marital status, veteran status, disability status or any other characteristic protected by law.
Crypto Security Engineer in London employer: Blockchain.com
Contact Detail:
Blockchain.com Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Crypto Security Engineer in London
✨Tip Number 1
Network like a pro! Reach out to folks in the crypto and security space on LinkedIn or at industry events. A friendly chat can open doors that a CV just can't.
✨Tip Number 2
Show off your skills! Create a portfolio or GitHub repo showcasing your projects, especially those related to security engineering. This gives potential employers a taste of what you can do.
✨Tip Number 3
Prepare for interviews by brushing up on common security scenarios and how you'd tackle them. Think about how you’d explain complex concepts to non-techies – clarity is key!
✨Tip Number 4
Don't forget to apply through our website! It’s the best way to ensure your application gets seen by the right people. Plus, we love seeing candidates who are proactive!
We think you need these skills to ace Crypto Security Engineer in London
Some tips for your application 🫡
Tailor Your CV: Make sure your CV is tailored to the Crypto Security Engineer role. Highlight your relevant experience in security engineering and any specific skills that match the job description, like threat modelling or KMS expertise.
Craft a Compelling Cover Letter: Your cover letter is your chance to shine! Use it to explain why you're passionate about crypto security and how your background makes you a perfect fit for our team. Keep it concise but impactful!
Showcase Your Technical Skills: Don’t forget to showcase your technical skills in your application. Mention any experience with SIEM tools, secrets management platforms, or programming languages relevant to our stack. We love seeing practical examples!
Apply Through Our Website: We encourage you to apply through our website for the best chance of getting noticed. It’s straightforward and ensures your application goes directly to us. Plus, we can’t wait to see what you bring to the table!
How to prepare for a job interview at Blockchain.com
✨Know Your Stuff
Make sure you brush up on your security engineering knowledge, especially around threat modelling and risk assessments. Familiarise yourself with the specific tools and technologies mentioned in the job description, like KMS/HSM and SIEM systems. This will help you speak confidently about your experience and how it relates to the role.
✨Understand the Business
It's crucial to translate technical concepts into business risks, especially for C-suite stakeholders. Prepare examples of how you've done this in the past, focusing on how your work has impacted the bottom line or improved operational security. This will show that you understand the bigger picture.
✨Prepare for Technical Questions
Expect to dive deep into your technical expertise during the interview. Be ready to discuss structured reviews like STRIDE and how you've applied them in real-world scenarios. Practising coding questions or pull request audits in languages relevant to the role can also give you an edge.
✨Show Your Collaborative Side
This role involves working closely with various teams, so be prepared to discuss your experience collaborating with trading, quant, or middle office teams. Share specific examples of how you've successfully partnered with others to achieve security goals, as this will highlight your teamwork skills.