Staff Security Engineer, Product Security

Staff Security Engineer, Product Security

Full-Time 80000 - 100000 € / year (est.) Home office (partial)
Chainalysis

At a Glance

  • Tasks: Lead product security for innovative SaaS offerings and conduct hands-on penetration testing.
  • Company: Join Chainalysis, a leader in blockchain technology and financial crime investigation.
  • Benefits: Competitive salary, diverse team culture, and opportunities for professional growth.
  • Other info: Dynamic work environment with a commitment to diversity and inclusion.
  • Why this job: Make a real impact in securing cutting-edge blockchain solutions and AI tools.
  • Qualifications: 8+ years in application security with strong coding skills in Java or similar languages.

The predicted salary is between 80000 - 100000 € per year.

About Chainalysis: Blockchain technology is powering a growing wave of innovation. Businesses and governments around the world are using blockchains to make banking more efficient, connect with their customers, and investigate criminal cases. As adoption of blockchain technology grows, more and more organizations seek access to all this ecosystem has to offer. That’s where Chainalysis comes in. We provide complete knowledge of what’s happening on blockchains through our data, services, and solutions. With Chainalysis, organizations can navigate blockchains safely and with confidence.

About the Team: Product Security at Chainalysis keeps our SaaS platform — used by governments, banks, and crypto exchanges to investigate financial crime — secure by design. We partner directly with product and platform engineering on threat modeling, design reviews, penetration testing, and remediation of findings across our AWS and Kubernetes estate.

In this role, you’ll:

  • Lead Product Security across Chainalysis' SaaS offerings, partnering with product and platform engineering teams on design, code, and remediation.
  • Own Unified Security Review process for new product launches, vendor evaluations, and AI tooling — including custom penetration tests scoped to each review.
  • Drive Security Engineering Risk Management Framework, for consistent risk classification and remediation tracking across product.
  • Lead the Vulnerability Disclosure Program and security bug reporting workflow, from researcher intake through fix.
  • Drive SOC2 and compliance-related security remediation across product engineering, partnering with R&D leads on architectural fixes.
  • Provide security review and guardrails for internal AI platforms and coding agents (LLM gateways, prompt/response controls, agent permissioning).
  • Participate in a shared on-call rotation for high-severity production security incidents.

We’re looking for candidates who have:

  • 8+ years of application security engineering experience.
  • Strong production coding ability in at least one of Java (preferred), TypeScript/JavaScript, Python, or Go — enough to perform deep code review, write proof-of-concept exploits, and contribute fixes directly into product repos.
  • Building security automation into CI/CD pipelines.
  • Hands-on penetration testing of production SaaS applications, including custom tests scoped to new product launches.
  • Threat modeling, secure design reviews, and static/dynamic code analysis across the SDLC.
  • Identifying and remediating common web application vulnerabilities (OWASP Top 10).
  • Experience securing internal AI/LLM platforms and coding agents (model gateways, prompt/response controls, agent permissioning).

Nice to have experience:

  • Experience in Web3, Blockchain or Digital Assets.
  • Experience building AI workflows, agents, and guardrailing.

Technologies we use:

  • Cloud and containers: AWS, GCP, Kubernetes (EKS/GKE).
  • Infrastructure-as-Code: Terraform.
  • Security tooling: Wiz, SonarCloud, Burp, Cloudflare.
  • CI/CD and source control: GitHub, GitHub Actions, Artifactory and related build/deploy tooling.
  • Languages and scripting: Java, JavaScript, Python, Go.
  • AI Coding Agents, Tooling, Systems.

You belong here. At Chainalysis, we believe that diversity of experience and thought makes us stronger. With both customers and employees around the world, we are committed to ensuring our team reflects the unique communities around us. We’re ensuring we keep learning by committing to continually revisit and reevaluate our diversity culture.

We encourage applicants across any race, ethnicity, gender/gender expression, age, spirituality, ability, experience and more. If you need any accommodations to make our interview process more accessible to you due to a disability, don't hesitate to let us know. You can learn more here. We can’t wait to meet you.

Staff Security Engineer, Product Security employer: Chainalysis

Chainalysis is an exceptional employer that champions innovation in blockchain technology while fostering a collaborative and inclusive work culture. As a Staff Security Engineer, you will have the opportunity to lead critical security initiatives within a dynamic team, ensuring the safety of our SaaS platform used by governments and financial institutions. With a strong emphasis on employee growth, diversity, and continuous learning, Chainalysis offers a unique environment where your contributions directly impact the future of secure blockchain applications.

Chainalysis

Contact Detail:

Chainalysis Recruiting Team

StudySmarter Expert Advice🤫

We think this is how you could land Staff Security Engineer, Product Security

Tip Number 1

Network like a pro! Reach out to folks in the industry, attend meetups, and connect with current employees at Chainalysis. A friendly chat can sometimes lead to insider info about job openings or even a referral!

Tip Number 2

Show off your skills! If you’ve got a portfolio of projects or contributions to open-source, make sure to highlight them. Demonstrating your hands-on experience in security engineering can really set you apart from the crowd.

Tip Number 3

Prepare for the technical interview! Brush up on your coding skills and be ready to discuss your approach to security challenges. Practising common scenarios and potential solutions will help you shine during the interview.

Tip Number 4

Apply through our website! It’s the best way to ensure your application gets seen by the right people. Plus, it shows you’re genuinely interested in joining the Chainalysis team. Don’t miss out!

We think you need these skills to ace Staff Security Engineer, Product Security

Application Security Engineering
Production Coding (Java, TypeScript/JavaScript, Python, Go)
Deep Code Review
Proof-of-Concept Exploits
Security Automation in CI/CD Pipelines
Hands-on Penetration Testing
Threat Modeling

Some tips for your application 🫡

Tailor Your Application:Make sure to customise your CV and cover letter for the Staff Security Engineer role. Highlight your experience in application security engineering and any relevant coding skills, especially in Java or Python. We want to see how your background aligns with what we do at Chainalysis!

Show Off Your Skills:Don’t just list your skills; demonstrate them! Include specific examples of your hands-on penetration testing and any security automation you've built into CI/CD pipelines. We love seeing real-world applications of your expertise.

Be Clear and Concise:Keep your application clear and to the point. Use bullet points where possible to make it easy for us to read through your experiences. We appreciate a well-structured application that gets straight to the good stuff!

Apply Through Our Website:We encourage you to apply directly through our website. It’s the best way to ensure your application gets to the right people. Plus, it shows us you’re genuinely interested in joining the Chainalysis team!

How to prepare for a job interview at Chainalysis

Know Your Tech Stack

Make sure you’re well-versed in the technologies mentioned in the job description, especially AWS, Kubernetes, and the programming languages like Java and Python. Brush up on your coding skills and be ready to discuss how you've used these technologies in past projects.

Showcase Your Security Expertise

Prepare to discuss your experience with application security engineering, penetration testing, and threat modelling. Have specific examples ready that demonstrate your ability to identify and remediate vulnerabilities, particularly those listed in the OWASP Top 10.

Understand the Product Security Landscape

Familiarise yourself with the current trends in product security, especially in relation to SaaS platforms and AI tooling. Be prepared to share your thoughts on how you would approach security reviews and risk management for new product launches.

Ask Insightful Questions

Prepare thoughtful questions about Chainalysis' approach to security, their Vulnerability Disclosure Program, and how they integrate security into their CI/CD pipelines. This shows your genuine interest in the role and helps you assess if the company is the right fit for you.