Lead Product Security Engineer (Staff) - Remote UK

Lead Product Security Engineer (Staff) - Remote UK

Full-Time 80000 - 100000 £ / year (est.) No working from home possible
P2P

At a Glance

  • Tasks: Lead product security for innovative SaaS offerings and conduct hands-on penetration testing.
  • Company: Join Chainalysis, a leader in blockchain technology and security.
  • Benefits: Enjoy remote work, competitive salary, and a commitment to diversity.
  • Other info: Dynamic team with opportunities for growth and learning in a diverse environment.
  • Why this job: Make a real impact in securing cutting-edge blockchain applications.
  • Qualifications: 8+ years in application security and strong coding skills in Java or similar languages.

The predicted salary is between 80000 - 100000 £ per year.

Location: United Kingdom; London

Employment Type: Full time

Location Type: Remote

Department: R&D InfoSec

About Chainalysis: Blockchain technology is powering a growing wave of innovation. Businesses and governments around the world are using blockchains to make banking more efficient, connect with their customers, and investigate criminal cases. As adoption of blockchain technology grows, more and more organizations seek access to all this ecosystem has to offer. That’s where Chainalysis comes in. We provide complete knowledge of what’s happening on blockchains through our data, services, and solutions. With Chainalysis, organizations can navigate blockchains safely and with confidence.

About the Team: Product Security at Chainalysis keeps our SaaS platform — used by governments, banks, and crypto exchanges to investigate financial crime — secure by design. We partner directly with product and platform engineering on threat modeling, design reviews, penetration testing, and remediation of findings across our AWS and Kubernetes estate.

In this role, you’ll:

  • Lead Product Security across Chainalysis's SaaS offerings, partnering with product and platform engineering teams on design, code, and remediation.
  • Own Unified Security Review process for new product launches, vendor evaluations, and AI tooling — including custom penetration tests scoped to each review.
  • Drive Security Engineering Risk Management Framework, for consistent risk classification and remediation tracking across product.
  • Lead the Vulnerability Disclosure Program and security bug reporting workflow, from researcher intake through fix.
  • Drive SOC2 and compliance‑related security remediation across product engineering, partnering with R&D leads on architectural fixes.
  • Provide security review and guardrails for internal AI platforms and coding agents (LLM gateways, prompt/response controls, agent permissioning).
  • Participate in a shared on‑call rotation for high‑severity production security incidents.

We’re looking for candidates who have:

  • 8+ years of application security engineering experience.
  • Strong production coding ability in at least one of Java (preferred), TypeScript/JavaScript, Python, or Go — enough to perform deep code review, write proof‑of‑concept exploits, and contribute fixes directly into product repos.
  • Building security automation into CI/CD pipelines.
  • Hands‑on penetration testing of production SaaS applications, including custom tests scoped to new product launches.
  • Threat modeling, secure design reviews, and static/dynamic code analysis across the SDLC.
  • Identifying and remediating common web application vulnerabilities (OWASP Top 10).
  • Experience securing internal AI/LLM platforms and coding agents (model gateways, prompt/response controls, agent permissioning).

Nice to have experience:

  • Experience in Web3, Blockchain or Digital Assets.
  • Experience building AI workflows, agents, and guard‑railing.

Technologies we use:

  • Cloud and containers: AWS, GCP, Kubernetes (EKS/GKE).
  • Infrastructure‑as‑Code: Terraform.
  • Security tooling: Wiz, SonarCloud, Burp, Cloudflare.
  • CI/CD and source control: GitHub, GitHub Actions, Artifactory and related build/deploy tooling.
  • Languages and scripting: Java, JavaScript, Python, Go.
  • AI Coding Agents, Tooling, Systems.

You belong here. At Chainalysis, we believe that diversity of experience and thought makes us stronger. With both customers and employees around the world, we are committed to ensuring our team reflects the unique communities around us. We’re ensuring we keep learning by committing to continually revisit and reevaluate our diversity culture. We encourage applicants across any race, ethnicity, gender/gender expression, age, spirituality, ability, experience and more. If you need any accommodations to make our interview process more accessible to you due to a disability, don’t hesitate to let us know.

Lead Product Security Engineer (Staff) - Remote UK employer: P2P

Chainalysis is an exceptional employer that champions innovation in blockchain technology while fostering a collaborative and inclusive work culture. As a Lead Product Security Engineer, you will enjoy the flexibility of remote work in the UK, alongside opportunities for professional growth through hands-on projects and leadership in security initiatives. With a commitment to diversity and continuous learning, Chainalysis empowers its employees to thrive in a dynamic environment where their contributions directly impact the safety and efficiency of financial systems worldwide.

P2P

Contact Details:

P2P Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Lead Product Security Engineer (Staff) - Remote UK

Tip Number 1

Network like a pro! Reach out to folks in the industry, especially those at Chainalysis. A friendly chat can open doors and give you insights that a job description just can't.

Tip Number 2

Show off your skills! If you've got a portfolio or GitHub with projects related to security engineering, make sure to highlight them. Real-world examples of your work can set you apart from the crowd.

Tip Number 3

Prepare for the interview by brushing up on your technical knowledge. Be ready to discuss your experience with AWS, Kubernetes, and penetration testing. We want to see how you think and solve problems!

Tip Number 4

Apply through our website! It’s the best way to ensure your application gets seen. Plus, it shows you're genuinely interested in joining the Chainalysis team.

We think you need these skills to ace Lead Product Security Engineer (Staff) - Remote UK

Application Security Engineering
Java
TypeScript
JavaScript
Python
Go
Penetration Testing

Some tips for your application 🫡

Tailor Your CV:Make sure your CV is tailored to the Lead Product Security Engineer role. Highlight your experience in application security engineering and coding skills, especially in Java or any other relevant languages. We want to see how your background aligns with what we do at Chainalysis!

Craft a Compelling Cover Letter:Your cover letter is your chance to shine! Use it to explain why you're passionate about product security and how your skills can contribute to our mission. Be sure to mention any specific experiences that relate to our work in blockchain technology.

Showcase Your Projects:If you've worked on any relevant projects, whether personal or professional, make sure to include them. We love seeing hands-on experience, especially with penetration testing and security automation. It gives us a better idea of your practical skills!

Apply Through Our Website:We encourage you to apply directly through our website. It’s the best way for us to receive your application and ensures you’re considered for the role. Plus, it shows us you’re keen on joining the Chainalysis team!

How to prepare for a job interview at P2P

Know Your Stuff

Make sure you brush up on your application security engineering knowledge, especially around the OWASP Top 10 vulnerabilities. Be ready to discuss your hands-on experience with penetration testing and how you've tackled security issues in production SaaS applications.

Showcase Your Coding Skills

Since strong production coding ability is key for this role, be prepared to demonstrate your proficiency in Java, TypeScript, Python, or Go. You might be asked to review code or even write a proof-of-concept exploit, so practice articulating your thought process while coding.

Understand the Tech Stack

Familiarise yourself with the technologies mentioned in the job description, like AWS, Kubernetes, and CI/CD tools. Being able to discuss how you've used these technologies in previous roles will show that you're not just a security expert but also a well-rounded engineer.

Prepare for Scenario Questions

Expect scenario-based questions where you'll need to demonstrate your problem-solving skills. Think about past experiences where you've led security reviews or managed vulnerability disclosures, and be ready to explain your approach and the outcomes.