Senior Product Security Engineer in London

Senior Product Security Engineer in London

London Full-Time 63000 - 77000 £ / year (est.) No working from home possible
United States Digital Space LLC

At a Glance

  • Tasks: Lead product security initiatives and ensure safe development practices across innovative crypto products.
  • Company: Join a fast-growing global crypto company trusted by millions.
  • Benefits: Competitive salary, equity, unlimited vacation, and flexible work culture.
  • Other info: Dynamic environment with opportunities for career growth and mentorship.
  • Why this job: Make a real impact in the future of finance with cutting-edge technology.
  • Qualifications: 4+ years in security engineering, with strong application security experience.

The predicted salary is between 63000 - 77000 £ per year.

The company is connecting the world to the future of finance. As the most trusted and fastest-growing global crypto company, it helps millions of people worldwide safely access cryptocurrency. Since its inception in 2011, the company has earned the trust of over 90 million wallet holders and more than 40 million verified users, facilitating over $1 trillion in crypto transactions.

You will operate the Product Security programme for the company.com’s internally-developed products across Consumer, OTC and MRE lines. This is a senior, hands-on role: you’ll design and run the secure development lifecycle, lead threat modeling and architecture review, own the security debt lifecycle for product engineering teams, and architect the automated pipelines that protect billions in transaction volume. You will embed with product and engineering teams, convert technical findings into business-prioritized remediation, and lift developer capabilities so security is delivered by code and process.

WHAT YOU WILL DO

  • Strategic Security Partnership: Act as a senior security engineer for the different product lines like Consumer, OTC. You will own the security gates for major feature releases and ensure security is integrated from the design phase.
  • Secure SDLC Operator: Operate and improve the secure development lifecycle. This includes orchestrating SAST/SCA/DAST, streamlining SARIF ingestion, PR review standards, CI/CD security automation, and vulnerability triage workflows.
  • AI-Driven SDLC Innovation: Research, architect, and safely embed cutting-edge AI utilities and Large Language Model (LLM) agents directly into our secure development lifecycle.
  • Threat Modelling & Architecture Reviews: Lead STRIDE/attack-tree threat models for sensitive flows including authentication, payment, custody, reconciliation and sign off on security architecture for critical designs.
  • Product Security Governance & Standards: Translate technical risks and regulatory demands into clear security policies. You will own the creation and upkeep of our Application Security Standards, reference architectures, and compliance-driven secure coding baselines.
  • Bug Bounty Leadership: Oversee the technical triage and remediation strategy for our Bug Bounty program. You will turn external researcher findings into internal architectural hardening projects.
  • Release Reviews: Perform deep-dive manual code reviews of security-sensitive Pull Requests, mentor engineers on secure coding patterns, and provide pragmatic remediation guidance.
  • Advanced Code Auditing: Conduct deep-dive manual and automated code reviews on highly sensitive Java and Kotlin backend Pull Requests.
  • Security Debt & Remediation Negotiation: Produce data-driven Security Debt packs and negotiate remediation into engineering roadmaps. You will negotiate remediation timelines with Product Owners and Engineering leadership, backed by risk-based data.
  • Detection & Telemetry Integration: Define application runtime signals (business-logic anomalies, auth anomalies, reconciliation mismatches) and work with SecOps to instrument logs and alerts.
  • Testing & Automation: Build and maintain product-level test harnesses, fuzzing/property tests and CI checks to prevent regressions for business-critical flows.
  • Incident Response Support: Provide product-level Incident Response expertise like test forensic runbooks, support reproduction of payment/settlement incidents, and advise on containment/remediation whenever needed.
  • Metrics & Risk Visibility: Define and own the Product Security metrics (e.g., MTTR for critical vulnerabilities, security debt burn-down, and defect density). You will translate these KPIs into high-level risk reports for the Head of Security and Engineering leadership to drive data-backed resourcing decisions.
  • People & Process: Coach junior product security engineers and security champions. You will assist the Product Security Lead to define hiring standards and capability plans.

WHAT YOU WILL NEED

Must-Haves: 4+ years total security engineering experience with at least 3+ years focused specially in application/product security or equivalent. Experience with Web, Mobile, Cloud, Infrastructure Pentests and Red Teaming (e.g., phishing). Proven track record of shipping security automation using CodeQL/GHAS, Snyk, or similar. You should be intimately familiar with the SARIF ecosystem and ASPM workflows. Expert-level ability to audit and propose fixes in Kotlin/Java, TypeScript/JS, Python, and familiarity with containerised deployments (Kubernetes). Strong threat modeling experience and pragmatic architecture guidance for high-stakes financial flows (AuthN/AuthZ, Cryptography, Payments). Experience building CI checks, test harnesses and lightweight fuzzing/property tests. Excellent stakeholder skills — able to negotiate remediation with Engineering Directors and Product owners, balancing security requirements with business velocity.

Nice-to-haves: Prior fintech/Trading/OTC product security experience or familiarity with custody/signing patterns. Practical experience designing or deploying AI-assisted security tooling, leveraging LLMs for automated software patch generation, or evaluating vulnerability detection agents within enterprise developer pipelines. Prior experience operating alongside GRC frameworks, authoring developer-facing security policies from scratch, and building automated policy-as-code gateway integrations. Public track record of CVEs, security research, or open-source contributions to security tooling. Advanced credentials such as OSCP, OSWE, CISSP or equivalent. Experience with on-chain/off-chain integration, payment reconciliation, or smart contract security. Familiarity with vulnerability management platforms (DefectDojo, Dependabot orchestration) and GRC/Gateway integrations. Prior contributions to security automation and developer tooling (open source or internal).

COMPENSATION & PERKS: Full-time salary based on experience and meaningful equity in an industry-leading company. This is a role based in our London office, with a mandatory in-office presence four days per week. Work from Anywhere Policy: You can work remotely from anywhere in the world for up to 20 days per year. ClassPass Unlimited vacation policy; work hard and take time when you need it. Apple equipment. The opportunity to be a key player and build your career at a rapidly expanding, global technology company in an emerging field. Flexible work culture. The company is committed to diversity and inclusion in the workplace and is proud to be an equal opportunity employer. We prohibit discrimination and harassment of any kind based on race, religion, color, national origin, gender, gender expression, sex, sexual orientation, age, marital status, veteran status, disability status or any other characteristic protected by law. This policy applies to all employment practices within our organization, including hiring, recruiting, promotion, termination, layoff, recall, leave of absence, and apprenticeship. The company makes hiring decisions based solely on qualifications, merit, and business needs at the time.

Senior Product Security Engineer in London employer: United States Digital Space LLC

United States Digital Space LLC is an exceptional employer, offering a dynamic work culture that prioritises innovation and collaboration in the heart of Greater London. With a strong focus on employee well-being and flexible work options, we provide ample opportunities for professional growth and development, making it an ideal environment for those looking to make a meaningful impact in the field of AI-enabled SaaS engineering.

United States Digital Space LLC

Contact Details:

United States Digital Space LLC Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Senior Product Security Engineer in London

Join Local Tech Meetups

Get out there and mingle with fellow developers by joining local tech meetups. It’s a fantastic way to meet people who might be working at United States Digital Space LLC or know someone who does. Plus, you can pick up some trendy tech skills and trends while you're at it!

Contribute to Open Source Projects

Show off your coding chops by jumping into open-source projects. Not only does this give you practical experience, but it also gets you noticed in the dev community. You'll create a killer portfolio that speaks volumes about your skills to United States Digital Space LLC.

Tap into Online Developer Communities

Don’t underestimate the power of online developer communities like GitHub, Stack Overflow, and even Reddit. Participate in discussions, share your projects, and build your visibility. We can often find opportunities through these channels that can lead to a full-time gig at companies like United States Digital Space LLC.

Explore Job Boards Specifically for Tech Roles

Keep your eyes peeled on job boards that focus on tech roles. Sites like TechCareers or Stack Overflow Jobs can often have listings for companies like United States Digital Space LLC that might not show up on broader job sites. Make it a habit to check these regularly, and don’t hesitate to apply directly through our website!

We think you need these skills to ace Senior Product Security Engineer in London

Application Security
Secure Development Lifecycle (SDLC)
Threat Modelling
Architecture Review
Security Automation
Code Auditing
Java

Some tips for your application 🫡

Show off your coding skills:When applying for a software engineering role, it's super important to showcase your coding skills. Make sure your CV includes your tech stack, any relevant programming languages you’re comfortable with, and examples of projects you've worked on. If you have a GitHub profile, link it up! We love to see code in action.

Tailor your portfolio:For a full-time role, we’d expect to see some solid examples of your work in your portfolio. Make sure to include at least two or three projects that highlight your problem-solving skills and your ability to work with different technologies. Focus on the projects that are most relevant to the position at United States Digital Space LLC.

Craft a killer cover letter:Your cover letter is your chance to stand out—make it personal! Explain why you want to work at United States Digital Space LLC and how your skills align with the role. Show us your passion for software development. We dig enthusiastic candidates who understand the value of collaboration and continuous learning!

Be clear and concise:When it comes to writing your CV and cover letter, clarity is key. Avoid jargon that could confuse us and stick to simple, direct language. Highlight your achievements with quantifiable results where possible, and keep everything easy to read. A well-organised application goes a long way!

How to prepare for a job interview at United States Digital Space LLC

Brush Up on Your Coding Skills

For a full-time software engineering role, it's crucial that we stay sharp with our coding abilities. Expect technical questions that might involve solving problems on the spot or discussing algorithms. Practise on platforms like LeetCode or HackerRank to get comfortable with the types of questions that often come up.

Know Your Tools and Frameworks

Make sure we’re well-acquainted with the tools and technologies listed in the job description. Familiarise ourselves with any specific frameworks or programming languages mentioned. If United States Digital Space LLC uses React or Node.js, for instance, be ready to discuss how we’ve used them in previous projects or coursework.

Showcase Your Projects

Bring along a portfolio that highlights our best work. This could be code samples, GitHub repositories, or any side projects we’ve built. Make sure we can talk through our thought process for each project, especially the challenges we faced and how we solved them—this shows our problem-solving skills in action.

Prepare for Behavioural Questions

While technical skills are key, full-time positions also require cultural fit. Be ready to discuss our previous experiences and how we handle teamwork, conflict, and deadlines. Brush up on the STAR method—Situation, Task, Action, Result—to clearly articulate our past experiences when discussing how we've contributed to a team.