Senior Product Security Engineer
Chainalysis Careers · New York Office
About this role
## About Chainalysis Blockchain technology is powering a growing wave of innovation. Chainalysis provides complete knowledge of what’s happening on blockchains through data, services, and solutions—helping organizations navigate blockchains safely and with confidence. As a **Senior Product Security Engineer**, you’ll be hands-on coding product security across one or more product areas. You’ll run security reviews, perform hands-on pentests, ship code and fixes directly into product repos, and drive **SOC 2** and risk-framework work across R&D/Engineering. ## About the Team Product Security at Chainalysis keeps the SaaS platform secure by design. The team partners with product and platform engineering on threat modeling, design reviews, penetration testing, and remediation across the company’s **AWS and Kubernetes** estate. ## In This Role, You’ll - Build Product Security across Chainalysis’ SaaS offerings, partnering with product and platform engineering on design, code, and remediation - Drive Security Code Reviews for new product launches, including custom penetration tests - Provide security review and guardrails for internal AI platforms and coding agents (LLM gateways, prompt/response controls) - Create threat modeling, secure design reviews, and static/dynamic code analysis across the SDLC - Build security automation into CI/CD pipelines - Participate in a shared on-call rotation for high-severity production security incidents ## We’re Looking For Candidates Who Have - **5+ years** of application security engineering experience - Strong production coding ability in at least one of: **Java (preferred)**, TypeScript/JavaScript, Python, or Go - Ability to perform deep code review, write proof-of-concept exploits, and contribute fixes directly into product repos - Experience building security automation into CI/CD pipelines - Hands-on penetration testing of production SaaS applications, including custom tests scoped to new product launches - Ability to identify and remediate common web application vulnerabilities (**OWASP Top 10**) - Experience securing internal AI/LLM platforms and coding agents (model gateways, prompt/response controls, agent permissioning) ## Nice to Have Experience - Experience in Web3, Blockchain, or Digital Assets - Experience building AI workflows, agents, and guardrailing ## Technologies We Use - **Cloud & containers:** AWS, GCP, Kubernetes (EKS/GKE) - **Infrastructure-as-Code:** Terraform - **Security tooling:** Wiz, SonarCloud, Burp, Cloudflare - **CI/CD & source control:** GitHub, GitHub Actions, Artifactory, and related build/deploy tooling - **Languages & scripting:** Java, JavaScript, Python, Go - **AI coding agents & tooling** ## About AI at Chainalysis AI is not a feature—it’s a new way of working. Chainalysis expects employees to take ownership of output quality, experiment with tools/workflows, and continuously build AI fluency. ## About Chainalysis Chainalysis is the blockchain data platform connecting the movement of digital assets to real-world services. Powered by deep blockchain data and AI, organizations can investigate illicit activity, manage risk exposure, and develop innovative market solutions. Chainalysis is committed to diversity and inclusion and encourages applicants across all backgrounds. If you need accommodations for the interview process, you can request them here: https://go.chainalysis.com/rs/503-FAP-074/images/Interview%20Accommodations%20Request.pdf
Listing freshness
CronJobs last confirmed this listing 2h ago. If its source stops confirming the opening for seven days, this page is removed from active inventory.