Senior Product Security Engineer
Listed on 2026-09-19
-
IT/Tech
Cybersecurity, Blockchain / Web3, AI Engineer (Applied/Software), Information Security & Data Protection
About Chainalysis
Blockchain technology is powering a growing wave of innovation. Businesses and governments around the world are using blockchains to make banking more efficient, connect with their customers, and investigate criminal cases. As adoption of blockchain technology grows, more and more organizations seek access to all this ecosystem has to offer. That’s where Chainalysis comes in. We provide complete knowledge of what’s happening on blockchains through our data, services, and solutions.
With Chainalysis, organizations can navigate blockchains safely and with confidence.
As a Senior Product Security Engineer, you'll be hands on coding our product security across one or more product areas. You'll run security reviews, perform hands-on pentests, ship code and fixes directly into product repos, and drive SOC2 and risk-framework work across R&D - Engineering. This is an outstanding opportunity to work with AI Powered products at the intersection of blockchain data, AI and Security.
About the TeamProduct Security at Chainalysis keeps our SaaS platform — used by governments, banks, and crypto exchanges to investigate financial crime — secure by design. We partner directly with product and platform engineering on threat modeling, design reviews, penetration testing, and remediation of findings across our AWS and Kubernetes estate.
In this role, you’ll:Build Product Security across Chainalysis' SaaS offerings, partnering with product and platform engineering teams on design, code, and remediation
Drive Security Code Reviews for new product launches — including custom penetration tests
Provide security review and guardrails for internal AI platforms and coding agents (LLM gateways, prompt/response controls)
Create threat modeling, secure design reviews, and static/dynamic code analysis across the SDLC
Build security automation into our CI/CD pipelines
Participate in a shared on-call rotation for high-severity production security incidents
5+ years of application security engineering experience
Strong production coding ability in at least one of Java (preferred), Type Script/JavaScript, Python, or Go — enough to perform deep code review, write proof-of-concept exploits, and contribute fixes directly into product repos
Building security automation into CI/CD pipelines
Hands-on penetration testing of production SaaS applications, including custom tests scoped to new product launches
Identifying and remediating common web application vulnerabilities (OWASP Top 10)
Experience securing internal AI/LLM platforms and coding agents (model gateways, prompt/response controls, agent permissioning)
Experience in Web3, Blockchain or Digital Assets
Experience building AI workflows, agents, and guard railing
Cloud and containers: AWS, GCP, Kubernetes (EKS/GKE)
Infrastructure-as-Code:
TerraformSecurity tooling:
Wiz, Sonar Cloud, Burp, CloudflareCI/CD and source control:
Git Hub, Git Hub Actions, Artifactory and related build/deploy toolingLanguages and scripting:
Java, JavaScript, Python, GoAI Coding Agents, Tooling, Systems
AI at Chainalysis
AI is not a feature at Chainalysis - it is a new way of working. One that turns instructions into work done, and helps us move faster than the threats we're built to counter, and we expect our employees to take ownership of the output and ensure quality. As the world's most trusted blockchain analytics platform, Chainalysis sits at a rare intersection of proprietary data, regulatory relationships and crypto expertise that makes it uniquely placed to shape and lead the next era of AI-driven intelligence - and we expect everyone here, regardless of role, to be an active part of it.
AI fluency is tied…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).