Product Security at Chainalysis keeps our SaaS platform – used by governments, banks, and crypto exchanges to investigate financial crime – secure by design.
As a Staff Product Security Engineer, you’ll be the technical lead for product security across one or more product areas. You’ll run security reviews for new launches and AI tooling, perform hands‑on pentests, ship code and fixes directly into product repos, own our Vulnerability Disclosure Program, and drive SOC 2 and risk‑framework work across R&D. You’ll also participate in a shared on‑call rotation for production security incidents.
In This Role, You’ll:
- Lead Product Security across Chainalysis’ SaaS offerings, partnering with product and platform engineering teams on design, code, and remediation
- Own Unified Security Review process for new product launches, vendor evaluations, and AI tooling – including custom penetration tests scoped to each review
- Drive Security Engineering Risk Management Framework, for consistent risk classification and remediation tracking across product
- Lead the Vulnerability Disclosure Program and security bug reporting workflow, from researcher intake through fix
- Drive SOC 2 and compliance‑related security remediation across product engineering, partnering with R&D leads on architectural fixes
- Provide security review and guardrails for internal AI platforms and coding agents (LLM gateways, prompt/response controls, agent permissioning)
- Participate in a shared on‑call rotation for high‑severity production security incidents
We’re Looking For Candidates Who Have:
- 8+ years of application security engineering experience
- Strong production coding ability in at least one of Java (preferred), TypeScript/JavaScript, Python, or Go – enough to perform deep code review, write proof‑of‑concept exploits, and contribute fixes directly into product repos
- Building security automation into CI/CD pipelines
- Hands‑on penetration testing of production SaaS applications, including custom tests scoped to new product launches
- Threat modeling, secure design reviews, and static/dynamic code analysis across the SDLC
- Identifying and remediating common web application vulnerabilities (OWASP Top 10)
- Experience securing internal AI/LLM platforms and coding agents (model gateways, prompt/response controls, agent permissioning)
Nice To Have Experience:
- Experience in Web3, Blockchain or Digital Assets
- Experience building AI workflows, agents, and guardrailing
Technologies We Use:
- Cloud and containers: AWS, GCP, Kubernetes (EKS/GKE)
- Infrastructure‑as‑Code: Terraform
- Security tooling: Wiz, SonarCloud, Burp, Cloudflare
- CI/CD and source control: GitHub, GitHub Actions, Artifactory and related build/deploy tooling
- Languages and scripting: Java, JavaScript, Python, Go
- AI Coding Agents, Tooling, Systems
You belong here. At Chainalysis, we believe that diversity of experience and thought makes us stronger. With both customers and employees around the world, we are committed to ensuring our team reflects the unique communities around us. We’re ensuring we keep learning by committing to continually revisit and reevaluate our diversity culture.
We encourage applicants across any race, ethnicity, gender/gender expression, age, spirituality, ability, experience and more. If you need any accommodations to make our interview process more accessible to you due to a disability, don’t hesitate to let us know. You can learn more here. We can’t wait to meet you.
#J-18808-Ljbffr…
