Chainalysis
Blockchain
StaffSecurityEngineer,ProductSecurity
Neural analysis suggests this role is
optimal for Senior candidates.
“Staff Security Engineer, Product Security at Chainalysis. Skills: Product Security, application security engineering, penetration testing, threat modeling, secure design reviews, CI/CD security automation, AI/LLM platform security. Lead Product Security across Chainalysis' SaaS offerings. partnering with product and platform engineering teams on design, code, and remediation”
Industry & Context.
Participate in a shared on-call rotation for high-severity production security incidents
What They're Looking For.
Must Have
8+ years of application security engineering experience, production coding ability in at least one of Java (preferred), TypeScript/JavaScript, Python, or Go — enough to perform deep code review, write proof-of-concept exploits, and contribute fixes directly into product repos, Building security automation into CI/CD pipelines, Hands-on penetration testing of production SaaS applications, including custom tests scoped to new product launches, Threat modeling, secure design reviews, and static/dynamic code analysis across the SDLC, Identifying and remediating common web application vulnerabilities (OWASP Top 10), Experience securing internal AI/LLM platforms and coding agents (model gateways, prompt/response controls, agent permissioning)
Nice to Have
Experience in Web3, Blockchain or Digital Assets, Experience building AI workflows, agents, and guardrailing
What You'll Do.
Lead Product Security across Chainalysis' SaaS offerings
partnering with product and platform engineering teams on design
Own Unified Security Review process for new product launches
and AI tooling — including custom penetration tests scoped to each review
Drive Security Engineering Risk Management Framework
for consistent risk classification and remediation tracking across product
Lead the Vulnerability Disclosure Program and security bug reporting workflow
from researcher intake through fix
Drive SOC2 and compliance-related security remediation across product engineering
partnering with R&D leads on architectural fixes
Provide security review and guardrails for internal AI platforms and coding agents (LLM gateways
prompt/response controls
How You'll Work.
Team & Collaboration
partnering with product and platform engineering on design, code, and remediation; partnering with R&D leads on architectural fixes
Full Job Description
ABOUT CHAINALYSIS Blockchain technology is powering a growing wave of innovation. Businesses and governments around the world are using blockchains to make banking more efficient, connect with their customers, and investigate criminal cases. As adoption of blockchain technology grows, more and more organizations seek access to all this ecosystem has to offer. That’s where Chainalysis comes in. We provide complete knowledge of what’s happening on blockchains through our data, services, and solutions. With Chainalysis, organizations can navigate blockchains safely and with confidence. ABOUT THE TEAM Product Security at Chainalysis keeps our SaaS platform — used by governments, banks, and crypto exchanges to investigate financial crime — secure by design. We partner directly with product and platform engineering on threat modeling, design reviews, penetration testing, and remediation of findings across our AWS and Kubernetes estate. As a Staff Product Security Engineer, you'll be the technical lead for product security across one or more product areas. You'll run security reviews for new launches and AI tooling, perform hands-on pentests, ship code and fixes directly into product repos, own our Vulnerability Disclosure Program, and drive SOC2 and risk-framework work across R&D. You'll participate in a shared on-call rotation for production security incidents. IN THIS ROLE, YOU’LL: - Lead Product Security across Chainalysis' SaaS offerings, partnering with product and platform engineering teams on design, code, and remediation - Own Unified Security Review process for new product launches, vendor evaluations, and AI tooling — including custom penetration tests scoped to each review - Drive Security Engineering Risk Management Framework, for consistent risk classification and remediation tracking across product - Lead the Vulnerability Disclosure Program and security bug reporting workflow, from researcher intake through fix - Drive SOC2 and compliance-related security r
Applying for this Staff Security Engineer, Product Security role?
Most applicants get filtered before a human reads their resume. See if yours makes the cut.
How to Apply on Ashby
- Ashby is a fast modern ATS — most applications take under 3 minutes.
- The resume parser is strong; verify parsed experience dates and job titles.
- Custom screening questions are often scored algorithmically — answer completely.
- Location field affects geo-based screening; use your actual metro area.
ANONYMOUS · UNFILTERED
What do employees actually say about Chainalysis?
Real rants from real employees. Read before you apply.