Staff Security Engineer, Product Security
Bantu tim Product Security Chainalysis dengan review keamanan produk dan pentest
Sebagai Staff Product Security Engineer, Anda akan menjadi pemimpin teknis untuk keamanan produk di Chainalysis. Anda akan memimpin review keamanan untuk peluncuran baru dan alat AI, melakukan pentesting langsung, menulis kode dan perbaikan ke repositori produk, mengelola Program Pengungkapan Kerentanan, dan mendorong pekerjaan SOC2 dan kerangka kerja risiko di R&D. Anda juga akan berpartisipasi dalam rotasi on-call untuk insiden keamanan produks
Kenapa Menarik?
Bekerja di tim Product Security Chainalysis yang berfokus pada keamanan platform SaaS mereka yang digunakan oleh pemerintah, bank, dan bursa kripto untuk menyel
Tanggung Jawab Utama
- Mengelola proses review keamanan terpadu untuk peluncuran produk baru, evaluasi vendor, dan alat AI
- Mendorong kerangka kerja manajemen risiko keamanan engineering untuk klasifikasi risiko dan pelacakan perbaikan yang konsisten di seluruh pr
- Memimpin program pengungkapan kerentanan dan alur kerja pelaporan bug keamanan
- Memberikan review keamanan dan panduan untuk platform AI internal dan agen coding
Persyaratan
- Memiliki pengalaman 8+ tahun dalam application security engineering
Skills Wajib
Keywords
Lihat Deskripsi Asli dari Ashby Job Boards
Deskripsi asli dari Ashby Job Boards
ABOUT CHAINALYSIS Blockchain technology is powering a growing wave of innovation. Businesses and governments around the world are using blockchains to make banking more efficient, connect with their customers, and investigate criminal cases. As adoption of blockchain technology grows, more and more organizations seek access to all this ecosystem has to offer. That’s where Chainalysis comes in. We provide complete knowledge of what’s happening on blockchains through our data, services, and solutions. With Chainalysis, organizations can navigate blockchains safely and with confidence. ABOUT THE TEAM Product Security at Chainalysis keeps our SaaS platform — used by governments, banks, and crypto exchanges to investigate financial crime — secure by design. We partner directly with product and platform engineering on threat modeling, design reviews, penetration testing, and remediation of findings across our AWS and Kubernetes estate. As a Staff Product Security Engineer, you'll be the technical lead for product security across one or more product areas. You'll run security reviews for new launches and AI tooling, perform hands-on pentests, ship code and fixes directly into product repos, own our Vulnerability Disclosure Program, and drive SOC2 and risk-framework work across R&D. You'll participate in a shared on-call rotation for production security incidents. IN THIS ROLE, YOU’LL: - Lead Product Security across Chainalysis' SaaS offerings, partnering with product and platform engineering teams on design, code, and remediation - Own Unified Security Review process for new product launches, vendor evaluations, and AI tooling — including custom penetration tests scoped to each review - Drive Security Engineering Risk Management Framework, for consistent risk classification and remediation tracking across product - Lead the Vulnerability Disclosure Program and security bug reporting workflow, from researcher intake through fix - Drive SOC2 and compliance-related security remediation across product engineering, partnering with R&D leads on architectural fixes - Provide security review and guardrails for internal AI platforms and coding agents (LLM gateways, prompt/response controls, agent permissioning) - Participate in a shared on-call rotation for high-severity production security incidents WE’RE LOOKING FOR CANDIDATES WHO HAVE: - 8+ years of application security engineering experience - Strong production coding ability in at least one of Java (preferred), TypeScript/JavaScript, Python, or Go — enough to perform deep code review, write proof-of-concept exploits, and contribute fixes directly into product repos - Building security automation into CI/CD pipelines - Hands-on penetration testing of production SaaS applications, including custom tests scoped to new product launches - Threat modeling, secure design reviews, and static/dynamic code analysis across the SDLC - Identifying and remediating common web application vulnerabilities (OWASP Top 10) - Experience securing internal AI/LLM platforms and coding agents (model gateways, prompt/response controls, agent permissioning) NICE TO HAVE EXPERIENCE: - Experience in Web3, Blockchain or Digital Assets - Experience building AI workflows, agents, and guardrailing TECHNOLOGIES WE USE: - Cloud and containers: AWS, GCP, Kubernetes (EKS/GKE) - Infrastructure-as-Code: Terraform - Security tooling: Wiz, SonarCloud, Burp, Cloudflare - CI/CD and source control: GitHub, GitHub Actions, Artifactory and related build/deploy tooling - Languages and scripting: Java, JavaScript, Python, Go - AI Coding Agents, Tooling, Systems AI at Chainalysis AI is not a feature at Chainalysis - it is a new way of working. One that turns instructions into work done, and helps us move faster than the threats we're built to counter, and we expect our employees to take ownership of the output and ensure quality. As the world's most trusted blockchain analytics platform, Chainalysis sits at a rare intersection of proprietary data, regulatory relationships and crypto expertise that makes it uniquely placed to shape and lead the next era of AI-driven intelligence - and we expect everyone here, regardless of role, to be an active part of it. AI fluency is tied directly to how we measure performance and how we plan to win. There is no substitute for your own curiosity. We provide the tools, workflows, and space to experiment - but the expectation is that you develop these capabilities yourself, bring ideas, and collaborate across teams to reinvent the way work gets done. We are not using AI to do less. We are using it to do what was never possible before. About Chainalysis Chainalysis is the blockchain data platform, making it easy to connect the movement of digital assets to real-world services. Powered by deep blockchain data and AI, organizations can investigate illicit activity, manage risk exposure, and develop innovative market solutions built on the industry's most trusted blockchain intelligence. Our mission is to build trust in blockchains, blending safety and security with an unwavering commitment to growth and innovation. You belong here. At Chainalysis, we believe that diversity of experience and thought makes us stronger. With both customers and employees around the world, we are committed to ensuring our team reflects the unique communities around us. We’re ensuring we keep learning by committing to continually revisit and reevaluate our diversity culture. We encourage applicants across any race, ethnicity, gender/gender expression, age, spirituality, ability, experience and more. If you need any accommodations to make our interview process more accessible to you due to a disability, don't hesitate to let us know. You can learn more here https://go.chainalysis.com/rs/503-FAP-074/images/Interview%20Accommodations%20Request.pdf. We can’t wait to meet you.
Data & laporan pasar
Riset gaji & permintaan skill dari data lowongan kami sendiri.
- Lowongan IT Indonesia vs Remote Global (2026)Analisis data primer 2.049 lowongan: metodologi, klasifikasi, dataset bisa diunduh.
- Permintaan Skill AI: Indonesia vs Global (2026)10.000+ lowongan, classifier taxonomy-first, Wilson CI, pra-registrasi sebelum analisis.
- Laporan Hiring Indonesia: Tech vs Non-TechPermintaan lowongan per bidang dari hitungan agregat — bukan listing per-listing.
- Benchmark Gaji IndonesiaKisaran gaji agregat lintas peran, dengan metodologi dan dataset terbuka.
- Laporan Pasar Remote per PeranLaporan otomatis per kelompok peran — skill, senioritas, perusahaan, gaji.
