Назад
Company hidden
7 дней назад

Senior Product Security Engineer (Crypto)

Формат работы
hybrid
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
France
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Senior Product Security Engineer (Crypto): Operating and advancing the secure development lifecycle for cryptocurrency products across Consumer, OTC, and MRE lines with an accent on threat modeling, architecture reviews, security automation, and sensitive Java/Kotlin code auditing. Focus on embedding AI and LLM agents into security pipelines, protecting payment and custody flows, managing security debt, and building testing and telemetry for business-critical transactions.

Location: Paris, France; mandatory in-office presence four days per week. Remote work from anywhere in the world is available for up to 20 days per year.

Company

hirify.global is a global cryptocurrency company providing secure access to cryptocurrency and facilitating crypto transactions for millions of users.

What you will do

  • Operate and improve the secure development lifecycle across Consumer, OTC, and MRE products.
  • Orchestrate SAST, SCA, DAST, SARIF ingestion, CI/CD security automation, and vulnerability triage workflows.
  • Lead STRIDE and attack-tree threat modeling and approve security architecture for authentication, payments, custody, reconciliation, and other sensitive flows.
  • Conduct manual and automated security reviews of Java, Kotlin, TypeScript/JavaScript, and Python code, while mentoring engineers on secure coding.
  • Research and integrate AI and LLM-based security utilities into developer pipelines.
  • Manage bug bounty findings, security debt, runtime telemetry, testing, fuzzing, incident response support, and product security metrics.

Requirements

  • 4+ years of security engineering experience, including at least 3 years in application or product security.
  • Experience with web, mobile, cloud, and infrastructure penetration testing and red teaming.
  • Experience delivering security automation with CodeQL/GHAS, Snyk, or similar tools, including SARIF and ASPM workflows.
  • Expertise auditing and fixing Kotlin/Java, TypeScript/JavaScript, and Python code, plus familiarity with Kubernetes deployments.
  • Strong threat modeling and architecture review experience for financial flows involving authentication, cryptography, and payments.
  • Ability to build CI checks, test harnesses, fuzzing/property tests, and negotiate risk-based remediation with engineering and product leadership.

Nice to have

  • Fintech, trading, OTC, custody, signing, payment reconciliation, or smart contract security experience.
  • Experience with AI-assisted security tooling, LLM-based patch generation, or vulnerability detection agents.
  • Experience with GRC frameworks, security policies, policy-as-code gateways, DefectDojo, or Dependabot orchestration.
  • CVEs, security research, open-source security tooling contributions, or credentials such as OSCP, OSWE, or CISSP.

Culture & Benefits

  • Full-time salary based on experience and meaningful equity.
  • Unlimited vacation policy.
  • Unlimited books policy and access to a company library.
  • Apple equipment.
  • Remote work from anywhere in the world for up to 20 days per year.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →