Product Security Engineer

Blockchain intelligence company providing tools to detect, investigate, and manage crypto-related fraud, financial crime, and compliance for institutions and government agencies.

Maintainer signals as of 9/25/2026

450 Townsend Street, San Francisco, CA 94107, United States
About TRM Labs

TRM Labs provides blockchain intelligence for investigations and compliance, offering products such as forensics, wallet screening, entity screening, transaction monitoring, and APIs. It serves financial institutions, crypto businesses, and public sector agencies to trace funds, assess risk, and build cases across digital assets.

View jobs by TRM Labs

Skills

Candidate Availability

Required and preferred rules are kept separate and reflect the wording in the original posting.

About the Role

You will lead application security reviews, threat modeling, secure code review, architecture assessments, and testing. You will develop automated testing and secure SDLC practices, manage application vulnerabilities, coordinate penetration tests, support engineers with security practices, maintain the bug bounty program, and deliver secure-code training.

Requirements

  • At least 8 years of software development and testing experience
  • Proficiency in Python, NodeJS, and React
  • Understanding of encryption, authentication, and authorization protocols
  • Experience with OWASP, CWE, security testing methodologies, and security testing tools
  • Experience with GCP and AWS security solutions
  • Experience with secure software development lifecycles and threat modeling
  • Experience conducting code security reviews
  • Experience triaging and remediating package and library vulnerabilities
  • Experience with GitHub Advanced Security, SAST, DAST, and SCA tools
  • Experience with Burp Suite and OWASP ZAP
  • Experience with OWASP Threat Dragon
  • Experience with Agile software development
  • Experience with red teaming or application and infrastructure penetration testing
  • Strong written and verbal communication skills

Responsibilities

  • Lead application security reviews, threat modeling, secure code review, architecture assessments, and testing
  • Develop automated testing and mature the Secure SDLC
  • Own application security vulnerability management
  • Coordinate penetration testing engagements
  • Develop application security best practices for software engineers and product teams
  • Develop and maintain the bug bounty program
  • Bootstrap platform security initiatives to protect data
  • Foster security champions and coordinate secure-code training
  • Perform security risk assessments and triage vulnerabilities
  • Embed security testing and reviews into CI/CD pipelines

Hiring Process

Recruiter intro → hiring manager interview → first round of 1–2 skill-focused interviews → final panel round → references → offer → onboarding. The process may include a case study, AI skills assessment, and Leadership Principles interview.