About Bullish
Bullish is an institutionally focused global digital asset platform that provides market infrastructure and information services. These include:BullishExchange - a regulated and institutionally focused digital assets spot and derivatives exchange, integrating a high-performance central limit order book matching engine with automated market making to provide deep and predictable liquidity. Bullish Exchange is regulated in Germany, Hong Kong, and Gibraltar.CoinDeskIndices - a collection of tradable proprietary and single-asset benchmarks and indices that track the performance of digital assets for global institutions in the digital assets and traditional finance industries.CoinDeskData - a broad suite of digital assets market data and analytics, providing real-time insights into prices, trends, and market dynamics.CoinDeskInsights - a digital asset media and events provider and operator ofCoindesk.com, a digital media platform that covers news and insights about digital assets, the underlying markets, policy, and blockchain technology.
Reports to:
CISO AmericasPosition Overview
At Bullish, security is not a checkpoint, it is the foundation of trust that lets people move billions across our markets with confidence. The Bullish Security Architecture team secures Bullish Global, including the Bullish Exchange, Bullish Liquidity Services, CoinDesk Indices, CoinDesk Data, CoinDesk Media, and CoinDesk Events, designing the defenses that keep our mission-critical trading systems and other business lines resilient against the most capable adversaries in the world.
As a senior member on this team, you will sit at the intersection of cutting-edge engineering and high-stakes finance, shaping how secure software is built across web, API, mobile, and FIX platforms, and pushing our security bar beyond industry-leading. This is a senior technical leadership role, a hands-on application and cloud security architect who leads through influence, deep expertise, and mentorship.
If you thrive on solving complex technical challenges in a fast-moving crypto landscape and building first-of-their-kind systems, this is where you will do the most impactful work of your career.
This position is based in SoHo London and will be required to work full-time onsite.
Responsibilities:
Build complex threat models for critical systems and establish industry-leading cybersecurity requirements to turn ambiguity into clear, prioritized defenses.
Partner closely with Product, Engineering, and Infrastructure teams to design and ship secure software across web, API, mobile, FIX, and trading platforms.
Lead complex global security initiatives, build custom AI-powered tooling to maximize efficiency and scale the cybersecurity program.
Assess vulnerability risks, deliver actionable recommendations across all technical levels, and track health metrics and KPIs for executive reporting.
Drive high-impact projects and adapt to evolving business needs within a dynamic, fast-paced environment.
Provide technical leadership and mentorship to the cybersecurity and engineering teams.
Experience & Qualifications:
10+ years in cybersecurity, including 5+ years of hands-on coding, alongside deep expertise in threat modeling, pen testing, code reviews, and offensive security methodologies.
Strong foundation in network protocols (IP, DNS, HTTP, SSL/TLS), cryptography (PKI, encryption at rest/in motion), Linux environments, and public cloud platforms (AWS, Azure, or GCP).
Proficient in programming languages like C/C++, Java, JS, Python, Go, or Rust
Possess a deep understanding of common vulnerability frameworks (OWASP Top 10, SANS CWE Top 25).
Solid grasp of enterprise software development, Agile, CI/CD pipelines, and security tooling (SAST, DAST, OSA, Vulnerability Management, API traceability).
Excellent ability to convey complex technical risks to non-technical executives and engineers and build strong cross-functional partnerships.
A strong individual contributor with ability to drive projects independently from conception to complete with minimal oversight.
Nice to Have:
A restless drive to secure systems and continuously learn new technologies.
Experience securing trading, financial-market, or other regulated, high-stakes systems.
Relevant certifications, such as security architecture certifications (e.g. SABSA, TOGAF), offensive security (e.g. OSCP, OSCE, SANS, CREST) and cloud security specialty certifications (AWS, Azure, or GCP).
Bullish is proud to be an equal opportunity employer. We are fast evolving and striving towards being a globally-diverse community. With integrity at our core, our success is driven by a talented team of individuals and the different perspectives they are encouraged to bring to work every day.

