Bullish
Director, Senior Security Architect

How your CV stacks up
Upload your CV to see how well it fits this job role
?%
About Bullish
Bullish is an institutionally focused global digital asset platform that provides market infrastructure and information services. These include:
- Bullish Exchange – a regulated and institutionally focused digital assets spot and derivatives exchange, integrating a high-performance central limit order book matching engine with automated market making to provide deep and predictable liquidity. Bullish Exchange is regulated in Germany, Hong Kong, and Gibraltar.
- CoinDesk Indices – a collection of tradable proprietary and single-asset benchmarks and indices that track the performance of digital assets for global institutions in the digital assets and traditional finance industries.
- CoinDesk Data - a broad suite of digital assets market data and analytics, providing real-time insights into prices, trends, and market dynamics.
- CoinDesk Insights – a digital asset media and events provider and operator of Coindesk.com, a digital media platform that covers news and insights about digital assets, the underlying markets, policy, and blockchain technology.
Reports to:
CISO Americas
Position Overview
At Bullish, security is not a checkpoint, it is the foundation of trust that lets people move billions across our markets with confidence. The Bullish Security Architecture team secures Bullish Global, including the Bullish Exchange, Bullish Liquidity Services, CoinDesk Indices, CoinDesk Data, CoinDesk Media, and CoinDesk Events, designing the defenses that keep our mission-critical trading systems and other business lines resilient against the most capable adversaries in the world.
Reasons to use Rodeo
I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?
Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.
Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.
Start with a chat, not a search bar
Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.
Graduate Consultant — 2026 Scheme
Why you're a good match
StrongYour economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.
See breakdownIt searches the market for you
Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.
Why you're a good match
You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.
Experience fit
Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.
Only hits
No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.
As a senior member on this team, you will sit at the intersection of cutting-edge engineering and high-stakes finance, shaping how secure software is built across web, API, mobile, and FIX platforms, and pushing our security bar beyond industry-leading. This is a senior technical leadership role, a hands-on application and cloud security architect who leads through influence, deep expertise, and mentorship.
If you thrive on solving complex technical challenges in a fast-moving crypto landscape and building first-of-their-kind systems, this is where you will do the most impactful work of your career.
This position is based in SoHo London and will be required to work full-time onsite.
Responsibilities
- Build complex threat models for critical systems and establish industry-leading cybersecurity requirements to turn ambiguity into clear, prioritized defenses.
- Partner closely with Product, Engineering, and Infrastructure teams to design and ship secure software across web, API, mobile, FIX, and trading platforms.
- Lead complex global security initiatives, build custom AI-powered tooling to maximize efficiency and scale the cybersecurity program.
- Assess vulnerability risks, deliver actionable recommendations across all technical levels, and track health metrics and KPIs for executive reporting.
- Drive high-impact projects and adapt to evolving business needs within a dynamic, fast-paced environment.
- Provide technical leadership and mentorship to the cybersecurity and engineering teams.
Experience & Qualifications
- 10+ years in cybersecurity, including 5+ years of hands-on coding, alongside deep expertise in threat modeling, pen testing, code reviews, and offensive security methodologies.
- Strong foundation in network protocols (IP, DNS, HTTP, SSL/TLS), cryptography (PKI, encryption at rest/in motion), Linux environments, and public cloud platforms (AWS, Azure, or GCP).
- Proficient in programming languages like C/C++, Java, JS, Python, Go, or Rust.
- Possess a deep understanding of common vulnerability frameworks (OWASP Top 10, SANS CWE Top 25).
- Solid grasp of enterprise software development, Agile, CI/CD pipelines, and security tooling (SAST, DAST, OSA, Vulnerability Management, API traceability).
- Excellent ability to convey complex technical risks to non-technical executives and engineers and build strong cross-functional partnerships.
- A strong individual contributor with ability to drive projects independently from conception to complete with minimal oversight.


Get help with your application
Your very own career expert that helps elevate your application to the next level.
Nice to Have
- A restless drive to secure systems and continuously learn new technologies.
- Experience securing trading, financial-market, or other regulated, high-stakes systems.
- Relevant certifications, such as security architecture certifications (e.g. SABSA, TOGAF), offensive security (e.g. OSCP, OSCE, SANS, CREST) and cloud security specialty certifications (AWS, Azure, or GCP).
Bullish is proud to be an equal opportunity employer. We are fast evolving and striving towards being a globally-diverse community. With integrity at our core, our success is driven by a talented team of individuals and the different perspectives they are encouraged to bring to work every day.
“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”
Jessica, London
Location