Justin England

VP Security & Infrastructure, Chia Network

I run security, infrastructure, corporate IT, and DevOps for a major open-source blockchain company. Penn State alumnus.

Leadership Profile

I build and own global security and infrastructure programs from the ground up. Over 20 years that's meant GRC, custody risk, SecOps, platform security, DevOps, and corporate IT for distributed teams in regulated, high-scale, and digital-asset environments, with cost-effective and responsible execution throughout.

At Chia Network I'm VP of Security & Infrastructure. I run the full security stack and everything operational behind it: security architecture, GRC, SecOps, corporate IT, cloud on AWS and GCP, DevOps and DevSecOps, Terraform and Ansible, monitoring and alerting, SDLC guardrails, and logistics for a team spread across three continents. I also own our HSM-based multi-signature custody and signing authorization work.

I run shared platform and corporate IT with the same discipline I apply to security: clear accountability, automation first, measurable uptime, and services teams can depend on. That means vendor and colocation negotiation, ITSM-aligned incident and change discipline, executive escalation, and cost-conscious execution.

I work closely with engineering on threat modeling, attack-path analysis, and security architecture reviews before anything hits production. I've led secure agentic adoption across the company (~90% of employees), with data classification, access models, human-in-the-loop controls, and SDLC guardrails that helped us ship roughly 4x faster without blowing up our blast radius. I started our bug bounty and coordinated disclosure program; automated triage now marks 99.9% of thousands of daily submissions as duplicate before an analyst ever looks at them.

Our programs align to NIST CSF, ISO 27001, and SOC 2 Type II. I work with legal, auditors, vendors, and law enforcement on compliance, third-party risk, and financial-crime mitigation.

Before Chia, at T-Mobile, I led platform security architecture for 35,000 internal engineers and a 30-engineer team modernizing GitLab-driven CI/CD, secrets management, and DevSecOps at enterprise scale.

I'm a Penn State alumnus (BS, Information Sciences and Technology) and former PSU OIT Red Hat systems administrator.

I like building Secure-by-Design frameworks that hold up in financial services and decentralized ecosystems. Good documentation, clear process, and zero-trust integrity around high-value assets matter to me. So does making security feel like a team sport, not a gate.

Security is a team sport!

Program at a Glance

Domain Program Outcomes
GRC SOC 2 Type II certified; ISO 27001 readiness; NIST CSF alignment; automated audit cycles reducing prep from six weeks to three
Custody & Treasury Risk HSM-based multi-signature signing authorization; transaction policy controls and delegated approvals; $200M treasury protection; key-holder safety program across three continents
Signing & Key Management Enterprise key lifecycle; secure signing workflows; secrets management; privileged access; PKI-adjacent services
Global Operations Security practice across 10 countries and 4 continents; US, EMEA, and APAC footprint with 99.9999% critical-service uptime
AppSec & Supply Chain Open-source security at investment-bank attacker scale; supply chain hardening across all internal and external repositories; architecture review before production; bug bounty with automated triage (99.9% of thousands of daily submissions marked duplicate)
Agentic & AI Security ~90% employee adoption; data classification; human-in-the-loop controls; control-by-design for AI-assisted development; ~4x release velocity
Infrastructure & Cloud Ops AWS and GCP platform ownership; Terraform and Ansible for infrastructure-as-code; monitoring, alerting, and observability; 99.9999% critical-service uptime across US, EMEA, and APAC colocation and logistics
DevOps & SDLC End-to-end SDLC ownership for a massive open-source codebase; hardened CI/CD, release engineering, and DevSecOps pipelines; secure agentic adoption with ~4x release velocity and bounded blast radius
Corporate IT Global corporate IT and end-user computing for a distributed workforce across 10 countries; identity, endpoint, and productivity tooling standards from employee #24 through 100+
Service Delivery & IT Operations Shared platform and corporate IT ownership; vendor and colocation negotiation; ITSM-aligned incident, change, and problem management; executive escalation; cost-conscious automation
DevSecOps at Scale T-Mobile GitLab platform serving 35,000 engineers; 100,000+ daily pipeline activities; machine/service identities and pipeline secrets; enterprise DevSecOps transformation; current Chia supply chain and delivery hardening
Detection & Response Daily SIEM triage and remediation; incident response and threat modeling; residual risk assessment; pen test coordination; blameless post-mortem culture

Current Focus

Vice President of Security & Infrastructure at Chia Network

Dec 2022 to Present

I'm Vice President of Security & Infrastructure at Chia Network. I own the full security stack and all operational functions for a major open-source blockchain and technology company.

My scope spans security architecture, GRC, SecOps, corporate IT, DevOps, cloud infrastructure on AWS and GCP, infrastructure-as-code with Terraform and Ansible, monitoring and alerting, SDLC guardrails, and global logistics across three continents. Chia's security model is unusual: we operate at the attacker scale of a major investment bank while publishing our entire codebase for public review.

  • Operate infrastructure with Terraform/Ansible; monitoring, alerting, and observability for critical services at 99.9999% uptime.
  • Own corporate IT for a distributed workforce: identity, endpoint standards, productivity tooling, end-user security early stage through 100+ employees.
  • Hardened CI/CD, release engineering, and DevSecOps for a massive public codebase; supply chain security at investment-bank attacker scale.
  • Architected Chia HSM-backed multi-signature custody with transaction authorization, policy controls, delegated approvals, and secure signing workflows for high-value treasury across three continents; cut spend resolution 3 days.
  • Lead threat modeling, attack-path analysis, and security architecture reviews as pre-prod checkpoints across public/private codebases.
  • Founded bug bounty and coordinated disclosure; automated triage marks 99.9% of thousands of daily submissions duplicate before analyst review.
  • Led secure agentic adoption (~90% of employees): data classification, access models, human-in-the-loop controls, SDLC guardrails; ~4x release velocity, bounded blast radius.
  • Built real-time safety and asset protection for key holders guarding $200M treasury.
  • Security practice across 10 countries, 5 continents: crypto spends, key-holder safety, internal security, GRC.
  • Shortened SOC audit prep from six weeks to three; passed SOC 2 Type II recertification in Q2 2026.
  • Selected logistics/colocation vendors for global digital ops in the US, Europe, and Southeast Asia.
  • Built/lead global security & infrastructure: GRC, SecOps, custody, DevOps, corporate IT, cloud platform ops.

HSM Custody & Signing Authorization

The HSM-based authorization system I built at Chia protects high-value treasury and settlement operations. Here's how it works:

  • Signing & authorization: Multi-signature workflows, transaction authorization, policy controls, and delegated approvals
  • Key management: Enterprise key lifecycle, HSM-backed signing, secrets management, and privileged access
  • Blast radius: Policy-bound controls limiting who can sign, what can move, and under what conditions
  • Assurance: Threat modeling, security architecture review, and control-by-design delivery in regulated contexts

Thought Leadership & Blogs

Writing on custody, signing authorization, AI-assisted vulnerability management, and getting audit-ready.

Offensive & AI Security

Chia 2.7.1 is Out, Upgrade Now

The next step in our spring security push: post-mortems for 2.6.x and 2.7.0, plus fixes found after 2.7.0 shipped.

Read on Chia Blog

Security Patches Q&A

Community Q&A on the 2.6.x / 2.7.x security releases and what we learned from AI-assisted bounty triage at scale.

Watch on YouTube

The AI Siege: Combatting the LLM Attacker

A technical framework for AI-enabled threats; automated triage of thousands of daily bug bounty submissions with 99.9% marked duplicate before analyst review.

Read on Chia Blog

Wallet, Custody & Platform Security

Part 1: Wrench-Resistant by Design

Institutional custody and multi-signature design for real-world safety, not just cryptographic elegance.

View Series

Part 2: Account model just isn't good enough

Why traditional account-based custody models fall short for high-value assets, and what a coin-set approach enables instead.

Read More

Part 3: What does all this mean?

Delegated authority and wrench-resistant design for operators, key holders, and the ecosystem.

Read More

SOC 2 Type II Certification and Our Commitment to Security and Auditability

How Chia achieved SOC 2 Type II certification and what it signals about our commitment to security, auditability, and enterprise readiness.

Read More

Video: Global ASIC Rollout

Technical walkthrough of the global expansion of the Timelord network and ASIC hardware security.

Watch on YouTube

Career Highlights

Vice President of Security & Infrastructure at Chia Network

Dec 2022 to Present

Executive owner of security architecture, GRC, SecOps, corporate IT, and global platform operations for a distributed open-source blockchain company across 10 countries.

  • HSM-based multi-signature custody and signing authorization for high-value treasury operations across three continents
  • SOC 2 Type II certification; shortened audit prep from six weeks to three
  • Led secure agentic adoption (~90% of employees) with ~4x release velocity and bounded blast radius
  • Bug bounty program with automated triage marking 99.9% of thousands of daily submissions duplicate before analyst review
  • 99.9999% critical-service uptime across US, EMEA, and APAC colocation and cloud estates

Head of Platform and Security at Chia Network

Oct 2020 to Dec 2022

Joined Chia as head of Platform and Security during rapid growth, taking operations, DevOps, platform, and security responsibilities from the CEO. Sole ops/security engineer for roughly a year before hiring and growing the team to 14 engineers through public blockchain launch.

  • Architected greenfield GCP/AWS platform security: IAM, network segmentation, secrets management, and hardened CI/CD from bare accounts to production
  • Built security operations and IT infrastructure from employee #24 to 100, establishing the foundation for today's global security program
  • Prepared the company for pre-IPO audits: SOC 2, ISO 27001, blameless post-mortem culture (Chia Network post-mortem repo)
  • Hardened supply chain and delivery pipelines; mitigated 100+ security incidents daily across a massive open-source codebase
  • Implemented incident response and threat modeling; 99.9999% uptime for critical services
  • Instituted end-user security and tooling standards across all internal and external repositories

Principal Architect, Continuous Delivery Platform at T-Mobile

Jun 2019 to Oct 2020

Principal Architect on T-Mobile's shared Continuous Delivery Platform (GitLab SaaS), servicing 35,000 internal engineers. Led a 30-engineer team accountable for service performance, change and release discipline, developer adoption, and enterprise-wide DevOps pipeline modernization.

Designed and implemented a GitOps-driven CI/CD pipeline for T-Mobile's cloud-based platform, handling 100,000+ pull requests, merge requests, and engineer activities daily.

Secured the CI/CD pipeline and integrated security into all phases of the development lifecycle; addressed 1,500+ unique incidents daily while driving DevSecOps adoption across engineering teams.

Operationalized GitLab for enterprise-scale software delivery, reducing mean time to delivery across software projects by three weeks on average.

Governed machine/service identities and pipeline secrets; embedded security architecture into agile delivery for 35,000 engineers.

Senior DevOps Engineer at BombBomb

Jan 2018 to Jun 2019

Migrated production infrastructure to Kubernetes on AWS; built microservices, improved CI/CD, and strengthened monitoring and observability for a SaaS video engagement platform.

  • Operated AWS EKS with GitOps delivery, SSO-based access auditing, and SOC 2 aligned controls
  • Improved local development environments, release reliability, and platform stability for customer-facing services

Senior Systems Engineer at 10up

Aug 2014 to Jan 2018

Designed and operated AWS-hosted environments for enterprise publishing clients (Microsoft, ESPN, Adobe, and others): deployment, scaling, Linux platform support, and production operations.

  • Built container infrastructure with Ansible and Kubernetes; automated deployment and multi-tenant access controls
  • Supported regulated SaaS customer contexts including HIPAA and FedRAMP requirements
  • Owned incident response, maintenance, and after-action reporting for customer-facing outages

Platform Team Lead / Platform Systems Administrator at Hosting.com

May 2011 to Jul 2013

Linux and Windows systems administration for internal and customer-facing servers across a continent-wide managed hosting network.

  • Operated managed cloud and hosting infrastructure supporting HIPAA and FedRAMP customer compliance requirements
  • Led platform team operations as escalation POC: work delegation, kanban workflow management, and cross-team coordination

Red Hat Systems Administrator, OIT at Penn State University

May 2013 to Aug 2014

Linux platform operations for Penn State World Campus web properties and classroom technology during a modernization push from hand-rolled VMs toward infrastructure-as-code and cloud-friendly delivery.

  • Deployed DevOps culture and CI/CD workflow for World Campus web and classroom technology stacks
  • Converted infrastructure to Puppet-based infrastructure as code; transitioned to GitOps for code and platform changes
  • Red Hat Linux administration, patching, and security hardening in a higher-education production environment

Education

Bachelor of Science, Information Sciences and Technology

Certifications: ITIL Foundation (AXELOS, 2014) ยท Puppet Fundamentals (2014)

Side Projects

A few things I do on the side, alongside my work at Chia.

Bastion Cyber Security

2023 to Present

Architecture review, threat modeling, penetration testing coordination, and incident remediation for medium to large businesses.

Aetherguard

2025 to Present

Software-based signals intelligence for remote work, crypto asset holders, and high net worth individuals.

Vericreate

2026 to Present

Protect the Human Element in an Agentic Future. Cryptographically-backed proof of human contribution for students, educators, and academic integrity programs, as well as artists, coders, and designers.

What Colleagues Say

Colleagues from my enterprise platform security leadership at T-Mobile.

"Justin's approach to technology is rooted by his passion to always do what's right for his customers. Technology landscapes can be confusing and chaotic, but are ripe for Justin's ability to break down the concepts in simple terms and ensure there is continued progress. Justin is an asset for any team looking to build for the future."

Chris Hill Speaker, author, leader, evangelist, engineer, researcher, and disruptor in developer relations and experience View on LinkedIn

"Justin was a huge part of an important cultural and technical shifts within T-Mobile that brought the T-Mobile 'customer first' attitude to our internal collaborations. Justin and team worked tirelessly to advocate for, overhaul, and automate stale business processes that were holding us back. As a result, we were able to move FAST to adopt and succeed with the Continuous Delivery Platform. My team has since enjoyed faster throughput, greater stability, and improved resiliency as a direct result of Justin's efforts."

"There are some people you work with where you're able to go 'oh so-and-so is taking care of that now' and you can just stop worrying about it getting done right. Justin is one of those people. Justin was a huge huge part of operationalizing GitLab for all of T-Mobile. I watched him shepherd a company that 'wasn't sure about this whole SaaS thing' into being comfortable leveraging a modern Git forge to deliver production software, and he did it in a way that kept internal developers, as the primary internal customer and sole source of value in a technology company, at the center, which was not by any means always easy to do."

"I had the privilege of working with Justin on a large job. Things were going sideways due to various factors, as things sometimes do. Justin stepped up; and through his can-do attitude, excellent architect skills, strong engineering understanding, and insightful leadership kept the situation from spiraling out of control. He utilized clear communication channels and frequent communications to keep teams informed of progress and next steps, reducing the stress of all involved. Justin has been added to the small list of people I trust. I would 110% work with Justin again given the chance."

Mike Lindsay Senior Practice Engineer, Partner Enablement at GitLab Inc. View on LinkedIn

"Justin is a top-notch Engineer that can easily become an invaluable 'Swiss Army Knife' for any team. He picks up new technologies quickly, adapts to situations with ease, and is a downright pleasure to work with. He has a 'can-do' attitude and I've witnessed him wield that attitude to conquer some massive problems. I highly recommend Justin and think he would be a great addition to any team."

Joe Searcy Staff Engineer, CNCF Ambassador, Kubernetes, Service Mesh, Policy-as-Code, Distributed Systems View on LinkedIn

See all recommendations on LinkedIn

Happy to talk about secure platform leadership, IT service delivery, DevOps at scale, custody and signing architecture, GRC, or how to run reliable services without wasting money.

Get in touch