Application Security Architect

Brak informacji o wynagrodzeniu
SeniorFull-time
#446910·Dodano dziś·0
Źródło: Capital.com
Aplikuj teraz

Tech Stack / Keywords

AWSGCPOWASPSASTDASTIASTSCADockerKubernetesGraphQL

Firma i stanowisko

Capital.com builds and operates web and mobile trading platforms, public and partner APIs, and backend services in a highly regulated environment.

Wymagania

Experience:

  • 8+ years in technology including 5+ years in dedicated application or product security role with strong engineering background and hands-on architecture or design ownership
  • Proven track record creating, documenting, and rolling out security standards, patterns, and best practices across complex engineering organizations
  • Deep, demonstrable threat-modelling experience across product portfolios

Technical:

  • Experience designing and implementing secure SDLC in cloud-native environments; strong AWS knowledge required; exposure to GCP or other clouds welcome
  • Strong command of OWASP standards (Top 10, ASVS) and DevSecOps practice including AppSec tooling (SAST, DAST, IAST, SCA, secrets scanning) and vulnerability management
  • Deep understanding of modern distributed architectures: microservices, REST and GraphQL APIs, event-driven systems, OAuth2/OIDC, containerized workloads (Docker, Kubernetes), and reasoning about trust boundaries, attack surface, and data flows across web and mobile clients

Collaboration:

  • Exceptional ability to influence and align engineering teams without direct authority, briefing engineers and executives
  • Pragmatism and strategic thinking balancing ideal with achievable, protecting delivery throughput, and turning direction into actionable plans
  • Clear written communication through diagrams, ADRs, patterns; mentoring and cross-functional collaboration

Obowiązki

Security Architecture & Standards:

  • Define and maintain secure-by-default reference architectures for common patterns: web apps, mobile backends, microservices, public and partner APIs, and event-driven services
  • Own core application security architecture decisions including authentication and authorisation, session management, API security, secrets management, multi-tenant isolation, and security logging and auditing
  • Lead the redesign of user authentication and the delivery of security features into the product
  • Develop and roll out application security standards, secure-coding guidelines, configuration standards, reusable design patterns, and architecture decision records (ADRs)
  • Define internal policies for the safe use of AI-assisted and vibe-coding tools
  • Define security requirements for acquired technology and guide its secure integration

Threat Modelling & Design Review:

  • Establish and run a threat-modelling operating model covering scope, cadence, templates, and facilitation proportionate to each product's risk tier
  • Own the security review stage of the new product approval process, covering architecture design and configuration
  • Lead design reviews for high-impact initiatives such as new products, new auth flows, payment and sensitive-data flows, platform migrations, and major refactors
  • Identify design-level risks and agree practical, prioritised mitigations with engineering teams

Secure SDLC, DevSecOps & Supply Chain:

  • Assess current state of application security, propose improvements, and drive secure SDLC strategy with Engineering and Security leadership
  • Oversee AppSec processes and own the tooling strategy including SAST, DAST, IAST, SCA, and secrets scanning, including how findings flow back to engineering
  • Embed security controls as guardrails in CI/CD through policy-as-code with agreed enforcement and escalation paths
  • Partner with DevOps to organise repository management and prevent supply-chain attacks, covering safe component usage, dependency management, SBOMs, and build integrity
  • Improve security of internal tools

Benefity

  • Annual Bonus based on performance review cycle
  • Generous Annual Leave Policy
  • Medical Insurance and Pension fund with additional benefits based on location
  • Hybrid working model: 3 days from office and 2 days fully remote
  • Comprehensive Workation Policy with 30 additional remote days available
  • Possibility of taking two additional paid leave days per year for volunteering efforts
Premie
Płatny urlop
Opieka zdrowotna
Capital.com

Capital.com

14 aktywnych ofert

Zobacz wszystkie oferty
Aplikuj teraz