Senior Application Security Engineer
Brak informacji o wynagrodzeniu
SeniorFull-time
#446911·Dodano dziś·0
Źródło: Capital.comTech Stack / Keywords
PythonGoJavaScriptOWASP Top TenSASTDASTSCACI/CDKubernetesAWS
Firma i stanowisko
Capital.com's Product Security team operates in a highly regulated environment protecting web and mobile applications, infrastructure, and external perimeter.
Wymagania
Experience:
- 5+ years in application or product security with senior or staff-level impact.
- Experience leading security architecture reviews and threat modelling (e.g. STRIDE, attack trees, data-flow analysis) across multiple teams or products.
- Proven ability to automate and scale security processes via tooling and self-service workflows.
Technical:
- Strong hands-on security testing skills including code review and security assessments of web, mobile, and API applications.
- Ability to triage and validate external vulnerability reports and bug bounty submissions.
- Strong software engineering ability in at least one language (e.g. Python, Go, JavaScript) to build automation.
- Deep understanding of the OWASP Top Ten, secure design, and secure coding best practices.
- Experience with SAST, DAST, SCA, and vulnerability management platforms integrated into CI/CD.
- Strong understanding of modern application architectures including REST APIs, microservices, cloud-based systems, and containers.
- Practical experience or enthusiasm for applying AI and LLM tooling to security work.
Collaboration:
- Excellent communication and influencing skills to explain security concepts to technical and non-technical stakeholders.
- Self-starter who solves complex problems, builds leverage through automation, mentors others, and strengthens security culture.
Nice to have:
- Experience securing AI harness including hardening LLM and agent pipelines against prompt injection and data leakage.
- Experience securing Kubernetes clusters covering hardening, RBAC, network policies, and supply-chain security.
- Experience securing AWS infrastructure including IAM, network architecture, key and secret management.
- Experience building AI-assisted security tooling or internal self-service security platforms.
- Experience mentoring or technically leading a security team.
- Offensive or advanced security certifications such as OSAI, OSEP, OSCP, or OSWE.
Obowiązki
Security Architecture & Threat Modelling:
- Lead security architecture reviews and threat modelling for new and existing systems using AI tools.
- Influence standards, patterns, and guardrails to enable fast and secure team operations.
Security Automation & Tooling:
- Design, build, and automate scalable security processes for self-serve use.
- Integrate and automate security checks across SDLC and CI/CD pipelines including SAST, DAST, SCA, secrets, and IaC scanning.
- Own and evolve security tooling such as DefectDojo and SAST, DAST, and SCA platforms.
- Apply AI and LLM-based tooling to architecture review, threat modelling, code review, and vulnerability triage.
Security Testing & Vulnerability Management:
- Conduct and oversee security assessments of web and mobile applications, APIs, and cloud infrastructure.
- Run vulnerability scans on internal infrastructure and external perimeter, analyze findings, define remediation, and track issues to closure.
- Support and triage Bug Bounty Program and external vulnerability reports, automating triage where possible.
- Participate in and help lead red teaming and offensive security exercises.
Enablement:
- Drive knowledge sharing on secure development.
- Mentor engineers and deliver training for development and QA teams.
Benefity
- Annual Bonus based on performance reviews.
- Generous Annual Leave Policy.
- Medical Insurance and Pension fund with location-based additional benefits.
- Hybrid working model: 3 days in office and 2 days remote.
- Comprehensive Workation Policy with 30 additional remote days.
- Possibility of two additional paid leave days for volunteering efforts.
Premie
Płatny urlop
Opieka zdrowotna
Capital.com
14 aktywnych ofert