
Senior Application Security Engineer
capital.com8 hours ago
Limassol, Cyprus or Warsaw, PolandSenior
Responsibilities
- Lead security architecture reviews and threat modeling for new and existing systems.
- Define security standards, patterns, and guardrails across engineering teams.
- Build scalable security automation, integrations, and self-service workflows.
- Integrate and tune security checks across development and CI/CD processes.
- Own and evolve DefectDojo and SAST, DAST, and SCA platforms.
- Apply AI and LLM tooling to architecture review, threat modeling, code review, and vulnerability triage.
- Conduct security assessments of web and mobile applications, APIs, and cloud infrastructure.
- Run vulnerability scans, analyze findings, define remediation, and track issues to closure.
- Support bug bounty and external vulnerability report triage.
- Participate in and help lead red teaming and offensive security exercises.
- Share security knowledge, mentor engineers, and train development and QA teams.
Requirements
- At least 5 years of application or product security experience, or equivalent depth, with senior- or staff-level impact.
- Experience leading security architecture reviews and threat modeling across multiple teams or products.
- Experience building tooling, integrations, and self-service workflows to automate and scale security processes.
- Strong hands-on security testing, code review, web application, mobile application, and API security assessment skills.
- Ability to triage and validate external vulnerability reports and bug bounty submissions.
- Strong software engineering ability in at least one language, such as Python, Go, or JavaScript.
- Deep understanding of the OWASP Top Ten, secure design, and secure coding practices.
- Experience with SAST, DAST, SCA, vulnerability management platforms, and CI/CD integration.
- Understanding of modern application architectures, REST APIs, microservices, cloud systems, and containers.
- Practical experience applying AI and LLM tooling to security work, or clear aptitude to do so.
- Preferred experience securing LLM and agent pipelines, Kubernetes, and AWS infrastructure.
- Preferred experience building AI-assisted security tooling or internal self-service security platforms.
- Preferred experience mentoring or technically leading a security team.
- Offensive or advanced security certifications such as OSAI, OSEP, OSCP, or OSWE are desirable.
Benefits
- Annual performance-based bonus.
- Generous annual leave policy.
- Medical insurance and pension fund, with additional benefits based on location.
- Hybrid work model with 3 days in the office and 2 days fully remote.
- Workation policy with 30 additional remote days available.
- Possibility of 2 additional paid leave days per year for volunteering.
- Work-life balance focused workplace.
Tech Stack
Categories
About capital.com
Capital.com is a retail trading platform that lets individuals trade CFDs on shares, indices, forex, commodities, and crypto via web and mobile. Founded in 2016 and privately held, it is headquartered in Limassol, Cyprus, with regulated entities in the UK and EU; it earns revenue from spreads, overnight financing, and other brokerage fees. The platform also offers education resources and real-time market insights.