capital.com

Application Security Architect

capital.com
Apply
8 hours ago
Limassol, Cyprus or Warsaw, PolandSenior

Responsibilities

  • Define and maintain secure-by-default reference architectures for web applications, mobile backends, microservices, APIs, and event-driven services.
  • Own application security architecture decisions involving authentication, authorization, session management, API security, secrets management, multi-tenant isolation, and security logging.
  • Lead authentication redesigns and delivery of security features into products.
  • Develop and roll out secure-coding guidelines, configuration standards, reusable design patterns, architecture decision records, and AI-assisted tooling policies.
  • Establish and operate threat-modeling and security review processes for products and high-impact initiatives.
  • Identify design-level risks and agree on prioritized mitigations with engineering teams.
  • Drive secure SDLC strategy and oversee AppSec tooling, vulnerability management, and security findings workflows.
  • Embed security controls in CI/CD through policy-as-code and partner with DevOps on repository, dependency, SBOM, artifact, and build integrity security.
  • Define security requirements for acquired technology and guide secure integration.
  • Improve the security of internal tools and influence, mentor, and align engineering teams without direct authority.

Requirements

  • 8+ years in technology, including 5+ years in a dedicated application or product security role, with strong engineering and hands-on architecture or design ownership experience.
  • Demonstrated experience creating, documenting, and rolling out security standards, patterns, and best practices across complex engineering organizations.
  • Deep threat-modeling experience across product portfolios.
  • Experience designing and implementing secure SDLC practices in cloud-native environments, with strong AWS knowledge; GCP or other cloud experience is welcome.
  • Strong knowledge of OWASP Top 10, OWASP ASVS, DevSecOps practices, SAST, DAST, IAST, SCA, secrets scanning, and vulnerability management.
  • Deep understanding of distributed architectures, REST and GraphQL APIs, event-driven systems, OAuth2/OIDC, Docker, and Kubernetes, including trust boundaries, attack surfaces, and data flows.
  • Ability to influence engineering teams without direct authority and communicate with engineers and executives.
  • Experience in fintech, trading, brokerage, or regulated environments is preferred.
  • Awareness of FCA and CySEC operational resilience requirements, GDPR, and PCI DSS is preferred.
  • Experience with software supply-chain security, SBOMs, artifact and build integrity, AI-integrated product security, Security Champions programs, or relevant certifications such as CSSLP or GIAC GDSA is preferred.

Benefits

  • Annual performance-based bonus.
  • Generous annual leave policy.
  • Medical insurance, pension fund, and additional location-based benefits.
  • Hybrid working model with 3 days in the office and 2 days fully remote.
  • Workation policy with 30 additional remote days available.
  • Two additional paid volunteering leave days per year.
capital.com

About capital.com

1,001-5,000 employees

Capital.com is a retail trading platform that lets individuals trade CFDs on shares, indices, forex, commodities, and crypto via web and mobile. Founded in 2016 and privately held, it is headquartered in Limassol, Cyprus, with regulated entities in the UK and EU; it earns revenue from spreads, overnight financing, and other brokerage fees. The platform also offers education resources and real-time market insights.

Contact me