Application Security Architect

Capital.comWarsaw, MazoviaHybridFull-timeMid level, 2–5 yearsListed 2 hours ago

Apply now

About this role

Responsibilities:

Security Architecture & Standards:

- Define and maintain secure-by-default reference architectures for common patterns: web apps, mobile backends, microservices, public and partner APIs, and event-driven services

- Own core application security architecture decisions: authentication and authorisation, session management, API security, secrets management, multi-tenant isolation, and security logging and auditing

- Lead the redesign of user authentication and the delivery of security features into the product

- Develop and roll out application security standards, secure-coding guidelines, configuration standards, reusable design patterns, and architecture decision records (ADRs) that engineers can apply without a security expert in the room

- Define internal policies for the safe use of AI-assisted and vibe-coding tools

- Define security requirements for acquired technology and guide its secure integration

Threat Modelling & Design Review:

- Establish and run a threat-modelling operating model, covering scope, cadence, templates, and facilitation, proportionate to each product's risk tier

- Own the security review stage of the new product approval process, covering architecture design and configuration

- Lead design reviews for high-impact initiatives: new products, new auth flows, payment and sensitive-data flows, platform migrations, and major refactors

- Identify design-level risks and agree practical, prioritised mitigations with engineering teams

Secure SDLC, DevSecOps & Supply Chain:

- Assess the current state of application security, propose improvements, and drive the secure SDLC strategy with Engineering and Security leadership

- Oversee AppSec processes and own the tooling strategy (SAST, DAST, IAST, SCA, and secrets scanning), including how findings flow back to engineering

- Embed security controls as guardrails in CI/CD through policy-as-code, with agreed enforcement and escalation paths

- Partner with DevOps to organise repository management and prevent supply-chain attacks, covering safe component usage, dependency management, SBOMs, and build integrity

- Improve the security of our internal tools

Requirements:

Experience:

- 8+ years in technology, including 5+ years in a dedicated application or product security role, with a strong engineering background and hands-on architecture or design ownership

- Proven track record creating, documenting, and rolling out security standards, patterns, and best practices across a complex engineering organisation

- Deep, demonstrable threat-modelling experience across product portfolios

Technical:

- Experience designing and implementing a secure SDLC in a cloud-native environment. Strong AWS knowledge is required, and exposure to GCP or other clouds is welcome

- Strong command of OWASP standards (Top 10, ASVS) and DevSecOps practice, including AppSec tooling (SAST, DAST, IAST, SCA, secrets scanning) and vulnerability management

- Deep understanding of modern distributed architectures: microservices, REST and GraphQL APIs, event-driven systems, OAuth2/OIDC, and containerised workloads (Docker, Kubernetes). You should be able to reason about their trust boundaries, attack surface, and data flows across web and mobile clients

Collaboration:

- Exceptional ability to influence and align engineering teams without direct authority, and to brief both engineers and executives

- Pragmatism and strategic thinking: you balance the ideal with the achievable, protect delivery throughput, and turn long-term direction into an actionable plan

- Clear written communication through diagrams, ADRs, and patterns, plus a track record of mentoring and cross-functional collaboration

Nice to have:

- Experience in fintech, trading, brokerage, or another regulated environment

- Awareness of relevant regulatory and compliance drivers: FCA and CySEC operational resilience, GDPR, and PCI DSS

- Software supply-chain security, including SBOMs and artifact and build integrity

- Experience securing AI-integrated product features, or using AI to scale an AppSec programme

- Experience building or running a Security Champions programme

- CSSLP, GIAC GDSA, or a hands-on offensive security certification. Certifications are valued but secondary to demonstrated experience

What you'll get in return:

- You will join the company, that cares about work and life balance

- Annual Bonus based on the performance review cycle

- Generous Annual Leave Policy

- Medical Insurance and Pension fund, with additional benefit packages based on the location

- Hybrid working model (3 days from our modern office and 2 days fully remotely)

- Comprehensive Workation Policy with 30 more remote days available.

- Possibility of taking two additional days of paid leave per year to dedicate to volunteering efforts.