About this role
Responsibilities:
Security Architecture & Standards:
- Define and maintain secure-by-default reference architectures for common patterns: web apps, mobile backends, microservices, public and partner APIs, and event-driven services
- Own core application security architecture decisions: authentication and authorisation, session management, API security, secrets management, multi-tenant isolation, and security logging and auditing
- Lead the redesign of user authentication and the delivery of security features into the product
- Develop and roll out application security standards, secure-coding guidelines, configuration standards, reusable design patterns, and architecture decision records (ADRs) that engineers can apply without a security expert in the room
- Define internal policies for the safe use of AI-assisted and vibe-coding tools
- Define security requirements for acquired technology and guide its secure integration
Threat Modelling & Design Review:
- Establish and run a threat-modelling operating model, covering scope, cadence, templates, and facilitation, proportionate to each product's risk tier
- Own the security review stage of the new product approval process, covering architecture design and configuration
- Lead design reviews for high-impact initiatives: new products, new auth flows, payment and sensitive-data flows, platform migrations, and major refactors
- Identify design-level risks and agree practical, prioritised mitigations with engineering teams
Secure SDLC, DevSecOps & Supply Chain:
- Assess the current state of application security, propose improvements, and drive the secure SDLC strategy with Engineering and Security leadership
- Oversee AppSec processes and own the tooling strategy (SAST, DAST, IAST, SCA, and secrets scanning), including how findings flow back to engineering
- Embed security controls as guardrails in CI/CD through policy-as-code, with agreed enforcement and escalation paths
- Partner with DevOps to organise repository management and prevent supply-chain attacks, covering safe component usage, dependency management, SBOMs, and build integrity
- Improve the security of our internal tools
Requirements:
Experience:
- 8+ years in technology, including 5+ years in a dedicated application or product security role, with a strong engineering background and hands-on architecture or design ownership
- Proven track record creating, documenting, and rolling out security standards, patterns, and best practices across a complex engineering organisation
- Deep, demonstrable threat-modelling experience across product portfolios
Technical:
- Experience designing and implementing a secure SDLC in a cloud-native environment. Strong AWS knowledge is required, and exposure to GCP or other clouds is welcome
- Strong command of OWASP standards (Top 10, ASVS) and DevSecOps practice, including AppSec tooling (SAST, DAST, IAST, SCA, secrets scanning) and vulnerability management
- Deep understanding of modern distributed architectures: microservices, REST and GraphQL APIs, event-driven systems, OAuth2/OIDC, and containerised workloads (Docker, Kubernetes). You should be able to reason about their trust boundaries, attack surface, and data flows across web and mobile clients
Collaboration:
- Exceptional ability to influence and align engineering teams without direct authority, and to brief both engineers and executives
- Pragmatism and strategic thinking: you balance the ideal with the achievable, protect delivery throughput, and turn long-term direction into an actionable plan
- Clear written communication through diagrams, ADRs, and patterns, plus a track record of mentoring and cross-functional collaboration
Nice to have:
- Experience in fintech, trading, brokerage, or another regulated environment
- Awareness of relevant regulatory and compliance drivers: FCA and CySEC operational resilience, GDPR, and PCI DSS
- Software supply-chain security, including SBOMs and artifact and build integrity
- Experience securing AI-integrated product features, or using AI to scale an AppSec programme
- Experience building or running a Security Champions programme
- CSSLP, GIAC GDSA, or a hands-on offensive security certification. Certifications are valued but secondary to demonstrated experience
What you'll get in return:
- You will join the company, that cares about work and life balance
- Annual Bonus based on the performance review cycle
- Generous Annual Leave Policy
- Medical Insurance and Pension fund, with additional benefit packages based on the location
- Hybrid working model (3 days from our modern office and 2 days fully remotely)
- Comprehensive Workation Policy with 30 more remote days available.
- Possibility of taking two additional days of paid leave per year to dedicate to volunteering efforts.