Application Security Architect
capital · Warsaw, Mazowieckie, Poland ·
- Work mode
- Hybrid
- Category
- Security
- Experience
- 5+ years
capital · Warsaw, Mazowieckie, Poland ·
dPOP · Detroit, Wayne County
Rocket Companies · Seattle - 100 Stewart St
Oceaneering · Houston, TX, United States
Interac · Toronto
Senior application security design authority at Capital.com, a fintech company running web and mobile trading platforms. Day to day: own secure-by-design patterns and standards, lead threat modelling and architecture reviews, and drive the AppSec tooling and secure SDLC strategy across AWS, Kubernetes, OAuth2/OIDC, and DevSecOps tooling.
Capital.com builds and operates web and mobile trading platforms, public and partner APIs, and the backend services behind them, all in a highly regulated environment. As Application Security Architect, you will be the senior design authority for the security of these products. You will set the direction for how we secure software at scale: you will own secure-by-design patterns and standards, lead threat modelling and architecture reviews, and define the application security baseline that engineering teams build against.
Working closely with the Product Security team and the Director of Product Security, you will guide AppSec processes and set the vision for your area without direct line management. You will treat security as a shared outcome rather than a gate, balancing strong protection with developer experience and delivery speed, and you will earn adoption through enablement rather than mandates.
Security Architecture & Standards:
Threat Modelling & Design Review:
Secure SDLC, DevSecOps & Supply Chain:
Experience:
Technical:
Collaboration:
Kyndryl · Madrid, Spain