Verified from career page · Posted 5d ago

Capital.com

Application Security Architect

Capital.com · Technology

Warsaw

Mid-level

SecurityAWSCI/CDDevSecOpsDockerEvent-drivenGCPGraphQLKubernetesMicroservicesOAuth / OIDCOWASP

Last seen yesterday

Posted
5d ago

Posted on 29 September 2026

Workplace
Hybrid

Work model: Hybrid

Salary
Not disclosed

Salary range not shared by the company

Visa sponsorship
Not specified

Visa sponsorship details unknown

Capital.com builds and operates web and mobile trading platforms, public and partner APIs, and the backend services behind them, all in a highly regulated environment. As Application Security Architect, you will be the senior design authority for the security of these products. You will set the direction for how we secure software at scale: you will own secure-by-design patterns and standards, lead threat modelling and architecture reviews, and define the application security baseline that engineering teams build against.

Working closely with the Product Security team and the Director of Product Security, you will guide AppSec processes and set the vision for your area without direct line management. You will treat security as a shared outcome rather than a gate, balancing strong protection with developer experience and delivery speed, and you will earn adoption through enablement rather than mandates.

\n

Responsibilities:

Security Architecture & Standards:

Define and maintain secure-by-default reference architectures for common patterns: web apps, mobile backends, microservices, public and partner APIs, and event-driven services

Own core application security architecture decisions: authentication and authorisation, session management, API security, secrets management, multi-tenant isolation, and security logging and auditing

Lead the redesign of user authentication and the delivery of security features into the product

Develop and roll out application security standards, secure-coding guidelines, configuration standards, reusable design patterns, and architecture decision records (ADRs) that engineers can apply without a security expert in the room

Define internal policies for the safe use of AI-assisted and vibe-coding tools

Define security requirements for acquired technology and guide its secure integration

Threat Modelling & Design Review:

Establish and run a threat-modelling operating model, covering scope, cadence, templates, and facilitation, proportionate to each product's risk tier

Own the security review stage of the new product approval process, covering architecture design and configuration

Lead design reviews for high-impact initiatives: new products, new auth flows, payment and sensitive-data flows, platform migrations, and major refactors

Identify design-level risks and agree practical, prioritised mitigations with engineering teams

Secure SDLC, DevSecOps & Supply Chain:

Assess the current state of application security, propose improvements, and drive the secure SDLC strategy with Engineering and Security leadership

Oversee AppSec processes and own the tooling strategy (SAST, DAST, IAST, SCA, and secrets scanning), including how findings flow back to engineering

Embed security controls as guardrails in CI/CD through policy-as-code, with agreed enforcement and escalation paths

Partner with DevOps to organise repository management and prevent supply-chain attacks, covering safe component usage, dependency management, SBOMs, and build integrity

Improve the security of our internal tools

Requirements:

Experience:

8+ years in technology, including 5+ years in a dedicated application or product security role, with a strong engineering background and hands-on architecture or design ownership

Proven track record creating, documenting, and rolling out security standards, patterns, and best practices across a complex engineering organisation

Deep, demonstrable threat-modelling experience across product portfolios

Technical:

Experience designing and implementing a secure SDLC in a cloud-native environment. Strong AWS knowledge is required, and exposure to GCP or other clouds is welcome

Strong command of OWASP standards (Top 10, ASVS) and DevSecOps practice, including AppSec tooling (SAST, DAST, IAST, SCA, secrets scanning) and vulnerability management

Deep understanding of modern distributed architectures: microservices, REST and GraphQL APIs, event-driven systems, OAuth2/OIDC, and containerised workloads (Docker, Kubernetes). You should be able to reason about their trust boundaries, attack surface, and data flows across web and mobile clients

Collaboration:

Exceptional ability to influence and align engineering teams without direct authority, and to brief both engineers and executives

Pragmatism and strategic thinking: you balance the ideal with the achievable, protect delivery throughput, and turn long-term direction into an actionable plan

Clear written communication through diagrams, ADRs, and patterns, plus a track record of mentoring and cross-functional collaboration

Nice to have:

Experience in fintech, trading, brokerage, or another regulated environment

Awareness of relevant regulatory and compliance drivers: FCA and CySEC operational resilience, GDPR, and PCI DSS

Software supply-chain security, including SBOMs and artifact and build integrity

Experience securing AI-integrated product features, or using AI to scale an AppSec programme

Experience building or running a Security Champions programme

CSSLP, GIAC GDSA, or a hands-on offensive security certification. Certifications are valued but secondary to demonstrated experience

What you'll get in return:

You will join the company, that cares about work and life balance

Annual Bonus based on the performance review cycle

Generous Annual Leave Policy

Medical Insurance and Pension fund, with additional benefit packages based on the location

Hybrid working model (3 days from our modern office and 2 days fully remotely)

Comprehensive Workation Policy with 30 more remote days available.

Possibility of taking two additional days of paid leave per year to dedicate to volunteering efforts.

\n

About Capital.com

Capital.com is an online trading platform for CFDs and investing. A fintech with product and engineering across Europe.

Apply at Capital.com

Similar roles

  1. PRO members only Pro Remote
  2. Data Engineer (Data Engineering Team) Hybrid Capital.com Product & Engineering Warsaw DataAirflowAWSdbt +6 High-growth Not disclosed Visa: Not specified 4d ago
  3. Reconciliations Manager Hybrid Capital.com Digital Assets Cyprus High-growth Not disclosed Visa: Not specified 5d ago
  4. Senior Application Security Engineer Hybrid Capital.com Technology Warsaw SecurityAWSCI/CDJavaScript +6 High-growth Not disclosed Visa: Not specified 5d ago
  5. Senior Workplace Experience Coordinator On-site Capital.com People Warsaw People & HR High-growth Not disclosed Visa: Not specified 5d ago
  6. IAM Specialist Hybrid Capital.com Technology Warsaw SecurityAWS High-growth Not disclosed Visa: Not specified 6d ago
1,427 more roles like this. Open the board →