Application Security Architect

Lever, Inc.

Warszawa

Hybrid

PLN 260,000 - 380,000

Full time

3 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

Annual bonus
Generous annual leave
Medical insurance
Pension fund
Hybrid work model
Remote work days
Workation policy
Volunteer leave

Job summary

Capital.com builds and operates web and mobile trading platforms, public and partner APIs, and backend services in a regulated environment. As Application Security Architect, you will be the senior design authority for the security of these products, owning secure-by-design patterns and standards, lead threat modelling and architecture reviews.

You will guide AppSec processes, balance protection with developer experience, and earn adoption through enablement rather than mandates.

Qualifications

  • 8+ years in technology with 5+ years in application/security design ownership.
  • Proven track record creating and rolling out security standards across a complex org.
  • Deep threat-modelling experience across product portfolios.

Responsibilities

  • Define and maintain secure-by-default reference architectures for web apps, mobile backends, and APIs.
  • Own core application security architecture decisions: auth, API security, secrets, multi-tenant isolation, logging.
  • Lead redesign of user authentication and security feature delivery.
  • Develop and roll out security standards, secure-coding guidelines, and ADRs.
  • Define security requirements for acquired tech and its integration.

Skills

Threat modelling
Security architecture
Cloud security
Influence without authority
Mentoring

Tools

SAST
DAST
IAST
SCA
Secrets scanning

Job description

Capital.com builds and operates web and mobile trading platforms, public and partner APIs, and the backend services behind them, all in a highly regulated environment. As Application Security Architect, you will be the senior design authority for the security of these products. You will set the direction for how we secure software at scale: you will own secure-by-design patterns and standards, lead threat modelling and architecture reviews, and define the application security baseline that engineering teams build against.

Working closely with the Product Security team and the Director of Product Security, you will guide AppSec processes and set the vision for your area without direct line management. You will treat security as a shared outcome rather than a gate, balancing strong protection with developer experience and delivery speed, and you will earn adoption through enablement rather than mandates.

Responsibilities:
  • Define and maintain secure-by-default reference architectures for common patterns: web apps, mobile backends, microservices, public and partner APIs, and event-driven services
  • Own core application security architecture decisions: authentication and authorisation, session management, API security, secrets management, multi-tenant isolation, and security logging and auditing
  • Lead the redesign of user authentication and the delivery of security features into the product
  • Develop and roll out application security standards, secure-coding guidelines, configuration standards, reusable design patterns, and architecture decision records (ADRs) that engineers can apply without a security expert in the room
  • Define internal policies for the safe use of AI-assisted and vibe-coding tools
  • Define security requirements for acquired technology and guide its secure integration
Threat Modelling & Design Review:
  • Establish and run a threat-modelling operating model, covering scope, cadence, templates, and facilitation, proportionate to each product's risk tier
  • Own the security review stage of the new product approval process, covering architecture design and configuration
  • Lead design reviews for high-impact initiatives: new products, new auth flows, payment and sensitive-data flows, platform migrations, and major refactors
  • Identify design-level risks and agree practical, prioritised mitigations with engineering teams
Secure SDLC, DevSecOps & Supply Chain:
  • Assess the current state of application security, propose improvements, and drive the secure SDLC strategy with Engineering and Security leadership
  • Oversee AppSec processes and own the tooling strategy (SAST, DAST, IAST, SCA, and secrets scanning), including how findings flow back to engineering
  • Embed security controls as guardrails in CI/CD through policy-as-code, with agreed enforcement and escalation paths
  • Partner with DevOps to organise repository management and prevent supply-chain attacks, covering safe component usage, dependency management, SBOMs, and build integrity
  • Improve the security of our internal tools
Requirements:
Experience:
  • 8+ years in technology, including 5+ years in a dedicated application or product security role, with a strong engineering background and hands‑on architecture or design ownership
  • Proven track record creating, documenting, and rolling out security standards, patterns, and best practices across a complex engineering organisation
  • Deep, demonstrable threat-modelling experience across product portfolios
Technical:
  • Experience designing and implementing a secure SDLC in a cloud-native environment. Strong AWS knowledge is required, and exposure to GCP or other clouds is welcome
  • Strong command of OWASP standards (Top 10, ASVS) and DevSecOps practice, including AppSec tooling (SAST, DAST, IAST, SCA, secrets scanning) and vulnerability management
  • Deep understanding of modern distributed architectures: microservices, REST and GraphQL APIs, event-driven systems, OAuth2/OIDC, and containerised workloads (Docker, Kubernetes). You should be able to reason about their trust boundaries, attack surface, and data flows across web and mobile clients
Collaboration:
  • Exceptional ability to influence and align engineering teams without direct authority, and to brief both engineers and executives
  • Pragmatism and strategic thinking: you balance the ideal with the achievable, protect delivery throughput, and turn long-term direction into an actionable plan
  • Clear written communication through diagrams, ADRs, and patterns, plus a track record of mentoring and cross-functional collaboration
Nice to have:
  • Experience in fintech, trading, brokerage, or another regulated environment
  • Awareness of relevant regulatory and compliance drivers: FCA and CySEC operational resilience, GDPR, and PCI DSS
  • Software supply-chain security, including SBOMs and artifact and build integrity
  • Experience securing AI-integrated product features, or using AI to scale an AppSec programme
  • Experience building or running a Security Champions programme
  • CSSLP, GIAC GDSA, or a hands‑on offensive security certification. Certifications are valued but secondary to demonstrated experience
What you'll get in return:
  • You will join the company, that cares about work and life balance
  • Annual Bonusbased on the performance review cycle
  • Generous Annual Leave Policy
  • Medical Insurance and Pension fund, with additional benefit packages based on the location
  • Hybrid working model (3 days from our modern office and 2 days fully remotely)
  • Comprehensive Workation Policy with30 more remote daysavailable.
  • Possibility of taking two additional days of paid leave per year to dedicate to volunteering efforts.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Application Security Architect
Application Security Architect

Capital • Warszawa

Hybrid
PLN 250,000 - 400,000
Annual bonus
Generous annual leave
Medical insurance
+4
Senior Application Security Engineer
Senior Application Security Engineer

Capital • Warszawa

Hybrid
PLN 320,000 - 460,000
Hybrid work model
Medical insurance
Pension fund
+4
Senior Application Security Engineer
Senior Application Security Engineer

Lever, Inc. • Warszawa

Hybrid
PLN 260,000 - 380,000
Annual bonus
Medical Insurance
Hybrid work model
Application Security Engineer
Application Security Engineer

Solidgate • Województwo mazowieckie

On-site
PLN 167,400 - 279,000
30+ days off
Unlimited sick leave
Free office meals
+2
Application Security Engineer
Application Security Engineer

SOFTSWISS • Warszawa

On-site
PLN 60,000 - 90,000
Full-time remote work opportunities
Private insurance
Additional 1 Day Off per calendar year
+5
Application Security Engineer
Application Security Engineer

SOFTSWISS • Poland

On-site
PLN 218,579 - 327,869
Full-time remote work opportunities
Private insurance
Sports program compensation
+2
Senior Cybersecurity Architect
Senior Cybersecurity Architect

bolttech • Poland

On-site
PLN 250,000 - 380,000
Application Security Engineer
Application Security Engineer

Papaya Global • Kraków

On-site
PLN 300,000 - 420,000
Application Security Engineer (F/M)
Application Security Engineer (F/M)

AXA IT Solutions • Warszawa

Hybrid
PLN 180,000 - 240,000
The opportunity to influence product方向
Ambitious projects with high autonomy
Hybrid work model
Security Architect at Capital.Com
Security Architect at Capital.Com

Capital.Com • Warszawa

On-site
PLN 300,000 - 480,000
Generous annual leave
Health & pension benefits
Workation opportunities
+2