Head of Application Security

theapexgroup

Cape Town

On-site

ZAR 2,400,000 - 4,200,000

Full time

3 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

The Apex Group seeks a Head of Application Security to lead and mature its global security capability. This senior role defines strategy, sets standards, and drives execution across Application Security, DevSecOps, AI Security, and Cloud-Native Security Engineering.

You will ensure security is embedded by design throughout the technology lifecycle, enabling rapid and safe innovation while complying with regulatory and business requirements.

Qualifications

  • 10+ years in cybersecurity, software engineering, or platform engineering roles.
  • 8+ years in senior management positions within security engineering, architecture, or similar leadership roles, with proven accountability for strategy, team leadership and delivery of enterprise-scale security programs.

Responsibilities

  • Define and own the global Application Security strategy aligned to Apex's cyber risk posture and regulatory obligations.
  • Ensure developers meet KPI's and business deliverables.
  • Ensure developers keep up with emerging threats and technologies.
  • Lead and develop multiple security engineering teams across Application Security, DevSecOps, AI & Data Security, and Cloud & Infrastructure Developer Platform Security.
  • Serve as the senior security authority for application, platform, and DevSecOps-related design and engineering decisions.
  • Ensure security controls are documented and embedded throughout the SDLC and CI/CD pipelines.
  • Oversee application threat modelling, secure design reviews, and architecture risk assessments.
  • Drive adoption of secure coding standards, automated security testing (SAST, DAST, SCA), and secrets management.
  • Provide oversight on cloud-native and infrastructure security patterns in hybrid and multi-cloud environments.
  • Define security guardrails for AI-enabled applications, data pipelines, and emerging technologies.
  • Partner with Architecture, Engineering, Cloud, and Platform teams to deliver secure-by-default solutions.
  • Translate security policies and standards into practical, consumable engineering guidance.
  • Communicate application and platform risk to senior leadership and governance forums.
  • Support audit, regulatory, penetration testing and assurance activities related to application and platform security.
  • Execute delegated tasks as deemed appropriate by the Group CISO and other empowered Group Cyber leadership authorities, ensuring timely and effective completion in alignment with organizational priorities.
  • Support the Group Cyber Strategy end-to-end, driving alignment of all activities, decisions, and deliverables with strategic objectives and business outcomes.

Skills

Security leadership
App security architecture
Threat modeling
DevSecOps
Cloud security
API security
Microservices security
Regulatory compliance
Leadership

Tools

GitLab
GitHub

Job description

The Apex Group was established in Bermuda in 2003 and is now one of the world's largest fund administration and middle office solutions providers. Our business is unique in its ability to reach globally, service locally and provide cross-jurisdictional services. With our clients at the heart of everything we do, our hard-working team has successfully delivered on an unprecedented growth and transformation journey, and we are now represented by over circa 13,000 employees across 112 offices worldwide.Your career with us should reflect your energy and passion.

That's why, at Apex Group, we will do more than simply 'empower' you. We will work to supercharge your unique skills and experience.

Take the lead and we'll give you the support you need to be at the top of your game. And we offer you the freedom to be a positive disrupter and turn big ideas into bold, industry-changing realities.

For our business, for clients, and for you

The Role

Apex is seeking a Head of Application Security to lead and mature its global Application Security capability. This is a senior leadership position responsible for defining strategy, setting standards, and driving execution across key domains: Application Security, DevSecOps, AI Security, and Cloud-Native Application Security[WJ1.1] Engineering. As the Apex's senior authority for secure software and platform delivery, you will ensure that security is embedded by design throughout the technology lifecycle-enabling engineering teams to innovate rapidly and safely while maintaining compliance with regulatory and business requirements.

Key Responsibilities
  • Define and own the global Application Security strategy aligned to Apex's cyber risk posture and regulatory obligations.
  • Ensure developers meet KPI's and business deliverables.
  • Ensure developers keep up with emerging threats and technologies.
  • Lead and develop multiple security engineering teams across Application Security, DevSecOps, AI & Data Security[WJ3.1], and Cloud & Infrastructure[WJ4.1] Developer Platform Security.
  • Serve as the senior security authority for application, platform, and DevSecOps-related design and engineering decisions.
  • Ensure security controls are documented and [WJ5.1]embedded throughout the software development lifecycle (SDLC) and CI/CD pipelines.
  • Oversee application threat modelling, secure design reviews, and architecture risk assessments.
  • Drive adoption of secure coding standards, automated security testing (SAST, DAST, SCA), and secrets management.
  • Provide oversight on cloud-native and infrastructure security patterns in hybrid and multi-cloud environments.
  • Define security guardrails for AI-enabled applications, data pipelines, and emerging technologies.
  • Partner with Architecture, Engineering, Cloud, and Platform teams to deliver secure-by-default solutions.
  • Translate security policies and standards into practical, consumable engineering guidance.
  • Communicate application and platform risk to senior leadership and governance forums.
  • Support audit, regulatory, penetration testing and[WJ6.1] assurance activities related to application and platform security.
  • Execute delegated tasks as deemed appropriate by the Group CISO and other empowered Group Cyber leadership authorities, ensuring timely and effective completion in alignment with organizational priorities.
  • Support the Group Cyber Strategy end-to-end, driving alignment of all activities, decisions, and deliverables with strategic objectives and business outcomes.
Areas of Specialization
  • Application Security: Secure software architecture, threat modeling, secure design reviews, vulnerability management, and secure coding practices.
  • DevSecOps: CI/CD pipeline security, automation of security controls, integration of security tooling, and developer enablement.
  • Cloud & Infrastructure Security: Secure cloud-native architectures, infrastructure-as-code security, and platform hardening across hybrid and multi-cloud environments.
  • AI Security: Security and governance controls for AI-enabled applications, data pipelines, and emerging technologies.
Required Experience & Skills
  • Experience:
    • 10+ years in cybersecurity, software engineering, or platform engineering roles.
    • 8+ years in senior management positions within security engineering, architecture, or similar leadership roles, with proven accountability for strategy, team leadership and delivery of enterprise-scale security programs.
  • Technical Expertise: [WJ7.1]
    • Strong hands-on understanding of application security architecture, threat modeling, and DevSecOps practices.
    • Proven experience in securing microservices architecture and API ecosystems.
    • Knowledge of Gitlab, GitHub and API security and integrations.
    • Experience securing applications and platforms in cloud environments (Azure, AWS and OCI).
    • Deep knowledge of security principles, secure design patterns, and defense-in-depth strategies.
  • Knowledge of Standards: [WJ8.1]
    • Familiarity w
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Head of Application Security
Head of Application Security

Apex Group Ltd (UK Branch) • Cape Town

On-site
ZAR 1,000,000 - 1,500,000
Opportunity for career growth
Collaboration with senior leaders
Head of Enterprise Security Architecture & Projects
Head of Enterprise Security Architecture & Projects

theapexgroup • Cape Town

On-site
ZAR 3,000,000 - 4,600,000
Senior Security Engineer
Senior Security Engineer

Apex Group Ltd • Cape Town

On-site
ZAR 900,000 - 1,600,000
Global Head of Application Security & DevSecOps
Global Head of Application Security & DevSecOps

theapexgroup • Cape Town

On-site
ZAR 2,400,000 - 4,200,000
Global Head of Application Security & DevSecOps
Global Head of Application Security & DevSecOps

Apex Group Ltd (UK Branch) • Cape Town

On-site
ZAR 1,000,000 - 1,500,000
Opportunity for career growth
Collaboration with senior leaders
Head of Enterprise Security Architecture & Projects
Head of Enterprise Security Architecture & Projects

Apex Group Ltd • Cape Town

On-site
ZAR 900,000 - 1,200,000
Leadership development opportunities
Exposure to large-scale transformation projects
Global collaboration with technology leaders
Head of Enterprise Security Architecture & Projects
Head of Enterprise Security Architecture & Projects

Apex Group • Cape Town

On-site
ZAR 1,800,000 - 2,800,000
Security Support Analyst – Identity and Access Management
Security Support Analyst – Identity and Access Management

Apex Group Ltd • Cape Town

On-site
ZAR 600,000 - 900,000
Chief Enterprise Security Architect & Projects Lead
Chief Enterprise Security Architect & Projects Lead

Apex Group • Cape Town

On-site
ZAR 1,800,000 - 2,800,000
Information Security Manager - MEA
Information Security Manager - MEA

theapexgroup • Cape Town

On-site
ZAR 1,200,000 - 1,800,000