Application Security Architect
Core
Senior design authority for security of web/mobile trading platforms, APIs, and backend services in a regulated environment, setting secure-by-design patterns and standards.
Role type
Senior IC Application Security Architect
Builds
Secure-by-default reference architectures, security standards, and guardrails for engineering teams
Domain
Fintech / Trading / Cloud-native security
Required skills
Threat modelling, Secure SDLC strategy, Cloud-native architecture (AWS), DevSecOps tooling (SAST/DAST/IAST/SCA), Distributed systems (microservices, APIs, OAuth2/OIDC, Kubernetes), Policy-as-code, Supply chain security
Preferred skills
Fintech/regulated environment experience, Regulatory compliance (FCA, CySEC, GDPR, PCI DSS), AI security, Security Champions programme
Technologies
AWS, Docker, Kubernetes, OAuth2, OIDC, SAST, DAST, IAST, SCA, SBOM
Responsibilities
Define secure-by-default reference architectures for web/mobile/APIs; Lead threat modelling and design reviews for high-impact initiatives; Oversee AppSec tooling strategy and embed security controls in CI/CD; Guide secure integration of acquired technology; Define internal policies for AI-assisted coding tools
Seniority
Senior, hands-on IC with strategic influence