Capital Group
· Warsaw, Mazowieckie, Poland / Sofia City, Bulgaria / Limassol, Cyprus
· Full-time
LocationWarsaw, Mazowieckie, Poland / Sofia City, Bulgaria / Limassol, Cyprus
EmploymentFull-time
Role typeTechnology – Security - AppSec /
PostedOct 01, 2026
AWSPlatformCI/CDKubernetesGCPIaCDockerCloudAIPCI
Capital Group
Financial Services👥 5001 employees📍 Los Angeles, CA, USEst. 1931
Capital Group was established in 1931 in Los Angeles, California, and now has 31 offices around the globe. For over 90 years we've provided carefully researched investment solutions and services to f…
📋 Job Overview
Capital.com builds and operates web and mobile trading platforms, public and partner APIs, and the backend services behind them, all in a highly regulated environment. As Application Security Architect, you will be the senior design authority for the security of these products. You will set the direction for how we secure software at scale: you will own secure-by-design patterns and standards, lead threat modelling and architecture reviews, and define the application security baseline that engineering teams build against.
🏢 About Capital.com
Capital.com is a financial technology company that provides trading platforms and services in a highly regulated environment.
🎯 The Role
Working closely with the Product Security team and the Director of Product Security, you will guide AppSec processes and set the vision for your area without direct line management. You will treat security as a shared outcome rather than a gate, balancing strong protection with developer experience and delivery speed, and you will earn adoption through enablement rather than mandates.
✅ Key Responsibilities
Define and maintain secure-by-default reference architectures for common patterns: web apps, mobile backends, microservices, public and partner APIs, and event-driven services
Own core application security architecture decisions: authentication and authorisation, session management, API security, secrets management, multi-tenant isolation, and security logging and auditing
Lead the redesign of user authentication and the delivery of security features into the product
Develop and roll out application security standards, secure-coding guidelines, configuration standards, reusable design patterns, and architecture decision records (ADRs) that engineers can apply without a security expert in the room
Define internal policies for the safe use of AI-assisted and vibe-coding tools
Define security requirements for acquired technology and guide its secure integration
Establish and run a threat-modelling operating model, covering scope, cadence, templates, and facilitation, proportionate to each product's risk tier
Own the security review stage of the new product approval process, covering architecture design and configuration
Lead design reviews for high-impact initiatives: new products, new auth flows, payment and sensitive-data flows, platform migrations, and major refactors
Identify design-level risks and agree practical, prioritised mitigations with engineering teams
Assess the current state of application security, propose improvements, and drive the secure SDLC strategy with Engineering and Security leadership
Oversee AppSec processes and own the tooling strategy (SAST, DAST, IAST, SCA, and secrets scanning), including how findings flow back to engineering
Embed security controls as guardrails in CI/CD through policy-as-code, with agreed enforcement and escalation paths
Partner with DevOps to organise repository management and prevent supply-chain attacks, covering safe component usage, dependency management, SBOMs, and build integrity
Improve the security of our internal tools
📌 Required Qualifications
8+ years in technology, including 5+ years in a dedicated application or product security role, with a strong engineering background and hands-on architecture or design ownership
Proven track record creating, documenting, and rolling out security standards, patterns, and best practices across a complex engineering organisation
Deep, demonstrable threat-modelling experience across product portfolios
Experience designing and implementing a secure SDLC in a cloud-native environment. Strong AWS knowledge is required, and exposure to GCP or other clouds is welcome
Strong command of OWASP standards (Top 10, ASVS) and DevSecOps practice, including AppSec tooling (SAST, DAST, IAST, SCA, secrets scanning) and vulnerability management
Deep understanding of modern distributed architectures: microservices, REST and GraphQL APIs, event-driven systems, OAuth2/OIDC, and containerised workloads (Docker, Kubernetes). You should be able to reason about their trust boundaries, attack surface, and data flows across web and mobile clients
Exceptional ability to influence and align engineering teams without direct authority, and to brief both engineers and executives
Pragmatism and strategic thinking: you balance the ideal with the achievable, protect delivery throughput, and turn long-term direction into an actionable plan
Clear written communication through diagrams, ADRs, and patterns, plus a track record of mentoring and cross-functional collaboration
⭐ Desirable Experience
Experience in fintech, trading, brokerage, or another regulated environment
Awareness of relevant regulatory and compliance drivers: FCA and CySEC operational resilience, GDPR, and PCI DSS
Software supply-chain security, including SBOMs and artifact and build integrity
Experience securing AI-integrated product features, or using AI to scale an AppSec programme
Experience building or running a Security Champions programme
CSSLP, GIAC GDSA, or a hands-on offensive security certification. Certifications are valued but secondary to demonstrated experience
🎁 Benefits
You will join the company that cares about its employees and provides a competitive compensation package
🛂 Visa & Eligibility
No specific visa or eligibility information provided.
Please let Capital Group know that you found this role at devopsprojectshq.com as a way to support us, so we can keep providing you with awesome DevOps jobs.
Never miss a job
Join 2,000+ DevOps developers getting weekly alerts for remote and US/EU roles, Kubernetes, AWS, Terraform, filtered for your stack.
🔒 Need an IP to whitelist?
Get a dedicated static EU outbound IP for Banks, payments, EHRs, APIs, AI.