Senior Application Security Engineer - Vice President
iCapital Network
· Lisbon, Portugal
· Full-time
LocationLisbon, Portugal
EmploymentFull-time
Role typeEngineering
PostedOct 04, 2026
PlatformCI/CDCloudPythonAGIAILLMSecurityOSSSLA
📋 Job Overview
We are looking for a technically strong Senior Application Security practitioner ready to take on real ownership. You will work directly with the Head of AppSec, contributing to the Secure Design practice and helping drive shift-left security across the organization.
🏢 About iCapital Network
iCapital Network is a leading alternative investment platform that connects institutional investors with private capital opportunities. We are seeking a Senior Application Security Engineer to join our growing security team and help build a world-class security program.
🎯 The Role
You will work directly with the Head of AppSec, contributing to the Secure Design practice and helping drive shift-left security across the organization.
✅ Key Responsibilities
Help build and mature the Secure Design and Threat Modeling program by defining methodology, review standards, and sign-off criteria across the organization
Drive shift-left security initiatives, embedding security earlier in the development lifecycle through design reviews, developer enablement, and security gating in CI/CD
Own API security as a discipline
Support offensive security initiatives
Build and maintain security automation in Python, tooling that scales AppSec capacity
Work directly with developers on SAST and SCA remediation, scan optimization, and reducing friction in the security feedback loop
Contribute to AI-assisted security pipelines; define escalation paths, SLAs, and accountability structures for vulnerability management
📌 Required Qualifications
Hands-on experience across secure design, threat modeling, API security, and offensive security
Offensive security capability with penetration testing experience and solid understanding of real-world attack and API exploitation patterns
Deep familiarity with OWASP Top 10 in practice
API security depth, experience assessing REST and GraphQL APIs
Python proficiency, comfortable building automation tools that others will depend on
Experience in shift-left programs: security in CI/CD, developer enablement, design review processes
Understanding of web application and API security
Comfortable reading code across languages and engaging with engineering teams at technical depth
Familiarity with cloud-native environments and attack surface management
Demonstrated ability to influence across engineering and product and operate at architecture level
⭐ Desirable Experience
Relevant certifications are a plus: OSCP, OSWE, GWEB, CSSLP, CISSP, CEH
Exposure to AI-assisted security tooling or LLM security is a differentiator
Experience as a developer and fluency in Ruby, Python, and Scala are a plus
🎁 Benefits
iCapital offers a comprehensive benefits package that includes a total compensation program consisting of competitive salary, annual performance bonus, and equity for all full-time employees; healthcare with 100% employer-paid health and dental insurance; and generous paid time off (PTO).
🛂 Visa & Eligibility
Employees in this role will work in the office four days, with the flexibility to work remotely one day (Friday).
Please let iCapital Network know that you found this role at devopsprojectshq.com as a way to support us, so we can keep providing you with awesome DevOps jobs.
Never miss a job
Join 2,000+ DevOps developers getting weekly alerts for remote and US/EU roles, Kubernetes, AWS, Terraform, filtered for your stack.
🔒 Need an IP to whitelist?
Get a dedicated static EU outbound IP for Banks, payments, EHRs, APIs, AI.