Capital.com builds and operates web and mobile trading platforms, public and partner APIs, and the backend services behind them, all in a highly regulated environment. As Application Security Architect, you will be the senior design authority for the security of these products. You will set the direction for how we secure software at scale: you will own secure-by-design patterns and standards, lead threat modelling and architecture reviews, and define the application security baseline that engineering teams build against.
Working closely with the Product Security team and the Director of Product Security, you will guide AppSec processes and set the vision for your area without direct line management. You will treat security as a shared outcome rather than a gate, balancing strong protection with developer experience and delivery speed, and you will earn adoption through enablement rather than mandates.
Responsibilities:
Requirements:
Experience:
- 8+ years in technology, including 5+ years in a dedicated application or product security role, with a strong engineering background and hands-on architecture or design ownership
- Proven track record creating, documenting, and rolling out security standards, patterns, and best practices across a complex engineering organisation
- Deep, demonstrable threat-modelling experience across product portfolios
Technical:
- Experience designing and implementing a secure SDLC in a cloud-native environment. Strong AWS knowledge is required, and exposure to GCP or other clouds is welcome
- Strong command of OWASP standards (Top 10, ASVS) and DevSecOps practice, including AppSec tooling (SAST, DAST, IAST, SCA, secrets scanning) and vulnerability management
- Deep understanding of modern distributed architectures: microservices, REST and GraphQL APIs, event-driven systems, OAuth2/OIDC, and containerised workloads (Docker, Kubernetes). You should be able to reason about their trust boundaries, attack surface, and data flows across web and mobile clients
Collaboration:
- Exceptional ability to influence and align engineering teams without direct authority, and to brief both engineers and executives
- Pragmatism and strategic thinking: you balance the ideal with the achievable, protect delivery throughput, and turn long-term direction into an actionable plan
- Clear written communication through diagrams, ADRs, and patterns, plus a track record of mentoring and cross-functional collaboration
Nice to have:
- Experience in fintech, trading, brokerage, or another regulated environment
- Awareness of relevant regulatory and compliance drivers: FCA and CySEC operational resilience, GDPR, and PCI DSS
- Software supply-chain security, including SBOMs and artifact and build integrity
- Experience securing AI-integrated product features, or using AI to scale an AppSec programme
- Experience building or running a Security Champions programme
- CSSLP, GIAC GDSA, or a hands-on offensive security certification. Certifications are valued but secondary to demonstrated experience
What you'll get in return:
- You will join the company, that cares about work and life balance
- Annual Bonus based on the performance review cycle
- Generous Annual Leave Policy
- Medical Insurance and Pension fund, with additional benefit packages based on the location
- Hybrid working model (3 days from our modern office and 2 days fully remotely)
- Comprehensive Workation Policy with 30 more remote days available.
- Possibility of taking two additional days of paid leave per year to dedicate to volunteering efforts.