Application Security Architect
Capital.com · Limassol
Job description
About the role
Capital.com builds and operates web and mobile trading platforms, public and partner APIs, and the backend services behind them in a highly regulated environment. As an Application Security Architect you will be the senior design authority for the security of these products, setting direction for secure‑by‑design patterns, leading threat modelling and architecture reviews, and defining the application security baseline.
Key responsibilities
- Define and maintain secure‑by‑default reference architectures for web apps, mobile back‑ends, micro‑services, APIs and event‑driven services.
- Own core security decisions such as authentication, authorisation, session management, API security, secrets management and multi‑tenant isolation.
- Establish and run a threat‑modelling operating model, lead design reviews for high‑impact initiatives and identify practical mitigations.
- Assess and improve the secure SDLC, oversee AppSec tooling (SAST, DAST, IAST, SCA, secrets scanning) and embed security guardrails in CI/CD pipelines.
- Partner with DevOps to manage repositories, prevent supply‑chain attacks and improve internal tool security.
Required profile
- 8+ years in technology with 5+ years in a dedicated application or product security role and strong engineering background.
- Proven track record creating, documenting and rolling out security standards and patterns across complex organisations.
- Exceptional ability to influence and align engineering teams without direct authority.
- Pragmatic strategic thinker who balances strong protection with delivery speed.
Required skills
- AWS (strong knowledge) and exposure to GCP or other clouds.
- OWASP Top 10, ASVS and DevSecOps practices.
- AppSec tooling: SAST, DAST, IAST, SCA, secrets scanning.
- Modern distributed architectures: micro‑services, REST, GraphQL, OAuth2/OIDC.
- Container technologies: Docker, Kubernetes.
- CI/CD pipelines, policy‑as‑code, SBOMs and supply‑chain security.
What we offer
- Work‑life balance with hybrid working model (3 days onsite, 2 days remote).
- Annual bonus based on performance and generous annual leave policy.
- Medical insurance, pension fund and additional location‑based benefits.
- Comprehensive workation policy with extra remote days and paid volunteer leave.
Questions fréquentes
Why are you reporting this job?
Explore further
Salaries, guides and searches in Cyprus.
Salaries by job title
Apply in 30 seconds
Enter your email to apply. An account will be created automatically.
By continuing, you accept our terms of use.
Already have an account? Login
A question about this job?
Ask it here: you will get the full job summary by e-mail, right away.
Published 5 hours ago
Expires 1 month from now
2 views · 0 interested
Boost your chances
Upload your CV — we will match you with relevant openings.
Analyzing your CV...
Capital.com
Limassol