Jobiglo

No results.

Application Security Architect

Capital.com · Limassol

New
Hybrid Senior 🇬🇧 English
AWS GCP ASVS SAST DAST IAST SCA secrets scanning microservices REST GraphQL OAuth2 OIDC Docker Kubernetes CI/CD policy-as-code SBOM

Job description

About the role

Capital.com builds and operates web and mobile trading platforms, public and partner APIs, and the backend services behind them in a highly regulated environment. As an Application Security Architect you will be the senior design authority for the security of these products, setting direction for secure‑by‑design patterns, leading threat modelling and architecture reviews, and defining the application security baseline.

Key responsibilities

  • Define and maintain secure‑by‑default reference architectures for web apps, mobile back‑ends, micro‑services, APIs and event‑driven services.
  • Own core security decisions such as authentication, authorisation, session management, API security, secrets management and multi‑tenant isolation.
  • Establish and run a threat‑modelling operating model, lead design reviews for high‑impact initiatives and identify practical mitigations.
  • Assess and improve the secure SDLC, oversee AppSec tooling (SAST, DAST, IAST, SCA, secrets scanning) and embed security guardrails in CI/CD pipelines.
  • Partner with DevOps to manage repositories, prevent supply‑chain attacks and improve internal tool security.

Required profile

  • 8+ years in technology with 5+ years in a dedicated application or product security role and strong engineering background.
  • Proven track record creating, documenting and rolling out security standards and patterns across complex organisations.
  • Exceptional ability to influence and align engineering teams without direct authority.
  • Pragmatic strategic thinker who balances strong protection with delivery speed.

Required skills

  • AWS (strong knowledge) and exposure to GCP or other clouds.
  • OWASP Top 10, ASVS and DevSecOps practices.
  • AppSec tooling: SAST, DAST, IAST, SCA, secrets scanning.
  • Modern distributed architectures: micro‑services, REST, GraphQL, OAuth2/OIDC.
  • Container technologies: Docker, Kubernetes.
  • CI/CD pipelines, policy‑as‑code, SBOMs and supply‑chain security.

What we offer

  • Work‑life balance with hybrid working model (3 days onsite, 2 days remote).
  • Annual bonus based on performance and generous annual leave policy.
  • Medical insurance, pension fund and additional location‑based benefits.
  • Comprehensive workation policy with extra remote days and paid volunteer leave.

Questions fréquentes

Le salaire n'est pas communiqué publiquement par le recruteur. Vous pouvez postuler et négocier directement avec Capital.com.
Cliquez sur "Postuler maintenant" en haut de la page. Vous pouvez importer votre CV en 1 clic — Jobiglo extrait automatiquement vos informations et postule pour vous.

Why are you reporting this job?

Thank you for your report. We will review this job.

Explore further

Salaries, guides and searches in Cyprus.

Apply in 30 seconds

Enter your email to apply. An account will be created automatically.

Apply now →

By continuing, you accept our terms of use.

Already have an account? Login

A question about this job?

Ask it here: you will get the full job summary by e-mail, right away.

💬 Chat with us on Telegram

Published 5 hours ago

Expires 1 month from now

2 views · 0 interested

Boost your chances

Upload your CV — we will match you with relevant openings.

Analyzing your CV...

Capital.com

Limassol