Lead Application Security Engineer
Core
Lead Application Security Engineer responsible for embedding security into the design, development, and shipping of software, defining secure development strategies, and automating security controls.
Role type
Lead Application Security Engineer (hands-on IC with team leadership)
Builds
Secure software development lifecycle, automated security controls, threat modeling practices
Domain
Fintech / Alternative Investments / Cloud Security
Required skills
Application security, secure architecture, threat modeling, secure code reviews, CI/CD security automation, vulnerability management, AWS security, container security, SAST/DAST, dependency scanning, AI/automation in security, Java/Kotlin, JavaScript/TypeScript (React)
Preferred skills
Experience growing security practices from early stage, experimenting with new tooling
Technologies
AWS, EKS, SAST, DAST, CI/CD pipelines, Java, Kotlin, JavaScript, TypeScript, React
Responsibilities
Design and implement automated security controls within CI/CD; Conduct security architecture and design reviews; Drive threat modeling strategy; Triage and prioritize security findings; Partner with engineers to embed security into design and development; Experiment with AI tools and automated workflows for security
Seniority
Senior, hands-on IC with leadership responsibilities
