Lead Application Security Engineer
Core
Lead the application security practice by embedding security into the design, development, and release of software, using automation and AI to scale security controls.
Role type
Lead Application Security Engineer (hands-on IC with team leadership)
Builds
Secure CI/CD pipelines, automated security controls (SAST/DAST/scanning), and threat modeling practices for a fintech platform.
Domain
Fintech / Alternative Investments / Cloud Security
Deliverable
production ML models | product features | infrastructure
Required skills
Application security architecture, secure code reviews, threat modeling, CI/CD security integration, vulnerability management, AWS security, container security (EKS), SAST/DAST/scanning tools, AI-assisted security workflows, Java/Kotlin, JavaScript/TypeScript (React)
Preferred skills
Experience growing security practices from early stage, experimenting with new tooling, partnering with product owners
Technologies
AWS, EKS, SAST, DAST, CI/CD, Java, Kotlin, JavaScript, TypeScript, React
Responsibilities
Design and implement automated security controls within CI/CD; Conduct security architecture and design reviews; Drive threat modeling strategy; Triage and prioritize security findings; Partner with engineers to embed security in the SDLC; Experiment with AI tools and automation to scale security.
Seniority
Senior, hands-on IC with strategic ownership
