Lead Application Security Engineer

Lead Application Security Engineer

Full-Time 60000 - 80000 £ / year (est.) No working from home possible
CAIS Group

At a Glance

  • Tasks: Lead application security, ensuring our software is safe and secure while collaborating with engineers.
  • Company: Join CAIS, a pioneer in alternative investments and cutting-edge technology solutions.
  • Benefits: Competitive salary, inclusive culture, and opportunities for professional growth.
  • Other info: Dynamic environment with a focus on collaboration and continuous learning.
  • Why this job: Make a real impact on security practices while working with innovative technologies.
  • Qualifications: Experience in application security and a solid software engineering background.

The predicted salary is between 60000 - 80000 £ per year.

CAIS is the pioneer in democratizing access to and education about alternative investments for independent financial advisors, empowering them to engage and transact with leading asset managers on a massive scale through a wide variety of alternative investment products and technology solutions.

CAIS provides financial advisors with a broad selection of alternative investment strategies, including hedge funds, private equity, private credit, real estate, digital assets, and structured notes.

CAIS also delivers industry‑leading technology, operational efficiency, and world‑class client service throughout the pre‑trade, trade, and post‑trade experience.

CAIS supports over 50,000 advisors who oversee more than $6 trillion in network assets.

Application security sits at the center of how CAIS earns and keeps the trust of the advisors and asset managers who rely on our platform.

As our lead for application security, you will own how we protect the applications and services we build and embedding security into the heart of how we design, write, and ship software.

You will define and drive our approach to secure development: setting threat modeling strategy, owning security architecture and secure code reviews, and designing the controls that live inside our SDLC.

Just as importantly, you will use automation and AI to scale that work, turning security from a manual checkpoint into something engineers experience as fast, clear, and genuinely useful.

We are looking for a hands‑on technical leader who is as comfortable reading production code as setting strategy.

You are someone who enjoys partnering with engineers and product owners; you are eager to experiment with new technologies to raise our security bar across the stack, and you are easy to do business with.

You see a growing security practice not as a constraint to enforce but as a capability to build, one that helps us ship reliable products, grow as engineers, and have some fun along the way.

Responsibilities

  • Secure Software Development & Architecture
  • Own security elements of the software development lifecycle, designing and implementing automated controls within CI/CD, including SAST, DAST, dependency and container security scanning.
  • Conduct security architecture and design reviews across product and platform areas, surfacing risk early and providing clear, actionable remediation paths.
  • Drive CAIS's threat modeling strategy, establishing it as a repeatable practice across teams rather than a one‑off exercise.
  • Vulnerability Management & Engineering Partnership
  • Triage, validate, and prioritize findings, coordinating remediation through to resolution with clear ownership and follow‑through.
  • Liaise with key vendors on penetration testing, vulnerability scanning, and threat modeling, translating external findings into prioritized action.
  • Partner with engineers and product owners to embed security pragmatically into design, development, and release, supporting teams without becoming a blocker.
  • Provide secure coding guidance and clear documentation that helps teams understand risk and apply secure development practices independently.
  • Level up CAIS's security capability across the tech stack, experimenting with new tooling, automation, and AI‑assisted workflows as the practice grows.
  • Required Experience
  • Experience in application or product security teams. A software engineering background is
  • Solid AWS security experience, including securing cloud‑native, containerized environments (e. g. EKS).
  • Hands‑on experience with security tooling across the SDLC, such as SAST, DAST, and dependency or container scanning (specific products are not important).
  • Demonstrated experience driving threat modeling and leading security architecture and design reviews.
  • Proven ability to lead engineering and security teams in adopting AI tools and automated workflows when it comes to security as part of the SDLC.
  • A confident, collaborative communicator who partners effectively with engineers and product owners and explains risk clearly to both technical and non‑technical audiences.
  • A builder's mindset, you are energized by growing an application security practice from an early stage, eager to experiment and collaborative along the way.

We are an equal opportunity employer, and do not discriminate on the basis of any protected attribute, including race, religion, color, national origin, gender, sexual orientation, gender identity, gender expression, age, marital or veteran status, pregnancy or disability, or any other basis protected under applicable law.

#J-18808-Ljbffr

Lead Application Security Engineer employer: CAIS Group

At CAIS, we pride ourselves on being a forward-thinking employer that champions innovation and collaboration in the financial technology sector. Our work culture fosters continuous learning and growth, providing employees with ample opportunities to develop their skills while working on cutting-edge security practices. Located in a vibrant environment, we offer competitive benefits and a supportive atmosphere where your contributions directly impact the success of over 50,000 financial advisors and their clients.

CAIS Group

Contact Details:

CAIS Group Recruitment Team

We think you need these skills to ace Lead Application Security Engineer

Application Security
Secure Software Development
Security Architecture
Threat Modeling
Vulnerability Management
CI/CD Automation
SAST