Lead Application Security Engineer in London

Lead Application Security Engineer in London

London Full-Time Home office (partial)
C

At a Glance

  • Tasks: Lead application security, embedding security into software design and development.
  • Company: Join CAIS, a pioneer in alternative investments with a collaborative culture.
  • Benefits: Enjoy a supportive environment, competitive salary, and opportunities for growth.
  • Other info: Be part of a recognised Best Place to Work with a focus on inclusivity.
  • Why this job: Make a real impact on security practices while working with cutting-edge technology.
  • Qualifications: Experience in application security and a background in software engineering required.

CAIS is the pioneer in democratizing access to and education about alternative investments for independent financial advisors, empowering them to engage and transact with leading asset managers on a massive scale through a wide variety of alternative investment products and technology solutions. CAIS provides financial advisors with a broad selection of alternative investment strategies, including hedge funds, private equity, private credit, real estate, digital assets, and structured notes. CAIS also delivers industry-leading technology, operational efficiency, and world-class client service throughout the pre-trade, trade, and post-trade experience. CAIS supports over 50,000 advisors who oversee more than $6 trillion in network assets.

Application security sits at the center of how CAIS earns and keeps the trust of the advisors and asset managers who rely on our platform. As our lead for application security, you will own how we protect the applications and services we build and embedding security into the heart of how we design, write, and ship software.

You will define and drive our approach to secure development: setting threat modeling strategy, owning security architecture and secure code reviews, and designing the controls that live inside our SDLC. Just as importantly, you will use automation and AI to scale that work, turning security from a manual checkpoint into something engineers experience as fast, clear, and genuinely useful.

We are looking for a hands-on technical leader who is as comfortable reading production code as setting strategy. You are someone who enjoys partnering with engineers and product owners; you are eager to experiment with new technologies to raise our security bar across the stack, and you are easy to do business with. You see a growing security practice not as a constraint to enforce but as a capability to build, one that helps us ship reliable products, grow as engineers, and have some fun along the way.

Responsibilities

Secure Software Development & Architecture

  • Own security elements of the software development lifecycle, designing and implementing automated controls within CI/CD, including SAST, DAST, dependency and container security scanning.
  • Conduct security architecture and design reviews across product and platform areas, surfacing risk early and providing clear, actionable remediation paths.
  • Drive CAIS's threat modeling strategy, establishing it as a repeatable practice across teams rather than a one-off exercise.

Vulnerability Management & Engineering Partnership

  • Triage, validate, and prioritize findings, coordinating remediation through to resolution with clear ownership and follow-through.
  • Liaise with key vendors on penetration testing, vulnerability scanning, and threat modeling, translating external findings into prioritized action.
  • Partner with engineers and product owners to embed security pragmatically into design, development, and release, supporting teams without becoming a blocker.
  • Provide secure coding guidance and clear documentation that helps teams understand risk and apply secure development practices independently.
  • Level up CAIS's security capability across the tech stack, experimenting with new tooling, automation, and AI-assisted workflows as the practice grows.

Required Experience

  • Experience in application or product security teams. A software engineering background is
  • Ability to read and reason about production code and hold your own with senior engineers, with working knowledge of Java/Kotlin and JavaScript/TypeScript (React).
  • Solid AWS security experience, including securing cloud-native, containerized environments (e.g. EKS).
  • Hands-on experience with security tooling across the SDLC, such as SAST, DAST, and dependency or container scanning (specific products are not important).
  • Demonstrated experience driving threat modeling and leading security architecture and design reviews.
  • Proven ability to lead engineering and security teams in adopting AI tools and automated workflows when it comes to security as part of the SDLC .
  • A confident, collaborative communicator who partners effectively with engineers and product owners and explains risk clearly to both technical and non-technical audiences.
  • A builder's mindset, you are energized by growing an application security practice from an early stage, eager to experiment and collaborative along the way.

CAIS is consistently recognized as a Best Place to Work, and our culture is at the heart of our success. We are committed to fostering an inclusive environment where employees can be their most authentic self and feel inspired and supported to bring their voice forward to drive community, growth, and innovation. We are an equal opportunity employer, and do not discriminate on the basis of any protected attribute, including race, religion, color, national origin, gender, sexual orientation, gender identity, gender expression, age, marital or veteran status, pregnancy or disability, or any other basis protected under applicable law. Learn more about our culture, benefits, and people at https://www.caisgroup.com/our-company/careers

We use technology, including AI tools, to support parts of our recruitment process such as application screening, interview scheduling, and candidate communications. These tools are used to improve efficiency and consistency, but they do not replace human judgement. All hiring decisions are made by people, and we are committed to fair and unbiased assessment of every candidate.

Lead Application Security Engineer in London employer: CAIS

At CAIS, we pride ourselves on being a leading employer in the financial technology sector, offering a dynamic work culture that champions innovation and collaboration. Our commitment to employee growth is evident through our inclusive environment, where every team member is encouraged to bring their authentic self to work and contribute to meaningful projects that empower financial advisors. With access to cutting-edge technology and a focus on professional development, CAIS provides a unique opportunity for individuals looking to make a significant impact in application security while enjoying a supportive and engaging workplace.

C

Contact Details:

CAIS Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Lead Application Security Engineer in London

Get Involved in the Cybersecurity Community

Diving into the cybersecurity community is key for landing that full-time gig. Join forums like Reddit's r/cybersecurity or attend local meetups to connect with industry veterans and other job seekers. Networking is everything in this field—don’t just be a passive lurker!

Show Off Your Skills with Capture the Flag Competitions

Participate in Capture the Flag (CTF) competitions; these are not just a fun way to boost your skills but also a chance to showcase your talent to potential employers. Many companies, including CAIS, love seeing candidates who actively engage in these challenges.

Tailor Your Online Presence

Make sure your LinkedIn and any professional profiles reflect your cybersecurity expertise. Share your projects, whether they’re personal or from a previous role, to catch the eye of hiring managers. This is how they’ll find your passion and commitment to the field!

Apply Directly Through CAIS

Don’t forget to head straight to our website and check out any openings for cybersecurity roles at CAIS. Applying directly can sometimes give you an edge, especially if you can mention that you've been following our work or engaging in the community.

We think you need these skills to ace Lead Application Security Engineer in London

Application Security
Secure Software Development
Security Architecture
Threat Modeling
Vulnerability Management
CI/CD Automation
SAST

Some tips for your application 🫡

Show off your technical skills:In cybersecurity, it's crucial to highlight your technical prowess. Make sure your CV showcases specific skills like network security, penetration testing, or threat analysis. If you have relevant certifications (like CEH or CISSP), pop those on the front page to grab attention!

Tailor your portfolio for the role:Even for a full-time role, a portfolio can set you apart. If you've worked on any cybersecurity projects—be it CTF challenges, security assessments, or research papers—include these in your application. This demonstrates not just your skills, but also your hands-on experience!

Use real-world examples:When writing your cover letter, don’t just stick to your qualifications. Share real-world examples of how you’ve tackled security issues or vulnerabilities. This gives the hiring team at CAIS insight into your practical problem-solving abilities and makes your application memorable.

Demonstrate your passion for cybersecurity:Cybersecurity is an ever-evolving field, so show us that you’re always learning! Mention any recent courses, webinars, or industry events you’ve attended. This not only exhibits your enthusiasm but also signals to CAIS that you’re committed to staying ahead in the game.

How to prepare for a job interview at CAIS

Sharpen Your Technical Skills

For a role in cybersecurity, it’s essential to be up-to-date with the latest tools and techniques. Brush up on your knowledge of firewalls, intrusion detection systems, and vulnerability assessment tools. Be ready to discuss specific scenarios where you’ve applied these skills, as hands-on experience can really set us apart in interviews.

Prepare for Scenario-Based Questions

Expect the interviewers at CAIS to throw in some hypothetical situations to see how you’d handle them. Think about common security breaches or incidents and be prepared to explain how you would respond. This not only shows your problem-solving skills but also your understanding of real-world cybersecurity challenges.

Highlight Your Certifications

Certifications like CompTIA Security+, CISSP, or CEH can give you a significant edge in a full-time role in cybersecurity. Make sure to mention these during your interview and be prepared to discuss what you learned through those certifications and how they relate to the position at CAIS.

Show Your Passion for Cybersecurity

Since you’re going for a full-time gig, showing genuine enthusiasm for the field can make all the difference. Share any personal projects, blogs, or communities you’re part of that relate to cybersecurity. This not only showcases your passion but also your commitment to staying engaged in this ever-evolving field.