Lead Application Security Engineer in Whitehall

Lead Application Security Engineer in Whitehall

Whitehall Full-Time 63000 - 77000 £ / year (est.) No working from home possible
C

At a Glance

  • Tasks: Lead application security, embedding security into software design and development.
  • Company: Join CAIS, a pioneer in alternative investments with a vibrant culture.
  • Benefits: Enjoy a supportive environment, competitive salary, and opportunities for growth.
  • Other info: Be part of a recognised Best Place to Work with a focus on inclusivity.
  • Why this job: Make a real impact on security practices while collaborating with innovative engineers.
  • Qualifications: Experience in application security and a solid software engineering background required.

The predicted salary is between 63000 - 77000 £ per year.

CAIS is the pioneer in democratizing access to and education about alternative investments for independent financial advisors, empowering them to engage and transact with leading asset managers on a massive scale through a wide variety of alternative investment products and technology solutions. CAIS provides financial advisors with a broad selection of alternative investment strategies, including hedge funds, private equity, private credit, real estate, digital assets, and structured notes. CAIS also delivers industry-leading technology, operational efficiency, and world-class client service throughout the pre-trade, trade, and post-trade experience. CAIS serves over 2,500 wealth management firms that support more than 65,000 financial advisors who oversee approximately $8.5 trillion in end-client assets.

Application security sits at the center of how CAIS earns and keeps the trust of the advisors and asset managers who rely on our platform. As our lead for application security, you will own how we protect the applications and services we build and embedding security into the heart of how we design, write, and ship software. You will define and drive our approach to secure development: setting threat modeling strategy, owning security architecture and secure code reviews, and designing the controls that live inside our SDLC. Just as importantly, you will use automation and AI to scale that work, turning security from a manual checkpoint into something engineers experience as fast, clear, and genuinely useful.

We are looking for a hands-on technical leader who is as comfortable reading production code as setting strategy. You are someone who enjoys partnering with engineers and product owners; you are eager to experiment with new technologies to raise our security bar across the stack, and you are easy to do business with. You see a growing security practice not as a constraint to enforce but as a capability to build, one that helps us ship reliable products, grow as engineers, and have some fun along the way.

Responsibilities

  • Secure Software Development & Architecture
    • Own security elements of the software development lifecycle, designing and implementing automated controls within CI/CD, including SAST, DAST, dependency and container security scanning.
    • Conduct security architecture and design reviews across product and platform areas, surfacing risk early and providing clear, actionable remediation paths.
    • Drive CAIS's threat modeling strategy, establishing it as a repeatable practice across teams rather than a one-off exercise.
  • Vulnerability Management & Engineering Partnership
    • Triage, validate, and prioritize findings, coordinating remediation through to resolution with clear ownership and follow-through.
    • Liaise with key vendors on penetration testing, vulnerability scanning, and threat modeling, translating external findings into prioritized action.
    • Partner with engineers and product owners to embed security pragmatically into design, development, and release, supporting teams without becoming a blocker.
    • Provide secure coding guidance and clear documentation that helps teams understand risk and apply secure development practices independently.
    • Level up CAIS's security capability across the tech stack, experimenting with new tooling, automation, and AI-assisted workflows as the practice grows.

Required Experience

  • Experience in application or product security teams.
  • A software engineering background is required.
  • Ability to read and reason about production code and hold your own with senior engineers, with working knowledge of Java/Kotlin and JavaScript/TypeScript (React).
  • Solid AWS security experience, including securing cloud-native, containerized environments (e.g. EKS).
  • Hands-on experience with security tooling across the SDLC, such as SAST, DAST, and dependency or container scanning (specific products are not important).
  • Demonstrated experience driving threat modeling and leading security architecture and design reviews.
  • Proven ability to lead engineering and security teams in adopting AI tools and automated workflows when it comes to security as part of the SDLC.
  • A confident, collaborative communicator who partners effectively with engineers and product owners and explains risk clearly to both technical and non-technical audiences.
  • A builder's mindset, you are energized by growing an application security practice from an early stage, eager to experiment and collaborate along the way.

CAIS is consistently recognized as a Best Place to Work, and our culture is at the heart of our success. We are committed to fostering an inclusive environment where employees can be their most authentic self and feel inspired and supported to bring their voice forward to drive community, growth, and innovation. We are an equal opportunity employer, and do not discriminate on the basis of any protected attribute, including race, religion, color, national origin, gender, sexual orientation, gender identity, gender expression, age, marital or veteran status, pregnancy or disability, or any other basis protected under applicable law.

Learn more about our culture, benefits, and people at CAIS. We use technology, including AI tools, to support parts of our recruitment process such as application screening, interview scheduling, and candidate communications. These tools are used to improve efficiency and consistency, but they do not replace human judgement. All hiring decisions are made by people, and we are committed to fair and unbiased assessment of every candidate.

Lead Application Security Engineer in Whitehall employer: CAIS

CAIS is an exceptional employer, renowned for its commitment to fostering an inclusive and innovative work culture that empowers employees to thrive. As a Lead Application Security Engineer, you will have the opportunity to shape the security landscape of cutting-edge technology solutions while collaborating with talented engineers and product owners. With a focus on employee growth and a supportive environment, CAIS not only values your contributions but also encourages experimentation and continuous learning, making it a truly rewarding place to advance your career.

C

Contact Details:

CAIS Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Lead Application Security Engineer in Whitehall

Join Local Tech Meetups

Get out there and mingle with fellow developers by joining local tech meetups. It’s a fantastic way to meet people who might be working at CAIS or know someone who does. Plus, you can pick up some trendy tech skills and trends while you're at it!

Contribute to Open Source Projects

Show off your coding chops by jumping into open-source projects. Not only does this give you practical experience, but it also gets you noticed in the dev community. You'll create a killer portfolio that speaks volumes about your skills to CAIS.

Tap into Online Developer Communities

Don’t underestimate the power of online developer communities like GitHub, Stack Overflow, and even Reddit. Participate in discussions, share your projects, and build your visibility. We can often find opportunities through these channels that can lead to a full-time gig at companies like CAIS.

Explore Job Boards Specifically for Tech Roles

Keep your eyes peeled on job boards that focus on tech roles. Sites like TechCareers or Stack Overflow Jobs can often have listings for companies like CAIS that might not show up on broader job sites. Make it a habit to check these regularly, and don’t hesitate to apply directly through our website!

We think you need these skills to ace Lead Application Security Engineer in Whitehall

Application Security
Secure Software Development
Security Architecture
Threat Modeling
Vulnerability Management
CI/CD Automation
SAST

Some tips for your application 🫡

Show off your coding skills:When applying for a software engineering role, it's super important to showcase your coding skills. Make sure your CV includes your tech stack, any relevant programming languages you’re comfortable with, and examples of projects you've worked on. If you have a GitHub profile, link it up! We love to see code in action.

Tailor your portfolio:For a full-time role, we’d expect to see some solid examples of your work in your portfolio. Make sure to include at least two or three projects that highlight your problem-solving skills and your ability to work with different technologies. Focus on the projects that are most relevant to the position at CAIS.

Craft a killer cover letter:Your cover letter is your chance to stand out—make it personal! Explain why you want to work at CAIS and how your skills align with the role. Show us your passion for software development. We dig enthusiastic candidates who understand the value of collaboration and continuous learning!

Be clear and concise:When it comes to writing your CV and cover letter, clarity is key. Avoid jargon that could confuse us and stick to simple, direct language. Highlight your achievements with quantifiable results where possible, and keep everything easy to read. A well-organised application goes a long way!

How to prepare for a job interview at CAIS

Brush Up on Your Coding Skills

For a full-time software engineering role, it's crucial that we stay sharp with our coding abilities. Expect technical questions that might involve solving problems on the spot or discussing algorithms. Practise on platforms like LeetCode or HackerRank to get comfortable with the types of questions that often come up.

Know Your Tools and Frameworks

Make sure we’re well-acquainted with the tools and technologies listed in the job description. Familiarise ourselves with any specific frameworks or programming languages mentioned. If CAIS uses React or Node.js, for instance, be ready to discuss how we’ve used them in previous projects or coursework.

Showcase Your Projects

Bring along a portfolio that highlights our best work. This could be code samples, GitHub repositories, or any side projects we’ve built. Make sure we can talk through our thought process for each project, especially the challenges we faced and how we solved them—this shows our problem-solving skills in action.

Prepare for Behavioural Questions

While technical skills are key, full-time positions also require cultural fit. Be ready to discuss our previous experiences and how we handle teamwork, conflict, and deadlines. Brush up on the STAR method—Situation, Task, Action, Result—to clearly articulate our past experiences when discussing how we've contributed to a team.