994,162open jobs
59,296companies
165,357added this week
Browse all
Salary
≈ $71k – $132k per year (Estimated)
Location
Hybrid (Warsaw, Poland)
Seniority
Architect · 5+ years exp

Confirmed on the employer's own hiring board on Sep 30, 2026. First seen by Alion on Sep 29, 2026. Capital.com scores A on the Alion truth index.

Overview
Company
Impact
Profile match
Capital.com is a global fintech company and online trading platform headquartered in Limassol, Cyprus, and founded in 2016. The company provides access to over 5,500 financial instruments including contracts for difference (CFDs) on stocks, indices, commodities, forex, and cryptocurrencies. It operates internationally with offices in London, Melbourne, Warsaw, and Dubai, serving over three million registered accounts through its proprietary AI-powered web and mobile platforms.

Capital.com builds and operates web and mobile trading platforms, public and partner APIs, and the backend services behind them, all in a highly regulated environment. As Application Security Architect, you will be the senior design authority for the security of these products. You will set the direction for how we secure software at scale: you will own secure-by-design patterns and standards, lead threat modelling and architecture reviews, and define the application security baseline that engineering teams build against.

Working closely with the Product Security team and the Director of Product Security, you will guide AppSec processes and set the vision for your area without direct line management. You will treat security as a shared outcome rather than a gate, balancing strong protection with developer experience and delivery speed, and you will earn adoption through enablement rather than mandates.

Responsibilities:

    Security Architecture & Standards:

    • Define and maintain secure-by-default reference architectures for common patterns: web apps, mobile backends, microservices, public and partner APIs, and event-driven services
    • Own core application security architecture decisions: authentication and authorisation, session management, API security, secrets management, multi-tenant isolation, and security logging and auditing
    • Lead the redesign of user authentication and the delivery of security features into the product
    • Develop and roll out application security standards, secure-coding guidelines, configuration standards, reusable design patterns, and architecture decision records (ADRs) that engineers can apply without a security expert in the room
    • Define internal policies for the safe use of AI-assisted and vibe-coding tools
    • Define security requirements for acquired technology and guide its secure integration
    • Threat Modelling & Design Review:

      • Establish and run a threat-modelling operating model, covering scope, cadence, templates, and facilitation, proportionate to each product's risk tier
      • Own the security review stage of the new product approval process, covering architecture design and configuration
      • Lead design reviews for high-impact initiatives: new products, new auth flows, payment and sensitive-data flows, platform migrations, and major refactors
      • Identify design-level risks and agree practical, prioritised mitigations with engineering teams
      • Secure SDLC, DevSecOps & Supply Chain:

        • Assess the current state of application security, propose improvements, and drive the secure SDLC strategy with Engineering and Security leadership
        • Oversee AppSec processes and own the tooling strategy (SAST, DAST, IAST, SCA, and secrets scanning), including how findings flow back to engineering
        • Embed security controls as guardrails in CI/CD through policy-as-code, with agreed enforcement and escalation paths
        • Partner with DevOps to organise repository management and prevent supply-chain attacks, covering safe component usage, dependency management, SBOMs, and build integrity
        • Improve the security of our internal tools

Requirements:

    Experience:

    • 8+ years in technology, including 5+ years in a dedicated application or product security role, with a strong engineering background and hands-on architecture or design ownership
    • Proven track record creating, documenting, and rolling out security standards, patterns, and best practices across a complex engineering organisation
    • Deep, demonstrable threat-modelling experience across product portfolios
    • Technical:

      • Experience designing and implementing a secure SDLC in a cloud-native environment. Strong AWS knowledge is required, and exposure to GCP or other clouds is welcome
      • Strong command of OWASP standards (Top 10, ASVS) and DevSecOps practice, including AppSec tooling (SAST, DAST, IAST, SCA, secrets scanning) and vulnerability management
      • Deep understanding of modern distributed architectures: microservices, REST and GraphQL APIs, event-driven systems, OAuth2/OIDC, and containerised workloads (Docker, Kubernetes). You should be able to reason about their trust boundaries, attack surface, and data flows across web and mobile clients
      • Collaboration:

        • Exceptional ability to influence and align engineering teams without direct authority, and to brief both engineers and executives
        • Pragmatism and strategic thinking: you balance the ideal with the achievable, protect delivery throughput, and turn long-term direction into an actionable plan
        • Clear written communication through diagrams, ADRs, and patterns, plus a track record of mentoring and cross-functional collaboration

Nice to have:

    • Experience in fintech, trading, brokerage, or another regulated environment
    • Awareness of relevant regulatory and compliance drivers: FCA and CySEC operational resilience, GDPR, and PCI DSS
    • Software supply-chain security, including SBOMs and artifact and build integrity
    • Experience securing AI-integrated product features, or using AI to scale an AppSec programme
    • Experience building or running a Security Champions programme
    • CSSLP, GIAC GDSA, or a hands-on offensive security certification. Certifications are valued but secondary to demonstrated experience

What you'll get in return:

  • You will join the company, that cares about work and life balance
  • Annual Bonus based on the performance review cycle
  • Generous Annual Leave Policy
  • Medical Insurance and Pension fund, with additional benefit packages based on the location
  • Hybrid working model (3 days from our modern office and 2 days fully remotely)
  • Comprehensive Workation Policy with 30 more remote days available.
  • Possibility of taking two additional days of paid leave per year to dedicate to volunteering efforts.
Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
994,162 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account Continue with Google
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Security
Similar stack
Same company
Warsaw
≈ $61k – $107k per year (Estimated) • In office • 3+ years exp • Bachelor's Degree • Katowice
Cybersecurity
Zscaler
Zero Trust
PKI
DLP
Apply
DevSecOps Engineer 27 days ago
≈ $60k – $106k per year (Estimated) • Hybrid • Full-Time • 8+ years exp • Bachelor's Degree • Łódź
AI/ML
LLM
LLM Guardrails
NIST AI RMF
DevOps
Terraform
FluxCD
GitLab CI
Azure
CI/CD
GitOps
AWS
Kubernetes
IAM
Cybersecurity
HashiCorp Vault
ISO 27001
NIST CSF
CIS Benchmarks
SOC 2
OWASP ASVS
Threat Modeling
PKI
OWASP
Apply
≈ $64k – $116k per year (Estimated) • Remote (Poland) • Full-Time
DevOps
IAM
Cybersecurity
ISO 27001
SOC 2
Mend
SIEM
Apply
≈ $24k – $67k per year (Estimated) • Hybrid • Full-Time • 1+ year exp • Gdańsk
DevOps
Linux
Windows
Cybersecurity
Microsoft Sentinel
Tanium
SIEM
Management
Service Desk
Apply
≈ $50k – $89k per year (Estimated) • Hybrid • Full-Time • 4+ years exp • Warsaw
Python
AI/ML
LLM
LLM Guardrails
DevOps
Terraform
GCP
Azure
CI/CD
AWS
Kubernetes
Azure AKS
FinOps
IAM
Cybersecurity
SOC 2
Apply
$205k – $426k per year • In office • Bachelor's Degree • San Antonio
Python
JavaScript
PowerShell
AI/ML
AI Agents
DevOps
Rest API
Splunk
Terraform
GCP
CloudFormation
Prometheus
Azure
CI/CD
AWS
Bicep
Cortex
IAM
Cybersecurity
Microsoft Sentinel
Cortex XSOAR
Tines
SIEM
Apply
≈ $32k – $56k per year (Estimated) • In office • 14+ years exp • Bachelor's Degree • Bengaluru
Python
JavaScript
TypeScript
SQL
Node JS
Python
Django
Databases
PostgreSQL
AI/ML
LangGraph
LangChain
Prompt Engineering
AI Agents
Langfuse
LLM
Machine Learning
Frontend
Angular
React.js
DevOps
GCP
Azure
CI/CD
Git
AWS
Analytics
Power BI
Apply
In office • 3+ years exp • Bachelor's Degree
Python
Databases
Redis
AI/ML
Computer Vision
NLP
Transfer Learning
Transformers
TensorFlow
PyTorch
BERT
OpenAI
Hugging Face
Edge AI
Machine Learning
DevOps
Terraform
GCP
CloudFormation
Azure
CI/CD
Git
AWS
Docker
Kubernetes
Apply
≈ $17k – $35k per year (Estimated) • In office • 6+ years exp • Bachelor's Degree • Bengaluru
SQL
Databases
MS SQL
DevOps
GCP
Azure
AWS
Cybersecurity
ISO 27001
Active Directory
Analytics
Tableau
Power BI
ETL/ELT
SSIS
Management
Power Automate
Power Apps
Apply
≈ $27k – $54k per year (Estimated) • Hybrid • Moscow
Databases
PostgreSQL
RabbitMQ
Apache Kafka
DevOps
Rest API
Zabbix
Jaeger
Kibana
OpenTelemetry
VMWare
Prometheus
GitLab CI
CI/CD
Jenkins
Docker
Kubernetes
Grafana
SLI/SLO/SLA
TCP/IP
DNS
VLAN
Cybersecurity
Keycloak
Tcpdump
LDAP
Management
Confluence
Jira
ServiceNow
ITIL
ITSM
QA
Postman
Apply
≈ $63k – $110k per year (Estimated) • Hybrid • 5+ years exp • Warsaw
Python
JavaScript
AI/ML
Model Context Protocol
LLM
Red Teaming
LLM Guardrails
DevOps
Rest API
CI/CD
AWS
Kubernetes
IAM
Cybersecurity
DefectDojo
STRIDE
OWASP
Chips/EDA
PoC Library
Apply
IAM Specialist 3 days ago
≈ $49k – $87k per year (Estimated) • Hybrid • 4+ years exp • Warsaw
Python
Databases
MySQL
PostgreSQL
DevOps
AWS
IAM
Linux
Cybersecurity
Okta
PCI DSS
Management
Jira
Google Workspace
Apply
≈ $52k – $93k per year (Estimated) • Hybrid • 3+ years exp • Warsaw
Python
AI/ML
Function Calling
AI Agents
LLM
RAG
LLM Guardrails
EU AI Act
Tool Use
Cybersecurity
GDPR
Apply
≈ $56k – $148k per year (Estimated) • Hybrid • 6+ years exp • Bachelor's Degree • Dubai
Python
DevOps
GCP
Azure
CI/CD
AWS
Kubernetes
IAM
Cybersecurity
ISO 27001
NIST CSF
SOC 2
GDPR
OWASP
Web3
Smart Contracts
Staking
Apply
≈ $20k – $39k per year (Estimated) • In office • 3+ years exp • Warsaw
Apply
$50k – $62k per year • Remote (likely Poland) • Full-Time • 3+ years exp • Warsaw
AI/ML
Model Context Protocol
AI Agents
AWS Bedrock
AWS Bedrock AgentCore
DevOps
AWS
IAM
Cybersecurity
Zero Trust
Apply
≈ $50k – $89k per year (Estimated) • Hybrid • Full-Time • 4+ years exp • Warsaw
Python
AI/ML
LLM
LLM Guardrails
DevOps
Terraform
GCP
Azure
CI/CD
AWS
Kubernetes
Azure AKS
FinOps
IAM
Cybersecurity
SOC 2
Apply
≈ $48k – $82k per year (Estimated) • Hybrid • Full-Time • Warsaw
Python
SQL
Databases
Databricks
AI/ML
Machine Learning
DevOps
GCP
Azure
CI/CD
Apply
≈ $43k – $101k per year (Estimated) • Hybrid • 4+ years exp • Warsaw
Analytics
Microsoft Excel
Management
Agile
Apply
≈ $23k – $51k per year (Estimated) • Hybrid • 2+ years exp • Warsaw
Management
Agile
Microsoft Office
Apply
See all jobs
This is one of many
994,162 more open roles from verified company boards, updated every day.