988,386open jobs
59,033companies
162,644added this week
Browse all
Salary
≈ $63k – $110k per year (Estimated)
Location
Hybrid (Warsaw, Poland)
Seniority
Senior · 5+ years exp

Confirmed on the employer's own hiring board on Sep 30, 2026. First seen by Alion on Sep 29, 2026. Capital.com scores A on the Alion truth index.

Overview
Company
Impact
Profile match
Capital.com is a global fintech company and online trading platform headquartered in Limassol, Cyprus, and founded in 2016. The company provides access to over 5,500 financial instruments including contracts for difference (CFDs) on stocks, indices, commodities, forex, and cryptocurrencies. It operates internationally with offices in London, Melbourne, Warsaw, and Dubai, serving over three million registered accounts through its proprietary AI-powered web and mobile platforms.

Capital.com's Product Security team protects our web and mobile applications, infrastructure, and external perimeter in a highly regulated environment. As Senior/Staff Application Security Engineer, you will raise the bar for application security across the organisation. This role is measured by leverage: how well you design, automate, and scale security processes so that many engineering teams can build securely by default.

You will lead security architecture reviews and threat modelling, increasingly with the help of AI tooling, and turn one-off security work into repeatable, self-service capabilities. The role combines deep hands-on offensive and defensive security expertise with the engineering mindset needed to automate at scale. You will work closely with development, QA, DevOps, and platform teams.

Responsibilities:

    Security Architecture & Threat Modelling:

    • Lead security architecture reviews and threat modelling for new and existing systems, using AI tools to make reviews faster, more consistent, and scalable across teams
    • Act as a security force multiplier by influencing the standards, patterns, and guardrails that let teams move fast and stay secure
    • Security Automation & Tooling:

      • Design, build, and automate scalable security processes that engineering teams can self-serve, covering secure design review, threat modelling, testing, and remediation workflows
      • Integrate and automate security checks across the SDLC and CI/CD pipelines (SAST, DAST, SCA, secrets, and IaC scanning), tuned for strong signal and low friction
      • Own and evolve security tooling such as DefectDojo and SAST, DAST, and SCA platforms, maximising automation, coverage, and integration
      • Apply AI and LLM-based tooling to architecture review, threat modelling, code review, and vulnerability triage, and help define how the team adopts these tools safely
      • Security Testing & Vulnerability Management:

        • Conduct and oversee security assessments of web and mobile applications, APIs, and cloud infrastructure, including manual testing and PoC development
        • Run vulnerability scans across internal infrastructure and the external perimeter, then analyse findings, define remediation, and track issues to closure
        • Support and triage the Bug Bounty Program and external vulnerability reports, automating triage where possible
        • Participate in and help lead red teaming and offensive security exercises
        • Enablement:

          • Drive knowledge sharing on secure development, mentor engineers, and deliver training for development and QA teams

Requirements:

    Experience:

    • 5+ years in application or product security, or equivalent depth, with a track record of senior or staff-level impact
    • Demonstrable experience leading security architecture reviews and threat modelling (e.g. STRIDE, attack trees, data-flow analysis) across multiple teams or products
    • Proven ability to automate and scale security processes by building tooling, integrations, and self-service workflows that reduce manual effort
    • Technical:

      • Strong hands-on security testing skills, including code review and web, mobile, and API application security assessments, as well as the ability to triage and validate external vulnerability reports and bug bounty submissions
      • Strong software engineering ability in at least one language (e.g. Python, Go, JavaScript), with the ability to build automation, not just scripts
      • Deep understanding of the OWASP Top Ten, secure design, and secure coding best practices
      • Experience with SAST, DAST, SCA, and vulnerability management platforms, and integrating them into CI/CD
      • Strong understanding of modern application architectures: REST APIs, microservices, cloud-based systems, and containers
      • Practical experience applying AI and LLM tooling to security work, or clear enthusiasm and aptitude to do so
      • Collaboration:

        • Excellent communication and influencing skills: you can explain security concepts to technical and non-technical stakeholders and drive change without direct authority
        • A self-starter who enjoys solving complex problems, building leverage through automation, mentoring others, and strengthening security culture

Nice to have:

    • Experience securing the AI harness: hardening LLM and agent pipelines, prompts, tool and MCP integrations, and model endpoints against prompt injection, data leakage, and insecure agent actions
    • Experience securing Kubernetes, including cluster hardening, RBAC, network policies, admission control, workload isolation, and image and supply-chain security
    • Experience securing AWS infrastructure, including IAM, network and account architecture, key and secret management, and CSPM
    • Experience building AI-assisted security tooling or internal self-service security platforms
    • Experience mentoring or technically leading a security team
    • Offensive or advanced security certifications such as OSAI, OSEP, OSCP, or OSWE

What you'll get in return:

  • You will join the company, that cares about work and life balance
  • Annual Bonus based on the performance review cycle
  • Generous Annual Leave Policy
  • Medical Insurance and Pension fund, with additional benefit packages based on the location
  • Hybrid working model (3 days from our modern office and 2 days fully remotely)
  • Comprehensive Workation Policy with 30 more remote days available.
  • Possibility of taking two additional days of paid leave per year to dedicate to volunteering efforts.
Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
988,386 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account Continue with Google
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Security
Similar stack
Same company
Warsaw
DevSecOps Engineer 27 days ago
≈ $60k – $106k per year (Estimated) • Hybrid • Full-Time • 8+ years exp • Bachelor's Degree • Łódź
AI/ML
LLM
LLM Guardrails
NIST AI RMF
DevOps
Terraform
FluxCD
GitLab CI
Azure
CI/CD
GitOps
AWS
Kubernetes
IAM
Cybersecurity
HashiCorp Vault
ISO 27001
NIST CSF
CIS Benchmarks
SOC 2
OWASP ASVS
Threat Modeling
PKI
OWASP
Apply
≈ $50k – $89k per year (Estimated) • Hybrid • Full-Time • 4+ years exp • Warsaw
Python
AI/ML
LLM
LLM Guardrails
DevOps
Terraform
GCP
Azure
CI/CD
AWS
Kubernetes
Azure AKS
FinOps
IAM
Cybersecurity
SOC 2
Apply
≈ $46k – $83k per year (Estimated) • In office • Full-Time • 3+ years exp • Poznań
Cybersecurity
SIEM
Management
Agile
Apply
≈ $24k – $67k per year (Estimated) • Hybrid • Full-Time • 1+ year exp • Gdańsk
DevOps
Linux
Windows
Cybersecurity
Microsoft Sentinel
Tanium
SIEM
Management
Service Desk
Apply
≈ $64k – $116k per year (Estimated) • Remote (Poland) • Full-Time
DevOps
IAM
Cybersecurity
ISO 27001
SOC 2
Mend
SIEM
Apply
$205k – $426k per year • In office • Bachelor's Degree • San Antonio
Python
JavaScript
PowerShell
AI/ML
AI Agents
DevOps
Rest API
Splunk
Terraform
GCP
CloudFormation
Prometheus
Azure
CI/CD
AWS
Bicep
Cortex
IAM
Cybersecurity
Microsoft Sentinel
Cortex XSOAR
Tines
SIEM
Apply
≈ $32k – $56k per year (Estimated) • In office • 14+ years exp • Bachelor's Degree • Bengaluru
Python
JavaScript
TypeScript
SQL
Node JS
Python
Django
Databases
PostgreSQL
AI/ML
LangGraph
LangChain
Prompt Engineering
AI Agents
Langfuse
LLM
Machine Learning
Frontend
Angular
React.js
DevOps
GCP
Azure
CI/CD
Git
AWS
Analytics
Power BI
Apply
≈ $25k – $57k per year (Estimated) • In office • 4+ years exp • Bachelor's Degree • Bengaluru
JavaScript
TypeScript
SQL
C#
C#
.NET
Entity Framework Core
Frontend
Angular
DevOps
Azure
CI/CD
Management
Agile
Apply
≈ $16k – $40k per year (Estimated) • In office • 1+ year exp • Bachelor's Degree • Johannesburg
Python
JavaScript
Ruby
C#
C++
C#
.NET
Databases
Azure SQL Database
AI/ML
Machine Learning
Frontend
JQuery
DevOps
Azure
Git
Analytics
Power BI
Microsoft Excel
Management
Power Automate
SharePoint
Agile
Apply
≈ $16k – $42k per year (Estimated) • In office • 4+ years exp • Bachelor's Degree • Kolkata
JavaScript
TypeScript
SQL
C#
C#
.NET
Entity Framework Core
Frontend
Angular
DevOps
Azure
CI/CD
Management
Agile
Apply
≈ $71k – $132k per year (Estimated) • Hybrid • 5+ years exp • Warsaw
Frontend
GraphQL
DevOps
Rest API
GCP
CI/CD
AWS
Docker
Kubernetes
Cybersecurity
PCI DSS
GDPR
OWASP ASVS
OWASP
Apply
IAM Specialist 3 days ago
≈ $49k – $87k per year (Estimated) • Hybrid • 4+ years exp • Warsaw
Python
Databases
MySQL
PostgreSQL
DevOps
AWS
IAM
Linux
Cybersecurity
Okta
PCI DSS
Management
Jira
Google Workspace
Apply
≈ $52k – $93k per year (Estimated) • Hybrid • 3+ years exp • Warsaw
Python
AI/ML
Function Calling
AI Agents
LLM
RAG
LLM Guardrails
EU AI Act
Tool Use
Cybersecurity
GDPR
Apply
≈ $56k – $148k per year (Estimated) • Hybrid • 6+ years exp • Bachelor's Degree • Dubai
Python
DevOps
GCP
Azure
CI/CD
AWS
Kubernetes
IAM
Cybersecurity
ISO 27001
NIST CSF
SOC 2
GDPR
OWASP
Web3
Smart Contracts
Staking
Apply
≈ $20k – $39k per year (Estimated) • In office • 3+ years exp • Warsaw
Apply
$50k – $62k per year • Remote (likely Poland) • Full-Time • 3+ years exp • Warsaw
AI/ML
Model Context Protocol
AI Agents
AWS Bedrock
AWS Bedrock AgentCore
DevOps
AWS
IAM
Cybersecurity
Zero Trust
Apply
≈ $50k – $89k per year (Estimated) • Hybrid • Full-Time • 4+ years exp • Warsaw
Python
AI/ML
LLM
LLM Guardrails
DevOps
Terraform
GCP
Azure
CI/CD
AWS
Kubernetes
Azure AKS
FinOps
IAM
Cybersecurity
SOC 2
Apply
≈ $48k – $82k per year (Estimated) • Hybrid • Full-Time • Warsaw
Python
SQL
Databases
Databricks
AI/ML
Machine Learning
DevOps
GCP
Azure
CI/CD
Apply
≈ $43k – $101k per year (Estimated) • Hybrid • 4+ years exp • Warsaw
Analytics
Microsoft Excel
Management
Agile
Apply
≈ $23k – $51k per year (Estimated) • Hybrid • 2+ years exp • Warsaw
Management
Agile
Microsoft Office
Apply
See all jobs
This is one of many
988,386 more open roles from verified company boards, updated every day.