{"id":453308,"url":"https://alion.io/job/icapital-application-security-engineer-vice-president","title":"Senior Application Security Engineer - Vice President","company":{"id":174521,"name":"iCapital","domain":"icapital.com","url":"https://alion.io/company/icapital","size_band":"501-1000","is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":"Greenhouse","truth_index":{"grade":"B","score":83,"open_postings":48,"ghost_share":0,"stale_share":0.5,"repost_share":0,"time_to_fill_p50_days":63,"computed_at":"2026-09-26T05:45:00Z"}},"role":"Security","role_family":"Security","seniority":"head","employment_type":null,"work_mode":"hybrid","remote_scope":null,"remote_scope_basis":null,"remote_working_hours":null,"hiring_geo_confidence":"structured","locations":["Lisbon, Portugal"],"countries":["PT"],"hiring_countries":[],"hiring_countries_total":0,"salary":null,"salary_estimate":{"min_usd":48000,"max_usd":120000,"period":"year","method":"global_role_cell_scaled_by_country","sample_n":106},"experience_years_min":null,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"CI/CD","optional":false},{"name":"GraphQL","optional":false},{"name":"OWASP Top 10","optional":false},{"name":"Python","optional":false},{"name":"Rest API","optional":false},{"name":"Shift-Left","optional":false},{"name":"Shift-Left Security","optional":false},{"name":"Threat Modeling","optional":false},{"name":"LLM","optional":true},{"name":"Ruby","optional":true},{"name":"Scala","optional":true}],"status":"live","first_seen_at":"2026-08-24T12:48:48Z","employer_posted_date":"2026-09-25","last_verified_at":"2026-09-27T04:14:08Z","board_verified":true,"closed_at":null,"days_open":33,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":33},"description":"About the role:\nWe are looking for a technically strong Senior Application Security practitioner ready to take on real ownership. You will work directly with the Head of AppSec, contributing to the Secure Design practice and helping drive shift-left security across the organization.\nWhat You'll Do\nHelp build and mature the Secure Design and Threat Modeling program by defining methodology, review standards, and sign-off criteria across the organization\nDrive shift-left security initiatives, embedding security earlier in the development lifecycle through design reviews, developer enablement, and security gating in CI/CD\nOwn API security as a discipline\nSupport offensive security initiatives\nBuild and maintain security automation in Python, tooling that scales AppSec capacity\nWork directly with developers on SAST and SCA remediation, scan optimization, and reducing friction in the security feedback loop\nContribute to AI-assisted security pipelines; define escalation paths, SLAs, and accountability structures for vulnerability management\nWhat We're Looking For\nHands-on experience across secure design, threat modeling, API security, and offensive security\nOffensive security capability with penetration testing experience and solid understanding of real-world attack and API exploitation patterns\nDeep familiarity with OWASP Top 10 in practice\nAPI security depth, experience assessing REST and GraphQL APIs\nPython proficiency, comfortable building automation tools that others will depend on\nExperience in shift-left programs: security in CI/CD, developer enablement, design review processes\nUnderstanding of web application and API security\nComfortable reading code across languages and engaging with engineering teams at technical depth\nFamiliarity with cloud-native environments and attack surface management\nDemonstrated ability to influence across engineering and product and operate at architecture level\nRelevant certifications are a plus: OSCP, OSWE, GWEB, CSSLP, CISSP, CEH\nExposure to AI-assisted security tooling or LLM security is a differentiator\nExperience as a developer and fluency in Ruby, Python, and Scala are a plus\nWe believe the best ideas and innovation happen when we are together. Employees in this role will work in the office four days, with the flexibility to work remotely one day (Friday).\nBenefits\niCapital offers a comprehensive benefits package that includes a total compensation program consisting of competitive salary, annual performance bonus, and equity for all full-time employees; healthcare with 100% employer-paid health and dental insurance; and generous paid time off (PTO).\nFor additional information on iCapital Network, please visit https://www.icapitalnetwork.com/about-us Twitter: @icapitalnetwork | LinkedIn: https://www.linkedin.com/company/icapital-network-inc","description_format":"text","description_chars":2825,"description_truncated":false,"requirements":{"experience_years_min":null,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":null,"security_clearance":false,"languages":[]},"benefits":["Dental insurance","Equity"],"hiring_locations":[{"name":"Portugal","iso":"PT","kind":"country"}],"hiring_excludes":[],"relocation_offered":false,"industries":["Application Security","Financial Software & Embedded Finance"],"lifecycle":[{"event":"open","at":"2026-09-06T09:09:34Z"}],"liveness":{"score":53,"band":"ok","label":"Likely open","p_open":1,"p_active":0.585,"p_room":0.9,"age_days":32,"expected_fill_days":63,"reasons":["conf:0","stale_co","velocity","win:mid","comp:brand"],"computed_at":"2026-09-26T05:45:00Z"},"pay":null,"html_url":"https://alion.io/job/icapital-application-security-engineer-vice-president","json_url":"https://alion.io/job/icapital-application-security-engineer-vice-president.json","meta":{"generated_at":"2026-09-27T05:32:34Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":4867,"day_limit":5000,"remaining_today":133,"minute_limit":60,"resets_at":"2026-09-28T00:00:00Z"}}}