Lead Application Security Engineer

Company: CAIS
Apply for the Lead Application Security Engineer
Location: London
Job Description:

Overview

In this role you will own the security of CAIS applications and services, embedding secure development practices into the software lifecycle. You will define threat modeling, security architecture, and automated controls to protect our platform at scale, partnering with engineers and product owners. You’ll drive vulnerability management and collaborate with vendors to translate findings into actionable fixes. By advancing AI-enabled security workflows, you help engineers ship reliable products while growing a security-first culture.

Responsibilities

  • Own security elements of the SDLC and implement automated controls in CI/CD (SAST, DAST, dependency and container scanning)
  • Conduct security architecture and design reviews across product and platform areas with actionable remediation paths
  • Lead threat modeling strategy and establish repeatable practice across teams
  • Triage, validate, and prioritize findings; coordinate remediation through to resolution
  • Liaise with vendors on penetration testing, vulnerability scanning, and threat modeling; translate findings into actions
  • Partner with engineers and product owners to embed secure development practices without becoming a blocker
  • Provide secure coding guidance and documentation to help teams understand risk
  • Level up security capability across the stack with new tooling, automation, and AI-assisted workflows

Key requirements

  • Experience in application or product security teams
  • Software engineering background with ability to read production code; knowledge of Java/Kotlin and JavaScript/TypeScript (React)
  • Solid AWS security experience, including cloud-native/containerized environments (e.g. EKS)
  • Hands-on experience with SDLC security tooling (SAST, DAST, dependency/container scanning)
  • Proven experience driving threat modeling and leading security architecture/design reviews
  • Experience leading engineering and security teams in adopting AI tools and automated workflows in SDLC
  • Strong communicator who collaborates with engineers and product owners and explains risk to technical and non-technical audiences
  • Builder’s mindset; eager to grow an early-stage application security practice
  • collaborative
  • clear communicator
  • risk-focused
  • SAST
  • DAST
  • dependency scanning

…

Posted: September 14th, 2026