Head of Application Security

Posted 15 Days Ago
Be an Early Applicant
House, MS, USA
In-Office
Expert/Leader
Fintech • Payments • Financial Services
The Role
Lead and mature a global Application Security capability, define strategy and standards, oversee AppSec/DevSecOps/AI Security/cloud-native controls, embed security across the SDLC and CI/CD, drive secure design reviews, tooling adoption, and communicate risk to senior leadership while supporting audits and regulatory assurance.
Summary Generated by Built In

The Apex Group was established in Bermuda in 2003 and is now one of the world’s largest fund administration and middle office solutions providers.

Our business is unique in its ability to reach globally, service locally and provide cross-jurisdictional services. With our clients at the heart of everything we do, our hard-working team has successfully delivered on an unprecedented growth and transformation journey, and we are now represented by over circa 13,000 employees across 112 offices worldwide.Your career with us should reflect your energy and passion.

That’s why, at Apex Group, we will do more than simply ‘empower’ you. We will work to supercharge your unique skills and experience.

Take the lead and we’ll give you the support you need to be at the top of your game. And we offer you the freedom to be a positive disrupter and turn big ideas into bold, industry-changing realities.

For our business, for clients, and for you

The Role
Apex is seeking a Head of Application Security to lead and mature its global Application Security capability.  This is a senior leadership position responsible for defining strategy, setting standards, and driving execution across key domains: Application Security, DevSecOps, AI Security, and Cloud-Native Application Security[WJ1.1] Engineering.

As the Apex’s senior authority for secure software and platform delivery, you will ensure that security is embedded by design throughout the technology lifecycle—enabling engineering teams to innovate rapidly and safely while maintaining compliance with regulatory and business requirements.

Key Responsibilities[WJ2.1]
•    Define and own the global Application Security strategy aligned to Apex’s cyber risk posture and regulatory obligations.
•    Ensure developers meet KPI’s and business deliverables.
•    Ensure developers keep up with emerging threats and technologies.
•    Lead and develop multiple security engineering teams across Application Security, DevSecOps, AI & Data Security[WJ3.1], and Cloud & Infrastructure[WJ4.1] Developer Platform Security.
•    Serve as the senior security authority for application, platform, and DevSecOps-related design and engineering decisions.
•    Ensure security controls are documented and [WJ5.1]embedded throughout the software development lifecycle (SDLC) and CI/CD pipelines.
•    Oversee application threat modelling, secure design reviews, and architecture risk assessments.
•    Drive adoption of secure coding standards, automated security testing (SAST, DAST, SCA), and secrets management.
•    Provide oversight on cloud-native and infrastructure security patterns in hybrid and multi-cloud environments.
•    Define security guardrails for AI-enabled applications, data pipelines, and emerging technologies.
•    Partner with Architecture, Engineering, Cloud, and Platform teams to deliver secure-by-default solutions.
•    Translate security policies and standards into practical, consumable engineering guidance.
•    Communicate application and platform risk to senior leadership and governance forums.
•    Support audit, regulatory, penetration testing and[WJ6.1] assurance activities related to application and platform security.
•    Execute delegated tasks as deemed appropriate by the Group CISO and other empowered Group Cyber leadership authorities, ensuring timely and effective completion in alignment with organizational priorities.
•    Support the Group Cyber Strategy end-to-end, driving alignment of all activities, decisions, and deliverables with strategic objectives and business outcomes.

Areas of Specialization
•    Application Security: Secure software architecture, threat modeling, secure design reviews, vulnerability management, and secure coding practices.
•    DevSecOps: CI/CD pipeline security, automation of security controls, integration of security tooling, and developer enablement.
•    Cloud & Infrastructure Security: Secure cloud-native architectures, infrastructure-as-code security, and platform hardening across hybrid and multi-cloud environments.
•    AI Security: Security and governance controls for AI-enabled applications, data pipelines, and emerging technologies.

Required Experience & Skills
•    Experience: 
o    10+ years in cybersecurity, software engineering, or platform engineering roles.
o    8+ years in senior management positions within security engineering, architecture, or similar leadership roles, with proven accountability for strategy, team leadership and delivery of enterprise-scale security programs. 
•    Technical Expertise: [WJ7.1]
o    Strong hands-on understanding of application security architecture, threat modeling, and DevSecOps practices.
o    Proven experience in securing microservices architecture and API ecosystems. 
o    Knowledge of Gitlab, GitHub and API security and integrations.
o    Experience securing applications and platforms in cloud environments (Azure, AWS and OCI).
o    Deep knowledge of security principles, secure design patterns, and defense-in-depth strategies.
•    Knowledge of Standards: [WJ8.1]
o    Familiarity with frameworks such as NIST, ISO 27001, OWASP, SOC1 and SOC2.
o    Familiarity with Agile, iterative and incremental development models.
•    Leadership Skills: 
o    Demonstrated ability to lead, mentor, and develop high-performing security engineering teams across distributed or multi-location environments.
o    Proven track record influencing senior stakeholders and driving security initiatives aligned with business objectives.
•    Communication Skills: 
o    Ability to articulate technical risks and security recommendations to both technical and non-technical stakeholders, including executive leadership and governance forums.

Qualifications
•    Relevant certifications: CISSP, CCSP, CSSLP, AWS/Azure Security, or similar.
•    Exposure to architecture frameworks (SABSA, TOGAF).
•    Experience in financial services or highly regulated environments.
•    Familiarity with AI security, data protection, and modern platform engineering models.
What will you get in return:
•    Opportunity to shape and lead a critical global security capability.
•    Exposure to enterprise-scale, cloud-native, and modern engineering environments.
•    Collaboration with senior security, architecture, and technology leaders across the organisation.
•    A strong focus on team development, ownership, and career growth.

Disclaimer: Unsolicited CVs sent to Apex (Talent Acquisition Team or Hiring Managers) by recruitment agencies will not be accepted for this position. Apex operates a direct sourcing model and where agency assistance is required, the Talent Acquisition team will engage directly with our exclusive recruitment partners.

Skills Required

  • 10+ years in cybersecurity, software engineering, or platform engineering roles
  • 8+ years in senior management positions within security engineering, architecture, or similar leadership roles
  • Strong hands-on understanding of application security architecture, threat modeling, and DevSecOps practices
  • Proven experience in securing microservices architecture and API ecosystems
  • Knowledge of GitLab and GitHub and API security integrations
  • Experience securing applications and platforms in cloud environments (Azure, AWS, OCI)
  • Experience with automated security testing (SAST, DAST, SCA) and secrets management
  • Familiarity with frameworks such as NIST, ISO 27001, OWASP, SOC1 and SOC2
  • Demonstrated ability to lead, mentor, and develop high-performing distributed security engineering teams
  • Proven track record influencing senior stakeholders and driving security initiatives aligned with business objectives
  • Ability to articulate technical risks and security recommendations to technical and non-technical stakeholders including executives
  • Relevant certifications (CISSP, CCSP, CSSLP, AWS/Azure Security, or similar)
  • Experience in financial services or highly regulated environments
  • Familiarity with AI security, data protection, and modern platform engineering models
  • Exposure to architecture frameworks (SABSA, TOGAF)

Apex Group Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Apex Group and has not been reviewed or approved by Apex Group.

  • Flexible Benefits Flexible benefits are positioned as being tailored by country, with localized packages and perks that can differ by jurisdiction. Mobility options such as the JUMP program add a non-cash element that can increase the perceived total rewards value for those who can access it.
  • Wellbeing & Lifestyle Benefits Wellbeing support is described as including EAPs, mental-health workshops, mentoring support, and local lifestyle perks like gym or cycle-to-work schemes. These offerings broaden the benefits mix beyond purely financial rewards.
  • Retirement Support Retirement support is described in at least one jurisdiction as including an employer match structure and an additional automatic contribution after tenure. This can strengthen the non-salary portion of total compensation where offered.

Apex Group Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
7,423 Employees
Year Founded: 2003

What We Do

We are a single-source financial solutions provider dedicated to driving positive change while supporting the growth and ambitions of asset managers, allocators, financial institutions, and family offices around the world. Established in Bermuda in 2003, we have continually disrupted the industry through our investment in innovation and talent. Today, we set the pace in fund and asset servicing and stand out for our unique single-source solution and unified cross asset-class platform which supports the entire value chain, harnesses leading innovative technology, and benefits from cross-jurisdictional expertise delivered by a long-standing management team and over 13,000 highly integrated professionals. As a pioneering data and fintech-enabled company, we are a disruptor driving digital tools into fund and asset servicing. However, our vision to drive positive change extends beyond the industry. The Apex Foundation, a not-for-profit entity, is our passionate commitment to empower sustainable change

Similar Jobs

General Motors Logo General Motors

Senior Software Engineer

Automotive • Big Data • Information Technology • Robotics • Software • Transportation • Manufacturing
Remote or Hybrid
United States
165000 Employees

General Motors Logo General Motors

District Manager, Sales - Western Region

Automotive • Big Data • Information Technology • Robotics • Software • Transportation • Manufacturing
Remote or Hybrid
United States
165000 Employees
76K-114K Annually

General Motors Logo General Motors

Staff Software Engineer

Automotive • Big Data • Information Technology • Robotics • Software • Transportation • Manufacturing
Remote or Hybrid
United States
165000 Employees

General Motors Logo General Motors

Sales Manager

Automotive • Big Data • Information Technology • Robotics • Software • Transportation • Manufacturing
Remote or Hybrid
United States
165000 Employees

Similar Companies Hiring

Hanover Park Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
42 Employees
Kepler  Thumbnail
Artificial Intelligence • Fintech • Software
New York, New York
9 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account