Lead Application Security Engineer

Posted 2 Days Ago
Be an Early Applicant
London, England, GBR
Hybrid
Senior level
Fintech • Software • Financial Services
CAIS is the leading alternative investment platform for independent financial advisors.
The Role
Lead application security for the platform by embedding automated controls into the SDLC, conducting security architecture and code reviews, driving threat modeling, triaging vulnerabilities, coordinating remediations, partnering with engineering/product teams, and scaling tooling and AI-assisted workflows to raise security across cloud-native and containerized environments.
Summary Generated by Built In

CAIS is the pioneer in democratizing access to and education about alternative investments for independent financial advisors, empowering them to engage and transact with leading asset managers on a massive scale through a wide variety of alternative investment products and technology solutions. CAIS provides financial advisors with a broad selection of alternative investment strategies, including hedge funds, private equity, private credit, real estate, digital assets, and structured notes. CAIS also delivers industry-leading technology, operational efficiency, and world-class client service throughout the pre-trade, trade, and post-trade experience. CAIS supports over 50,000 advisors who oversee more than $6 trillion in network assets.

Application security sits at the center of how CAIS earns and keeps the trust of the advisors and asset managers who rely on our platform. As our lead for application security, you will own how we protect the applications and services we build and embedding security into the heart of how we design, write, and ship software.

You will define and drive our approach to secure development: setting threat modeling strategy, owning security architecture and secure code reviews, and designing the controls that live inside our SDLC. Just as importantly, you will use automation and AI to scale that work, turning security from a manual checkpoint into something engineers experience as fast, clear, and genuinely useful.

We are looking for a hands-on technical leader who is as comfortable reading production code as setting strategy. You are someone who enjoys partnering with engineers and product owners; you are eager to experiment with new technologies to raise our security bar across the stack, and you are easy to do business with. You see a growing security practice not as a constraint to enforce but as a capability to build, one that helps us ship reliable products, grow as engineers, and have some fun along the way.

Responsibilities

Secure Software Development & Architecture

  • Own security elements of the software development lifecycle, designing and implementing automated controls within CI/CD, including SAST, DAST, dependency and container security scanning.
  • Conduct security architecture and design reviews across product and platform areas, surfacing risk early and providing clear, actionable remediation paths.
  • Drive CAIS's threat modeling strategy, establishing it as a repeatable practice across teams rather than a one-off exercise.

Vulnerability Management & Engineering Partnership

  • Triage, validate, and prioritize findings, coordinating remediation through to resolution with clear ownership and follow-through.
  • Liaise with key vendors on penetration testing, vulnerability scanning, and threat modeling, translating external findings into prioritized action.
  • Partner with engineers and product owners to embed security pragmatically into design, development, and release, supporting teams without becoming a blocker.
  • Provide secure coding guidance and clear documentation that helps teams understand risk and apply secure development practices independently.
  • Level up CAIS's security capability across the tech stack, experimenting with new tooling, automation, and AI-assisted workflows as the practice grows.

Required Experience

  • Experience in application or product security teams. A software engineering background is
  • Ability to read and reason about production code and hold your own with senior engineers, with working knowledge of Java/Kotlin and JavaScript/TypeScript (React).
  • Solid AWS security experience, including securing cloud-native, containerized environments (e.g. EKS).
  • Hands-on experience with security tooling across the SDLC, such as SAST, DAST, and dependency or container scanning (specific products are not important).
  • Demonstrated experience driving threat modeling and leading security architecture and design reviews.
  • Proven ability to lead engineering and security teams in adopting AI tools and automated workflows when it comes to security as part of the SDLC .
  • A confident, collaborative communicator who partners effectively with engineers and product owners and explains risk clearly to both technical and non-technical audiences.
  • A builder's mindset, you are energized by growing an application security practice from an early stage, eager to experiment and collaborative along the way.

CAIS is consistently recognized as a Best Place to Work, and our culture is at the heart of our success. We are committed to fostering an inclusive environment where employees can be their most authentic self and feel inspired and supported to bring their voice forward to drive community, growth, and innovation. We are an equal opportunity employer, and do not discriminate on the basis of any protected attribute, including race, religion, color, national origin, gender, sexual orientation, gender identity, gender expression, age, marital or veteran status, pregnancy or disability, or any other basis protected under applicable law. Learn more about our culture, benefits, and people at https://www.caisgroup.com/our-company/careers

We use technology, including AI tools, to support parts of our recruitment process such as application screening, interview scheduling, and candidate communications. These tools are used to improve efficiency and consistency, but they do not replace human judgement. All hiring decisions are made by people, and we are committed to fair and unbiased assessment of every candidate.

Skills Required

  • Experience in application or product security teams
  • Software engineering background with ability to read and reason about production code
  • Working knowledge of Java and/or Kotlin
  • Working knowledge of JavaScript and/or TypeScript (React)
  • Solid AWS security experience, including securing cloud-native, containerized environments (e.g., EKS)
  • Hands-on experience with SAST, DAST, dependency and container scanning tools across the SDLC
  • Demonstrated experience driving threat modeling and leading security architecture and design reviews
  • Proven ability to lead engineering and security teams in adopting AI tools and automated security workflows
  • Strong communication skills to explain risk to technical and non-technical audiences
  • Builder's mindset and willingness to grow an application security practice from an early stage

What the Team is Saying

Sanjam
Mark
Elisandra
Adam
Heaven-Leigh

CAIS Compensation & Benefits Highlights

  • Healthcare Strength Highly subsidized medical, dental, and vision plans are emphasized, alongside monthly wellness/lifestyle reimbursements. A coverage‑waiver allowance and optional add‑ons (e.g., pet insurance, legal/ID‑theft) broaden the offering.
  • Parental & Family Support Up to 16 weeks of fully paid parental leave for new parents is explicitly offered. Family‑supportive leave is positioned as a standout element of the package.
  • Retirement Support A 401(k) program with a 4% company match is advertised. This adds a clear employer contribution to long‑term savings.

CAIS Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: New York, NY
341 Employees
Year Founded: 2009

What We Do

CAIS is the leading alternative investment platform for independent financial advisors. The CAIS platform powers the pre-trade, trade, and post-trade lifecycle of alternative investments providing financial advisors and alternative asset managers a single operating system for scale and efficiency. CAIS serves over 2,000 wealth management firms that support more than 50,000 financial advisors who oversee approximately $6 trillion in end-client assets. Founded in 2009, CAIS is headquartered in New York City with offices in Austin and London. CAIS continues to be recognized for its innovation and leadership including awards for Alternative Investment Firm of the Year by Wealth Solutions Report, WealthTech100 List by Fintech Global, Great Places to Work by Fortune, Best RIA Platform by SPi, Best Alternative Investments Solution by Finovate, and many others. For more information about CAIS, please visit www.caisgroup.com.

Why Work With Us

As CAIS continues to grow and develop award-winning technology, we need true agents of change to join our growing team. CAIS has opportunities for every skillset—from interns to directors. If you’re looking for a transformative, welcoming culture in which personal success is supported, consider joining our team.

Gallery

Gallery
Gallery
Gallery
Gallery
Gallery
Gallery
Gallery
Gallery
Gallery

CAIS Offices

Hybrid Workspace

Employees engage in a combination of remote and on-site work.

Typical time on-site: 3 days a week
HQNew York, NY
Austin, TX
London, GB
Red Bank, NJ
Learn more

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account