Application Security Engineer - Vice President
Summary
The Application Security Engineer will drive shift-left security initiatives, manage threat modeling, and build security automation tools using Python. The role involves collaborating with developers to remediate vulnerabilities and securing API architectures within a fintech environment.
About the role:
We are looking for a technically strong Senior Application Security practitioner ready to take on real ownership. You will work directly with the Head of AppSec, contributing to the Secure Design practice and helping drive shift-left security across the organization.
What You'll Do
- Help build and mature the Secure Design and Threat Modeling program by defining methodology, review standards, and sign-off criteria across the organization
- Drive shift-left security initiatives, embedding security earlier in the development lifecycle through design reviews, developer enablement, and security gating in CI/CD
- Own API security as a discipline
- Support offensive security initiatives
- Build and maintain security automation in Python, tooling that scales AppSec capacity
- Work directly with developers on SAST and SCA remediation, scan optimization, and reducing friction in the security feedback loop
- Contribute to AI-assisted security pipelines; define escalation paths, SLAs, and accountability structures for vulnerability management
What We're Looking For
- Hands-on experience across secure design, threat modeling, API security, and offensive security
- Offensive security capability with penetration testing experience and solid understanding of real-world attack and API exploitation patterns
- Deep familiarity with OWASP Top 10 in practice
- API security depth, experience assessing REST and GraphQL APIs
- Python proficiency, comfortable building automation tools that others will depend on
- Experience in shift-left programs: security in CI/CD, developer enablement, design review processes
- Understanding of web application and API security
- Comfortable reading code across languages and engaging with engineering teams at technical depth
- Familiarity with cloud-native environments and attack surface management
- Demonstrated ability to influence across engineering and product and operate at architecture level
- Relevant certifications are a plus: OSCP, OSWE, GWEB, CSSLP, CISSP, CEH
- Exposure to AI-assisted security tooling or LLM security is a differentiator
- Experience as a developer and fluency in Ruby, Python, and Scala are a plus
We believe the best ideas and innovation happen when we are together. Employees in this role will work in the office four days, with the flexibility to work remotely one day (Friday).
Benefits
iCapital offers a comprehensive benefits package that includes a total compensation program consisting of competitive salary, annual performance bonus, and equity for all full-time employees; healthcare with 100% employer-paid health and dental insurance; and generous paid time off (PTO).
For additional information on iCapital Network, please visit Twitter: @icapitalnetwork | LinkedIn:
As published by greenhouse
First Name, Last Name, Email, Phone, Resume/CV, Cover Letter, Location
- Preferred First Name
- What is your full legal name?
- Are you legally eligible to work in the country where this role is located? choose one
- Do you currently require any type of visa sponsorship for employment? choose one
- How did you hear about this job? choose one
- If "Employee Referral" was selected for "How did you hear about this job?" please type the full name of the referring employee. If not, please type in "N/A".
- What is your LinkedIn profile URL? If applicable, please share the link. optional
- What is your personal website or online portfolio? If applicable, please share the link. optional