National AI Awards 2025Discover AI's trailblazers! Join us to celebrate innovation and nominate industry leaders.

Nominate & Attend

Principal Application Security Architect

Barclay Simpson
London
2 days ago
Create job alert

Position Overview Fast growing FinTech seeking a technically proficient Principal Application Security Architect to join our innovative FinTech organisation. This role is critical in shaping the security posture of complex, cloud-native applications that power fast-growing financial services and digital payments platforms. As an Application Security Architect, you will work closely with software engineers, DevSecOps specialists, product owners, and compliance teams to ensure that secure design principles and automated security controls are Embedded throughout the software development lifecycle (SDLC). You will take ownership of threat modeling, vulnerability management, and security automation efforts with a specific focus on cloud platforms, primarily Google Cloud Platform (GCP). You will be instrumental in building scalable, resilient security architectures that protect sensitive customer data, meet rigorous regulatory requirements, and enable rapid innovation in a dynamic FinTech environment. What You'll Do Application Security Architecture & Strategy Lead the design and implementation of comprehensive application security frameworks that guide the secure development of cloud-native APIs, microservices, and web applications.
Conduct detailed threat modeling workshops and architectural risk assessments, identifying vulnerabilities early and collaborating on risk mitigation strategies.
Define and enforce secure coding standards and architectural best practices aligned with industry benchmarks such as OWASP Top 10 and API Security Top 10.
Partner with cloud engineers and developers to embed security controls specific to GCP, such as workload identity, IAM policy enforcement, VPC Service Controls, and encryption.
Develop and maintain architectural blueprints and documentation that clearly communicate security design decisions and rationale across teams.
Security Testing & Automation Oversee the deployment and tuning of automated application security testing tools including Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), and Software Composition Analysis (SCA).
Collaborate with development teams to integrate security testing seamlessly into CI/CD pipelines, enabling early detection and continuous monitoring of vulnerabilities.
Drive the creation of custom security automation scripts and tools to enhance scanning coverage, improve detection accuracy, and streamline remediation workflows.
Analyze security findings to prioritize risk based on business impact, exploitability, and regulatory implications, and work with engineering teams to implement timely fixes.
Conduct regular security code reviews and support developers in secure coding practices to reduce vulnerabilities proactively.
Governance, Compliance & Training Ensure that application security architecture and practices comply with relevant regulatory and industry standards such as PCI-DSS, SOC 2, ISO 27001, and GDPR. Lead efforts to prepare for and support external and internal audits by providing comprehensive documentation, risk assessments, and remediation evidence. Develop and deliver targeted security training programs and awareness sessions designed to educate developers, testers, and product managers on secure development lifecycle best practices. Stay current with evolving FinTech regulations, cloud security trends, and emerging application threats to adapt security strategies proactively. Who You Are You are a passionate and detail-oriented security professional who thrives at the intersection of application development, cloud technology, and regulatory compliance. Your solid foundation in secure software engineering enables you to engage deeply with developers and architects to influence design decisions early and effectively. You have a deep understanding of cloud-native architectures, especially within Google Cloud Platform (GCP), and a clear grasp of the unique security challenges faced by FinTech companies operating in regulated environments. You are proactive in automating security processes and committed to fostering a culture of security- first thinking within fast-moving technical teams. Your communication skills allow you to articulate complex security concepts clearly and collaborate cross-functionally, driving security improvements that balance risk with business needs. Essential Qualifications Proven experience in application security or secure software engineering, preferably within FinTech or highly regulated industries.
Hands-on experience with a range of application security testing tools including SAST, DAST, and SCA, and integrating these into automated build and deployment pipelines.
Practical expertise with threat modeling methodologies such as STRIDE, PASTA, or Attack Trees.
Strong knowledge of secure coding standards and common vulnerabilities (OWASP Top 10, API Security Top 10) and how to mitigate them.
Familiarity with Google Cloud Platform (GCP) security features and best practices, including IAM, Cloud Armor, Security Command Center, and workload identity management.
Proficient in at least one programming or Scripting language such as Python, Java, JavaScript, or Go.
Solid understanding of FinTech compliance requirements and standards including PCI-DSS, SOC 2, GDPR, and ISO 27001. Excellent communication and collaboration skills, capable of working with diverse teams and stakeholders.
Nice to Have Industry certifications such as Certified Secure Software Lifecycle Professional (CSSLP), GIAC Web Application Penetration Tester (GWAPT), or Google Professional Cloud Security Engineer.
Experience securing containerized environments and orchestration platforms such as Kubernetes/GKE. Knowledge of DevSecOps tooling and automation frameworks (Jenkins, GitLab CI/CD, Terraform).
Familiarity with API security gateways, Web Application Firewalls (WAFs), and Runtime Application Self-Protection (RASP) technologies. Exposure to red teaming, adversary simulation, or threat intelligence focused on application layer attacks.
Experience in educating or mentoring engineering teams on secure development best practices.
What You'll Gain A critical leadership role with hands-on impact on securing innovative FinTech applications serving a global user base. The chance to architect and embed security practices in a cloud-first, automated development environment.
Work in a remote-first, agile culture that values innovation, collaboration, and continuous learning.
Opportunities for professional development including training and certifications.
The ability to directly influence business-critical security outcomes and help protect sensitive financial data in a fast-growing company.

#J-18808-Ljbffr

Related Jobs

View all jobs

Azure Security Architect

Principal Security Engineer (Vulnerability Management)

Principal Security Engineer

Principal Security Engineer (Vulnerability Management)

Principal Security Engineer (Vulnerability Management)

Principal Security Engineer (Vulnerability Management)

National AI Awards 2025

Subscribe to Future Tech Insights for the latest jobs & insights, direct to your inbox.

By subscribing, you agree to our privacy policy and terms of service.

Industry Insights

Discover insightful articles, industry insights, expert tips, and curated resources.

How to Present Cyber Security Solutions to Non-Technical Audiences: A Public Speaking Guide for Job Seekers

Cyber security is no longer just an IT issue—it’s a board-level priority. Whether you’re applying for a role in penetration testing, security operations, risk management, or compliance, your ability to clearly explain cyber threats and solutions to non-technical stakeholders is vital. This guide will help cyber security job seekers develop one of the most in-demand soft skills in the industry: public speaking. You’ll learn how to simplify complex concepts, structure effective presentations, use storytelling and analogies, and handle common stakeholder questions with confidence.

Cyber Security Jobs Employer Hotlist 2025: 50 UK Companies Actively Hiring Right Now

Bookmark this guide—refreshed every quarter—so you always know who’s really expanding their cyber security teams. Ransomware payouts broke records in 2024, the UK’s new Cyber Security Bill imposed mandatory breach disclosure, and the National Cyber Force’s move to Samlesbury has super‑charged the northern skills market. Result? Demand for security architects, SOC analysts, penetration testers, cloud‑security engineers, threat hunters & GRC specialists is at an all‑time high in 2025. Below you’ll find 50 organisations that have posted UK‑based cyber security vacancies or announced head‑count growth during the past eight weeks. They’re organised into five quick‑scan categories. For every employer you’ll see: Main UK hub Example live or recent vacancy Why it’s worth a look (tech stack, culture, mission) Search any company on CyberSecurityJobs.tech to view current ads, or set a free alert so fresh openings land straight in your inbox.

Return-to-Work Pathways: Relaunch Your Cyber Security Career with Returnships, Flexible & Hybrid Roles

Re-entering the workforce after a career break can feel especially challenging in a fast-moving field like cyber security. Whether you stepped away for parenting, caregiving or another life chapter, the UK’s cyber security sector now offers a range of return-to-work pathways—from structured returnships to flexible and hybrid roles. These programmes value the transferable skills and resilience you’ve developed during your break, pairing you with mentorship, upskilling opportunities and supportive networks to ease your transition back into cyber security. In this article, tailored for parents and carers, you’ll discover how to: Understand the growing demand for cyber security talent in the UK Translate your organisational, communication and problem-solving skills into cyber security roles Tackle common re-entry challenges with practical solutions Refresh your technical knowledge through targeted learning Access returnship and re-entry programmes specific to cyber security Find roles that accommodate family commitments—whether hybrid, flexible or full-time Balance your career relaunch with caring responsibilities Master applications, interviews and networking in cyber security Draw inspiration from real returner success stories Whether you aim to return as an analyst, penetration tester, security engineer or compliance specialist, this guide will equip you with the steps and resources to reignite your cyber security career.