SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
CAIS is a fintech platform democratizing access to alternative investments for independent financial advisors, supporting over 50,000 advisors managing $6 trillion in network assets. The company seeks a Lead Application Security Engineer to own application security strategy and embed security into the core of product development.
In this role, you will define and drive CAIS's secure development approach, setting threat modeling strategy, owning security architecture and secure code reviews, and designing controls within the SDLC. You will leverage automation and AI to scale security work, transforming it from a manual checkpoint into a fast, clear, and useful experience for engineers.
Key responsibilities include:
**Secure Software Development & Architecture:**
- Own security elements of the SDLC, designing and implementing automated controls within CI/CD pipelines, including SAST, DAST, dependency scanning, and container security scanning
- Conduct security architecture and design reviews across product and platform areas, surfacing risk early with actionable remediation paths
- Drive threat modeling strategy, establishing it as a repeatable practice across engineering teams
**Vulnerability Management & Engineering Partnership:**
- Triage, validate, and prioritize security findings, coordinating remediation through resolution with clear ownership
- Liaise with vendors on penetration testing, vulnerability scanning, and threat modeling, translating external findings into prioritized action items
- Partner with engineers and product owners to embed security pragmatically into design, development, and release cycles
- Provide secure coding guidance and documentation to help teams understand risk and apply secure development practices independently
- Level up security capability across the tech stack, experimenting with new tooling, automation, and AI-assisted workflows
You are a hands-on technical leader comfortable reading production code and setting strategy. You have a builder's mindset, energized by growing an application security practice from early stage, and you partner effectively with engineers and product owners to make security a capability rather than a constraint.