Startups

Application Security Engineer - Assistant Vice President

iCapital · Salt Lake City, Utah, United States · On-site

← All jobs
About iCapital

Helping Financial Advisors and Wealth Managers incorporate alternative strategies at scale. Helping Asset Managers open new lanes of distribution.

About the role

ICapital is looking for a hands-on Application Security practitioner to join a small, high-impact team building a modern AppSec program. This individual will work directly with the Head of AppSec and senior team members, executing secure design, API security, and developer enablement.

What they're looking for

  • Support threat modeling and design reviews across a broad and growing service portfolio
  • Support shift-left security initiatives, security in CI/CD, developer guidance, and SAST and SCA remediation workflows
  • Contribute to API security across the organization, assessing API exposure, validating authentication and authorization patterns
  • Write Python automation that scales AppSec capacity: triage tooling, finding pipelines, security context enrichment
  • Work directly with developers to remediate SAST and SCA findings, reduce false positive noise, and build security habits across engineering
  • Hands-on experience across some secure design and threat modeling, API security, offensive security, or SAST/SCA program work
More about this role

About the Role

ICapital is looking for a hands-on Application Security practitioner to join a small, high-impact team building a modern AppSec program. This individual will work directly with the Head of AppSec and senior team members, executing secure design, API security, and developer enablement.

Responsibilities

  • Support threat modeling and design reviews across a broad and growing service portfolio.
  • Support shift-left security initiatives, security in CI/CD, developer guidance, and SAST and SCA remediation workflows.
  • Contribute to API security across the organization, assessing API exposure, validating authentication and authorization patterns.
  • Write Python automation that scales AppSec capacity: triage tooling, finding pipelines, security context enrichment.
  • Work directly with developers to remediate SAST and SCA findings, reduce false positive noise, and build security habits across engineering.

Qualifications

  • Hands-on experience across some secure design and threat modeling, API security, offensive security, or SAST/SCA program work
  • Real understanding of attack patterns and exploitation techniques
  • Familiar with OWASP Top 10 in practice
  • API security...

Read the full posting on iCapital's site ↗

Information Security

Build your edge while you search

Free tools for founders and investors, plus VC Unfiltered, our take on startups, venture and the people who build them.