Lead Application Security Engineer
Listed on 2025-12-08
-
IT/Tech
Cybersecurity, Systems Engineer
About Us
We’re the world’s leading provider of secure financial messaging services, headquartered in Belgium. We are the way the world moves value – across borders, through cities and overseas. No other organisation can address the scale, precision, pace and trust that this demands, and we’re proud to support the global economy.
We’re unique too. We were established to find a better way for the global financial community to move value – a reliable, safe and secure approach that the community can trust, completely. We’re always striving to be better and are constantly evolving in an ever-changing landscape, without undermining that trust. Five decades on, our vibrant community reflects the complexity and diversity of the financial ecosystem.
We innovate diligently, test exhaustively, then implement fast. In a connected and exciting era, our mission has never been more relevant. Swift now has a presence in 200+ countries and legal territories to serve a community of more than 12,000 banks and financial institutions.
We re looking for a Lead Application Security Engineer to be the security expert for 75+ developers who build the core systems behind Swift s global financial messaging. You ll bring deep technical skills and help shape how we do security across our mature application security program - the infrastructure that connects thousands of financial institutions depends on getting this right.
Your work will vary day-to-day - sometimes you ll be embedded directly with development teams, other times providing security advice when teams need it, and you ll also do centralized security reviews for APIs, identity systems, and authentication frameworks
In this role you will:
- Lead comprehensive security architecture reviews for Swift s applications across all business domains
- Conduct advanced code security reviews with developers across Java, JavaScript, C++, and emerging programming languages including Python
- Lead business security assessments for our most critical applications and figure out what security controls we need based on business requirements
- Optimize and evolve Dev Sec Ops tools within CI/CD pipelines to reduce false positives and improve developer adoption
- Cross-Functional Collaboration & Influence
- Partner with 75+ developers across API and Identity teams to integrate security seamlessly into agile development workflows
- Take complex security requirements and make them practical for development teams - some teams are security-savvy, others need more guidance
- Champion security best practices through technical mentorship, training sessions, and documentation that scales across multiple development squads
- Collaborate with architecture teams to establish security patterns and standards for all domains in application security
- Technical Innovation & Enhancement
- Drive continuous improvement initiatives to enhance developer security tooling and reduce friction in secure development practices
- Build metrics and reports that show how well our security efforts are working and where we re reducing risk
- Stay ahead of emerging threats specific to financial services applications and infrastructure
- Leverage deep knowledge of financial services threat landscape and attack vectors specific to payment systems and financial messaging
What will make you successful?
We are seeking professionals with:
- Bachelor s degree
- 8 years of hands-on application security experience with demonstrated expertise in secure coding, vulnerability assessment, and security architecture
- Advanced proficiency in Java, JavaScript, C++, and Python (emerging) with strong understanding of secure coding practices and common vulnerability patterns in these languages
- Extensive experience with application security testing tools (SAST, DAST, IAST, SCA) and their integration into automated CI/CD pipelines
- Proven experience in threat modeling and security design sessions for complex applications and systems
- Strong background in conducting advanced code security reviews and vulnerability assessments
- Strong background in API security including OAuth, JWT, rate limiting, API gateway security, and RESTful service protection
- Unde…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).