← All roles Apply at iCapital
Application Security Engineer - Assistant Vice President
iCapital · Salt Lake City
Posted 3 September 2026 · Information Security · via Greenhouse
Apply for this roleAbout this role
About the Role
ICapital is looking for a hands-on Application Security practitioner to join a small, high-impact team building a modern AppSec program. This individual will work directly with the Head of AppSec and senior team members, executing secure design, API security, and developer enablement.
Responsibilities
- Support threat modeling and design reviews across a broad and growing service portfolio.
- Support shift-left security initiatives, security in CI/CD, developer guidance, and SAST and SCA remediation workflows.
- Contribute to API security across the organization, assessing API exposure, validating authentication and authorization patterns.
- Write Python automation that scales AppSec capacity: triage tooling, finding pipelines, security context enrichment.
- Work directly with developers to remediate SAST and SCA findings, reduce false positive noise, and build security habits across engineering.
- Hands-on experience across some secure design and threat modeling, API security, offensive security, or SAST/SCA program work
- Real understanding of attack patterns and exploitation techniques
- Familiar with OWASP Top 10 in practice
- API security experience with REST and GraphQL assessment
- Able to build and maintain security automation in Python, tooling that scales AppSec capacity
- Understanding of web application and API security
- Able to operate with autonomy in an environment still building its processes
- Relevant certifications, cloud-native environment experience and exposure to AI/LLM security are a plus
- Experience as a developer or engineer and fluency in Ruby, Python, and Scala are a plus