Logo for JustMarkets

DevSecOps & Application Security Lead

Role overview

Qualifications

  • 5+ years of experience in DevOps, SRE, Platform Engineering, or related infrastructure/security roles
  • 3+ years focused on DevSecOps and Application Security
  • 1+ years in a lead/ownership role
  • Deep understanding of modern software development and hands-on experience integrating security checks into CI/CD pipelines

Responsibilities

  • Build the DevSecOps/AppSec function from scratch, and create the roadmap, KPIs, and metrics for leadership
  • Create secure development processes, including release security gates and vulnerability management
  • Choose, configure, and integrate security scanners (SAST, SCA, secrets) with a focus on automation and AI-assisted workflows
  • Run threat modeling and security reviews for high-risk systems and major architecture changes

About the company

JustMarkets logo

JustMarkets

Financial Services

JustMarkets is a top-notch online CFD trading brokerage that has over a decade of successful working experience with clients in 180+ countries. Customer is JustMarkets' core value. We always listen carefully to every feedback we get to ensure that our services and developments help clients achieve their trading goals in the most efficient way. Our multilingual 24/7 customer support is always ready to help every JustMarkets user. We are attentive to those who help us develop. To do this, we have created a Three-Level IB partner system that allows our affiliates to conduct profitable and transparent business activities with us. JustMarkets is continuously developing and improving trading conditions, providing the lowest spreads, reducing commissions, and expanding the range of tools to trade Majors, Minors, Indices, Stocks, Metals, and Energies. JustMarkets Copytrading service is an in-house development that allows users to automatically copy trades of successful traders whose riskiness is ranked using the Risk Score service. We are all about Markets!

Company details

IndustryFinancial Services
Company size201 - 500

Your match analysis

See how your profile stacks up against this role.

We compared the job requirements to your profile to show where you're strong and where you fall short.

Job description

We are looking for a DevSecOps and Application Security Lead to join our team and build our application security from scratch. In this role, you will lead the security direction within our department, focusing on integrating security into the software development process. By balancing automation with practical DevSecOps practices, you will help our engineering teams find and fix vulnerabilities early, ensuring our products are safe and strong without slowing down development.

Responsibilities

  • Build the DevSecOps/AppSec function from scratch, and create the roadmap, KPIs, and metrics for leadership
  • Create secure development processes, including release security gates and vulnerability management
  • Choose, configure, and integrate security scanners (SAST, SCA, secrets) with a focus on automation and AI-assisted workflows
  • Integrate security checks into pipelines and development processes together with Engineering, DevOps, and Product teams
  • Run threat modeling and security reviews for high-risk systems and major architecture changes
  • Create clear security standards, checklists, and practical guidelines for developers (covering code, APIs, and secrets)
  • Launch and grow a Security Champions program to involve engineers in security processes
  • Help investigate incidents related to application vulnerabilities, leaked secrets, and supply-chain attacks

Requirements

  • 5+ years of experience in DevOps, SRE, Platform Engineering, or related  infrastructure/security roles
  • 3+ years focused on DevSecOps and Application Security
  • 1+ years in a lead/ownership role
  • Deep understanding of modern software development, Git workflows, and hands-on experience integrating security checks into CI/CD pipelines without creating bottlenecks
  • Practical experience with SAST, SCA, secrets scanning, and vulnerability management (triage, risk rating, remediation, and validation)
  • Ability to select and scale security tools based on accuracy, false-positive rates, and developer experience
  • Strong knowledge of web/API/mobile risks (OWASP Top 10, auth, supply-chain risks) and ability to run threat modeling and secure design reviews
  • Good scripting skills (Python, Bash, or similar) and understanding of cloud-native/containerized environments
  • Ability to write clear security requirements and guidelines for developers
  • English - Intermediate+ or higher

Nice to Have

  • Experience building AppSec/DevSecOps functions from scratch or early maturity stages
  • Hands-on experience with tools like Snyk, Aikido, Semgrep, Trivy, Gitleaks, GitHub/GitLab Security, or SonarQube
  • Experience with cloud/IaC security, Kubernetes, and mobile app security
  • Knowledge of compliance standards (SOC 2, ISO 27001, PCI DSS, DORA) and experience with Bug Bounty or pentest coordination
  • Experience with Security Champions programs and AI-assisted security tools

We offer

  • 20 paid vacation days per year
  • 10 paid sick leave days per year
  • Public holidays as per the company’s approved Public holiday list
  • Medical budget
  • Opportunity to work remotely
  • Professional education budget
  • Language learning budget
  • Wellness budget (gym membership, sports gear and related expenses)

Apply once. Then go straight to the hiring manager.

After you apply, unlock the direct contact details of the people who actually make the call. A quick follow-up makes you 5x more likely to land an interview.

MR

Marcus Rivera

Chief Revenue Officer

m.rivera@company.com
linkedin.com/in/marcusrivera
Unlocked after you apply
·

DevSecOps Related jobs

Other jobs at JustMarkets

Premium

Reach out to the hiring manager directly.

Gain access to the contact details of the hiring managers who actually decide, and reach out to network with them directly. That, plus more when you upgrade:

  • Full match report with fit score and gaps
  • Career diagnostics on how recruiters read you
  • Curated company matches and warm intros
  • 48h early access to new roles

Cancel anytime.