Senior Cybersecurity Developer / Application Security Architect (Equity Only)

HolistiQ Holdings
UK
about 2 months ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
8 years minimum
Compensation
£54,940.0 - £120,782.0
Working hours
Regular working hours
Job source

Tech stack

Kubernetes Security Java (Programming Language) .NET Framework Application Programming Interfaces (APIs) Amazon Web Services Amazon S3 Software System Penetration Testing User Authentication Microsoft Azure C Sharp (Programming Language) C++ (Programming Language) Software as a Service
+44 more
Cloud Computing Cloud Computing Security Cyber Security DevOps Digital Assets Distributed Systems Payment Systems Fraud Prevention and Detection Github Identity and Access Management Information Systems Security Architecture Professional Key Management PostgreSQL Microsoft SQL Server OAuth Open Web Application Security Systems Development Life Cycle Role-Based Access Control Openid Connect Swagger JSON Web Token Secure Coding Software Engineering Openapi .NET Core Software Security Asp.net Web Api Backend Xunit Specflow Gitlab-ci Playwright Cosmos DB Unreal Engine Api Gateway Restful APIs Marketplace Devsecops Atlassian Bamboo Docker Static Application Security Testing Vulnerability Analysis Microservices Dynamic Application Security Testing

Job description

We are not looking for someone to simply monitor systems, produce reports, or tick compliance boxes.

We are looking for someone who thinks differently.

Someone who naturally questions how systems can be exploited, how trust can be broken, and how vulnerabilities can be eliminated before they become problems.

Someone who can think like an attacker, build like an engineer, and lead like an architect.

As our ecosystem continues to grow, security will be embedded into every product, feature, transaction, reward system, customer interaction, and business partnership. We believe security is not an afterthought-it is a competitive advantage.

Role Overview

This is a strategic technical leadership opportunity for an experienced Cybersecurity Developer / Application Security Architect who wants to play a key role in shaping the future of multiple products and platforms.

You will work alongside our senior engineering team to design secure architectures, challenge assumptions, identify weaknesses before others do, and build secure, scalable, and resilient systems from day one.

The successful candidate will become part of our core leadership team, helping define security strategy, governance frameworks, technical standards, and long-term product architecture across the HolistiQ ecosystem.

Requirements

Do you have experience in SDLC?, * Minimum 8 years’ experience in software development, cybersecurity, application security, or security architecture

  • Proven experience securing production applications, APIs, cloud-native environments, and distributed systems
  • Experience conducting vulnerability assessments, penetration testing, threat modelling, and security reviews
  • Strong understanding of Secure Software Development Lifecycle (SSDLC)

Application Security

  • OWASP Top 10
  • OAuth2, OpenID Connect, JWT
  • Authentication and Authorisation Systems
  • Role-Based Access Control (RBAC)
  • API Security
  • Secure Coding Practices
  • Threat Modelling
  • Fraud Prevention and Abuse Detection
  • Identity and Access Management (IAM)

Cloud Security & DevSecOps

  • AWS Security (API Gateway, Cognito, Lambda, S3, RDS/Aurora)
  • Azure Security (DevOps, App Services, KeyVault, Cosmos DB)
  • Docker Security
  • Kubernetes Security
  • GitHub Security Workflows
  • GitLab CI/CD or Azure Pipelines
  • DevSecOps Methodologies
  • Secrets Management
  • Infrastructure Security

Backend & Technical Knowledge

  • C# .NET / .NET Core / .NET 6-8
  • Java (Spring or similar)
  • ASP.NET Web API
  • REST APIs (Swagger/OpenAPI)
  • Microservices Architecture
  • PostgreSQL
  • SQL Server

Security Testing & Automation

  • Playwright
  • SpecFlow
  • xUnit
  • Security Testing Automation
  • Vulnerability Scanning
  • SAST and DAST Tooling
  • TDD and Secure Development Practices

Security Governance & Compliance

  • Cyber Essentials
  • Cyber Essentials Plus
  • ISO 27001
  • GDPR
  • UK Data Protection Act 2018
  • Security Policies and Governance Frameworks
  • Incident Response Planning
  • Security Monitoring and Audit Controls

Highly Desirable Experience

  • Marketplace Platforms
  • SaaS Products
  • E-Commerce Systems
  • Payment Platforms
  • Loyalty and Rewards Programmes
  • Digital Wallets
  • Platform Credits and Cashback Systems
  • Subscription-Based Platforms
  • Fraud Detection Systems

Gaming & Interactive Systems (Advantageous)

  • Unity Engine (C#)
  • Unreal Engine (C++)
  • Multiplayer Systems Security
  • Virtual Economies and Reward Systems
  • Anti-Fraud and Anti-Cheat Concepts
  • Gamification Systems and Engagement Mechanics
  • Digital Asset and Transaction Security

Benefits & conditions

  • Profit sharing linked to long-term company growth
  • Strategic influence over security, architecture, and technical standards
  • The opportunity to help shape multiple products across several industries

This is not a traditional employment opportunity. We are looking for someone who wants to help build, protect, and scale innovative technology platforms while sharing in the long-term value they create.

The salary field shown on Indeed is a platform requirement and should be treated as a placeholder only.

Who This Is For

This opportunity is for someone who:

  • Naturally looks for vulnerabilities others miss
  • Enjoys breaking systems to understand how they can be improved
  • Thinks like a hacker but builds with integrity
  • Wants influence over technical strategy and security direction
  • Believes security should be designed into products, not added later
  • Enjoys solving complex technical challenges
  • Wants to be part of a long-term vision rather than a short-term project
  • Values ownership, accountability, and innovation

Who This Is Not For

This role is not suitable for candidates seeking:

  • Traditional corporate cybersecurity roles
  • Box-ticking compliance positions
  • Fixed salary employment at this stage
  • Low-responsibility environments
  • Short-term opportunities

Why Join HolistiQ Technologies

  • Join the core leadership team
  • Shape security strategy from the ground up
  • Equity participation and profit sharing-60% among the team
  • Influence multiple products and future ventures
  • Work across marketplace, lifestyle, hospitality, technology, and future gaming sectors
  • Help build products that impact businesses, communities, and consumers
  • Create long-term value while helping scale a growing technology ecosystem

If you are the type of person who naturally questions how systems can be broken, enjoys solving complex technical challenges, and wants to help build secure products that make a real-world impact, we would love to hear from you.

Bring the mindset of a hacker, the discipline of an engineer, and the vision of an architect-and help us build the future with HolistiQ Technologies.

Pay: £54,940.34-£120,782.31 per year

About the company

HolistiQ Technologies is building a portfolio of innovative digital products across marketplace, lifestyle, hospitality, technology, and future gaming sectors.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

6:36 min

Funding open source through GitHub Accelerator and Sponsors

Stormy Peters · World Congress 2023

2:04 min

Creating and configuring the unit test project

Roman Alexis Anastasini · World Congress 2021

2:49 min

Adopting OAuth best practices and removing outdated grants

Alexander Schwartz Alexander Schwartz · World Congress 2026 Europe

2:40 min

Using GitHub primitives for internal documentation and corporate operations

Kyle Daigle · Coffee With Developers

4:37 min

Writing readable test assertions without boilerplate test classes

Florian Bruhin · World Congress 2021

Videos

See all

Related articles

See all