Skip to main contentA logo with &quat;the muse&quat; in dark blue text.

Application Security Assurance Associate Director

2 days ago London, United Kingdom

Job Description

Are you ready to make an impact at DTCC?

Do you want to work on innovative projects, collaborate with a dynamic and supportive team, and receive investment in your professional development? At DTCC, we are at the forefront of innovation in the financial markets. We are committed to helping our employees grow and succeed. We believe that you have the skills and drive to make a real impact. We foster a thriving internal community and are committed to creating a workplace that looks like the world that we serve.

Pay and Benefits:

  • Competitive compensation, including base pay and annual incentive
  • Comprehensive health and life insurance and well-being benefits,
  • Pension
  • Paid Time Off and Personal/Family Care, and other leaves of absence when needed to support your physical, financial, and emotional well-being.
  • DTCC offers a flexible/hybrid model of 3 days onsite and 2 days remote (onsite Tuesdays, Wednesdays and a third day unique to each team or employee).


The Impact you will have in this role:

As a member of the CISO organization, this role provides strategic leadership for application security governance across DTCC's container platforms by unifying container security and vulnerability management into a cohesive, risk-driven control framework. The leader owns the design, delivery, and continuous improvement of platform-native AppSec controls-spanning build, deployment, and runtime-ensuring security is embedded through automation, policy-as-code, and standardized guardrails. By partnering closely with Cloud, Platform, and Application teams, this role enables secure scaling of containerized workloads while reducing material risk, improving vulnerability signal quality, and ensuring controls are audit-ready, measurable, and aligned to DTCC's regulatory and risk management expectations.

Want more jobs like this?

Get Software Engineering jobs in London, United Kingdom delivered to your inbox every week.

Job alert subscription


Your Primary Responsibilities:

  • Execute application security assessments at scale. Conduct application security assessments, risk analysis, vulnerability testing, and security reviews across DTCC businesses in alignment with established processes and DTCC Control Standards.
  • Identify, monitor, and escalate risk. Monitor application security risk, validate findings, track remediation, and escalate material issues in accordance with DTCC risk and escalation procedures.
  • Enable consistent security outcomes. Coordinate effectively with application development, infrastructure, database, and platform teams to ensure timely assessment, remediation, and risk mitigation.
  • Operate and optimize AppSec tooling. Manage and maintain the tools, servers, and supporting infrastructure used for application vulnerability testing and analysis, ensuring reliability, coverage, and effective use.
  • Strengthen secure development practices. Contribute to, maintain, and promote secure coding standards, guidelines, and best practices across engineering teams.
  • Continuously improve detection capabilities. Research emerging application and container security trends, tools, and techniques-including AI-enabled capabilities-and apply them pragmatically to improve detection, prioritization, and reporting.
  • Uphold strong risk and ethics discipline. Mitigate risk by following established procedures, monitoring controls, identifying control gaps or errors, and consistently demonstrating strong ethical judgment.


Qualifications:

  • Minimum of 8 years of related experience
  • Bachelor's degree preferred or equivalent experience
  • Relevant certification, for example CISM, CISSP, Burp Suite Certified Practitioner


Talents Needed for Success:

  • Container and cloud-native security expertise. Strong hands-on experience securing containers, Kubernetes, and cloud-native workloads across build, deploy, and runtime.
  • Modern AppSec execution. Practical experience with container scanning, SBOMs, image signing, runtime protection, and CI/CD security integration.
  • Automation mindset. Ability to apply automation and AI-enabled capabilities to reduce manual effort and improve prioritization and scale.
  • Delivery-focused leadership. Proven ability to lead small teams or pods, manage execution, and deliver measurable security outcomes.
  • Risk-based thinking. Comfortable prioritizing container and application risk in partnership with engineering teams.
  • Clear communicator. Able to explain technical risk and remediation expectations clearly to engineers and security leadership.
  • Continuous improvement orientation. Demonstrates curiosity, learning mindset, and willingness to evolve practices as platforms and threats change.


We are an equal opportunity employer and value diversity at our company. We do not discriminate on the basis of race, religion, color, national origin, sex, gender, gender expression, sexual orientation, age, marital status, veteran status, or disability status. We will ensure that individuals with disabilities are provided reasonable accommodation to participate in the job application or interview process, to perform essential job functions, and to receive other benefits and privileges of employment. Please contact us to request accommodation.

About Us

With over 50 years of experience, DTCC is the premier post-trade market infrastructure for the global financial services industry. From 20 locations around the world, DTCC, through its subsidiaries, automates, centralizes, and standardizes the processing of financial transactions, mitigating risk, increasing transparency, enhancing performance and driving efficiency for thousands of broker/dealers, custodian banks and asset managers. Industry owned and governed, the firm innovates purposefully, simplifying the complexities of clearing, settlement, asset servicing, transaction processing, trade reporting and data services across asset classes, bringing enhanced resilience and soundness to existing financial markets while advancing the digital asset ecosystem. In 2024, DTCC's subsidiaries processed securities transactions valued at U.S. $3.7 quadrillion and its depository subsidiary provided custody and asset servicing for securities issues from over 150 countries and territories valued at U.S. $99 trillion. DTCC's Global Trade Repository service, through locally registered, licensed, or approved trade repositories, processes more than 25 billion messages annually. To learn more, please visit us at www.dtcc.com or connect with us on LinkedIn , X , YouTube , Facebook and Instagram .

DTCC proudly supports Flexible Work Arrangements favoring openness and gives people freedom to do their jobs well, by encouraging diverse opinions and emphasizing teamwork. When you join our team, you'll have an opportunity to make meaningful contributions at a company that is recognized as a thought leader in both the financial services and technology industries. A DTCC career is more than a good way to earn a living. It's the chance to make a difference at a company that's truly one of a kind.

Learn more about Clearance and Settlement by clicking here .

About the Team

Serves as a dedicated technology resource for advancing DTCC's business opportunities and providing industry thought leadership for leveraging new technology. The goal of this new department is to partner internally with IT, our business and regulatory divisions and externally with clients, regulators, and fintech vendors, to help build new platforms and business models to advance DTCC's mission to support the financial markets.

Client-provided location(s): London, United Kingdom
Job ID: DTCC-213232
Employment Type: FULL_TIME
Posted: 2026-04-09T20:03:48

Perks and Benefits

  • Health and Wellness

    • Health Insurance
    • Dental Insurance
    • Vision Insurance
    • Life Insurance
    • Short-Term Disability
    • FSA
    • HSA With Employer Contribution
    • Long-Term Disability
    • HSA
    • Pet Insurance
    • Mental Health Benefits
  • Parental Benefits

    • On-site/Nearby Childcare
    • Adoption Assistance Program
    • Family Support Resources
    • Birth Parent or Maternity Leave
    • Non-Birth Parent or Paternity Leave
    • Return-to-Work Program
  • Work Flexibility

    • Hybrid Work Opportunities
    • Work-From-Home Stipend
  • Office Life and Perks

    • Casual Dress
    • Snacks
    • On-Site Cafeteria
    • Commuter Benefits Program
    • Company Outings
    • Holiday Events
  • Vacation and Time Off

    • Paid Vacation
    • Paid Holidays
    • Personal/Sick Days
    • Leave of Absence
    • Volunteer Time Off
  • Financial and Retirement

    • 401(K) With Company Matching
    • Performance Bonus
    • Financial Counseling
    • Pension
  • Professional Development

    • Work Visa Sponsorship
    • Leadership Training Program
    • Associate or Rotational Training Program
    • Tuition Reimbursement
    • Learning and Development Stipend
    • Promote From Within
    • Mentor Program
    • Shadowing Opportunities
    • Access to Online Courses
    • Lunch and Learns
    • Internship Program
    • Professional Coaching
  • Diversity and Inclusion

    • Diversity, Equity, and Inclusion Program
    • Employee Resource Groups (ERG)
    • Unconscious Bias Training