Here's an idea:
If you don't have an actual security background with financial applications, don't code a fucking exchange.
I know that's a bit mindblowing, but think about it mr "learn ruby/python/php/node/perl (hey a guy can dream that kids are still into perl) in 24 hrs. book" guy.