Bristol, Avon, South West, United Kingdom Hybrid / WFH Options
Hargreaves Lansdown
The Head of Application and Product Security is a strategic leadership role responsible for safeguarding the application landscape and digital products within HL. This pivotal position ensures that security is embedded throughout the software development lifecycle and product innovation pipeline, providing assurance to clients, regulators, and stakeholders during a period of significant digital transformation and on … an ongoing basis. The role will champion secure-by-default/design principles, drive security best practices, and lead a high-performing team in the context of ambitious cloud adoption, agile delivery, and regulatory evolution. The role balances strategic vision with operational oversight, ensuring security resilience and enabling the firm's growth aspirations. What you'll be doing … applicationsecurity architecture, reference models, and automation in line with cloud-first and hybrid environments (AWS, Azure, etc). Commission and manage securitytesting (SAST, DAST, pen testing, Interactive testing, Mobile testing, bug bounties), triage vulnerabilities, and drive remediation efforts with development teams. Report to executive leadership and the board on applicationMore ❯
Employment Type: Permanent, Part Time, Work From Home
source solutions, and embracing enterprise agile methodology. We encourage professional development to ensure you bring innovative ideas to our products while satisfying your own intellectual curiosity. Our Global Information Security team's mission is to ensure the development, implementation, and management of a comprehensive program that effectively protects the confidentiality, integrity, and availability of Point72 information assets. Our team … is comprised of security professionals with expertise in a diverse portfolio of security disciplines. What you'll do Collaborate with the DevOps team to design, implement, and manage a robust DevSecOps framework for our software development pipeline, integrating security tools and processes into our CI/CD workflows to enhance the developer experience Champion a security … testing tools and processes within the CI/CD pipeline, including static applicationsecuritytesting (SAST), dynamicapplicationsecuritytesting (DAST), software composition analysis (SCA), and open source security (OSS) Work together with the DevOps team to automate security controls and compliance checks within the development pipeline, ensuring adherence More ❯
Bristol, Gloucestershire, United Kingdom Hybrid / WFH Options
Hargreaves Lansdown PLC
have most of the skills or experience we're looking for, please go ahead and apply. We'd love to hear from you!About the role# The Head of Application and Product Security is a strategic leadership role responsible for safeguarding the application landscape and digital products within HL. This pivotal position ensures that security is … assurance to clients, regulators, and stakeholders during a period of significant digital transformation and on an ongoing basis. The role will champion secure-by-default/design principles, drive security best practices, and lead a high-performing team in the context of ambitious cloud adoption, agile delivery, and regulatory evolution. The role balances strategic vision with operational oversight, ensuring … applicationsecurity architecture, reference models, and automation in line with cloud-first and hybrid environments (AWS, Azure, etc). Commission and manage securitytesting (SAST, DAST, pen testing, Interactive testing, Mobile testing, bug bounties), triage vulnerabilities, and drive remediation efforts with development teams. Report to executive leadership and the board on applicationMore ❯
Harmondsworth, West Drayton, Middlesex, England, United Kingdom Hybrid / WFH Options
Hays Specialist Recruitment Limited
team. Working closely with the Cyber team as well as the digital team to ensure cybersecurity is embedded across all digital platforms. Key skills & Responsibility Lead the integration of security into the software development lifecycle (SDLC) using DevSecOps principles. Define and implement release strategies with a strong emphasis on application security. Identify and remediate security vulnerabilities through … and automated tooling. Collaborate with cross-functional teams to establish secure coding standards and quality benchmarks. Provide expert consultancy and guidance to engineering teams, enabling them to meet strategic security goals. Drive adoption of security best practices across CI/CD pipelines and cloud-native environments. Accountabilities Provide technical cyber leadership across all development teams, focusing on application … or qualifications desirable. Deep technical expertise in security tools and methodologies, including: Static ApplicationSecurityTesting (SAST) DynamicApplicationSecurityTesting (DAST) Software Composition Analysis (SCA) Threat Modelling Demonstrated success in leading or advising teams on secure development practices. Senior-level experience with a solid understanding of cloud migration challenges and solutions. More ❯
and have most of the skills or experience we're looking for, please go ahead and apply. We'd love to hear from you! About the role As an ApplicationSecurity Engineer at HL, you will play a key role in strengthening the security of our products and services. Partnering with Engineering and other security functions … you'll embed and enhance security across the SDLC. You will help shape our security tooling strategy, drive automation to scale assurance across the business and provide expert guidance to engineers on vulnerabilities, threats and risk mitigation. This role is an opportunity to influence how HL builds secure products at pace, while supporting a culture of 'Secure by … prioritising work, and providing progress updates against plan. Supporting the Security Champions program at HL through developer enablement and training. About you Experience of SAST/SCA/DAST toolsets (e.g. Snyk, Gitlab Ultimate ApplicationSecurity, Rapid7). Experience of API scanning tools (e.g. Salt, 42Crunch). Strong understanding of vulnerability scoring frameworks such as CVSS and More ❯
and have most of the skills or experience we're looking for, please go ahead and apply. We'd love to hear from you! About the role As an ApplicationSecurity Engineer at HL, you will play a key role in strengthening the security of our products and services. Partnering with Engineering and other security functions … you'll embed and enhance security across the SDLC. You will help shape our security tooling strategy, drive automation to scale assurance across the business and provide expert guidance to engineers on vulnerabilities, threats and risk mitigation. This role is an opportunity to influence how HL builds secure products at pace, while supporting a culture of 'Secure by … prioritising work, and providing progress updates against plan. Supporting the Security Champions program at HL through developer enablement and training. About you Experience of SAST/SCA/DAST toolsets (e.g. Snyk, Gitlab Ultimate ApplicationSecurity, Rapid7). Experience of API scanning tools (e.g. Salt, 42Crunch). Strong understanding of vulnerability scoring frameworks such as CVSS and More ❯
Bristol, Avon, South West, United Kingdom Hybrid / WFH Options
Hargreaves Lansdown
and have most of the skills or experience we're looking for, please go ahead and apply. We'd love to hear from you! About the role As an ApplicationSecurity Engineer at HL, you will play a key role in strengthening the security of our products and services. Partnering with Engineering and other security functions … you'll embed and enhance security across the SDLC. You will help shape our security tooling strategy, drive automation to scale assurance across the business and provide expert guidance to engineers on vulnerabilities, threats and risk mitigation. This role is an opportunity to influence how HL builds secure products at pace, while supporting a culture of 'Secure by … prioritising work, and providing progress updates against plan. Supporting the Security Champions program at HL through developer enablement and training. About you Experience of SAST/SCA/DAST toolsets (e.g. Snyk, Gitlab Ultimate ApplicationSecurity, Rapid7). Experience of API scanning tools (e.g. Salt, 42Crunch). Strong understanding of vulnerability scoring frameworks such as CVSS and More ❯
Employment Type: Permanent, Part Time, Work From Home
Bradley Stoke, Gloucestershire, United Kingdom Hybrid / WFH Options
Hargreaves Lansdown
and have most of the skills or experience we're looking for, please go ahead and apply. We'd love to hear from you! About the role As an ApplicationSecurity Engineer at HL, you will play a key role in strengthening the security of our products and services. Partnering with Engineering and other security functions … you'll embed and enhance security across the SDLC. You will help shape our security tooling strategy, drive automation to scale assurance across the business and provide expert guidance to engineers on vulnerabilities, threats and risk mitigation. This role is an opportunity to influence how HL builds secure products at pace, while supporting a culture of 'Secure by … prioritising work, and providing progress updates against plan. Supporting the Security Champions program at HL through developer enablement and training. About you Experience of SAST/SCA/DAST toolsets (e.g. Snyk, Gitlab Ultimate ApplicationSecurity, Rapid7). Experience of API scanning tools (e.g. Salt, 42Crunch). Strong understanding of vulnerability scoring frameworks such as CVSS and More ❯
bath, south west england, united kingdom Hybrid / WFH Options
Hargreaves Lansdown
and have most of the skills or experience we're looking for, please go ahead and apply. We'd love to hear from you! About the role As an ApplicationSecurity Engineer at HL, you will play a key role in strengthening the security of our products and services. Partnering with Engineering and other security functions … you'll embed and enhance security across the SDLC. You will help shape our security tooling strategy, drive automation to scale assurance across the business and provide expert guidance to engineers on vulnerabilities, threats and risk mitigation. This role is an opportunity to influence how HL builds secure products at pace, while supporting a culture of 'Secure by … prioritising work, and providing progress updates against plan. Supporting the Security Champions program at HL through developer enablement and training. About you Experience of SAST/SCA/DAST toolsets (e.g. Snyk, Gitlab Ultimate ApplicationSecurity, Rapid7). Experience of API scanning tools (e.g. Salt, 42Crunch). Strong understanding of vulnerability scoring frameworks such as CVSS and More ❯
Our client currently seek a SC Cleared AWS DevOps Engineer to join their dynamic team on an initial 6 month contract. This role is 95% remote with travel required once a month to the office. Key Skills … and Responsibilities: Design, deliver, and support secure and scalable AWS infrastructure using services like EC2, S3, ECS, and FARGATE Integrate SAST (Static ApplicationSecurityTesting) and DAST (DynamicApplicationSecurityTesting) tools into CI/CD pipelines to enforce secure development practices Automate infrastructure provisioning using CloudFormation, Terraform, or CDK Use tools like More ❯
Our client currently seek a SC Cleared AWS DevOps Engineer to join their dynamic team on an initial 6 month contract. This role is 95% remote with travel required once a month to the office. Key Skills … and Responsibilities: Design, deliver, and support secure and scalable AWS infrastructure using services like EC2, S3, ECS, and FARGATE Integrate SAST (Static ApplicationSecurityTesting) and DAST (DynamicApplicationSecurityTesting) tools into CI/CD pipelines to enforce secure development practices Automate infrastructure provisioning using CloudFormation, Terraform, or CDK Use tools like More ❯
Central London, London, United Kingdom Hybrid / WFH Options
Halian Technology Limited
modelling exercises, and continually improve the organisations applicationsecurity posture. Key Responsibilities Secure Development Lifecycle (SDLC) Experience working with static and dynamic code analysis tools (SAST, DAST) is essentialwhile you dont need to have set them up, you should have collaborated with developers to ensure code is scanned and critical vulnerabilities are blocked in the pipeline. Integrate … security controls into CI/CD pipelines and development workflows. Manage and monitor SAST, DAST, and SCA tools to detect vulnerabilities early in the lifecycle. Conduct secure code reviews and support remediation efforts. Threat Modelling & Architecture Review Requirements (Primarily Essential) 2+ years of experience in applicationsecurity or secure software development. Strong knowledge of OWASP Top … secure coding principles, and threat modelling. Hands-on experience with SAST, DAST, SCA, and vulnerability management tools. Familiarity with cloud platforms (Azure or AWS), CI/CD pipelines, and DevOps processes. Strong communication skills and the ability to collaborate effectively across teams. Understanding of regulatory and security standards (ISO 27001, FCA, NIST). (Nice to have) Youll need to More ❯
Manchester, Lancashire, United Kingdom Hybrid / WFH Options
Moonpig
About the role We're looking for a Product Security Engineer to help us build secure-by-design products that customers can trust. This is a key role in our Technology team where you'll work across the business to protect data, reduce risk, and enable safe innovation. From engineering security tooling to empowering teams with best practices … cloud provider (AWS, Azure or GCP) Familiar with Infrastructure as Code (e.g. Terraform, CloudFormation) Confident working with microservices, APIs and secure coding principles Hands-on experience with SAST/DAST tools in CI/CD environments Awareness of security tooling such as WAFs and vulnerability scanners Solid understanding of cryptography, authentication and authorisation A great communicator with a collaborative … Environment Languages: Python, Go or similar Infrastructure: AWS, Azure, GCP Tools: Terraform, CloudFormation, WAFs, vulnerability scanners DevOps: CI/CD pipelines, IaC, security automation Security focus: SAST, DAST, secure coding, threat modelling How We Get There We build with security in mind from day one We balance safety and speed with pragmatic decision-making We foster a More ❯
Central London, London, United Kingdom Hybrid / WFH Options
Halian Technology Limited
A leading fintech company is seeking a Lead AppSec Engineer to join their established team. Youll be instrumental in embedding security into every stage of the software development lifecycleguiding engineers, shaping best practices, and driving secure, scalable solutions across our platform. Key Responsibilities: Security Advisory : Serve as the go-to expert for applicationsecurity across engineering … teamsproviding hands-on guidance, resolving concerns, and fostering a security-first mindset. DevSecOps Enablement : Promote and implement secure development practices across CI/CD pipelines, secrets and key management, dependency management … and secure design. Vulnerability Management : Lead vulnerability remediation effortstriaging findings, prioritizing risks, and partnering with teams to deliver effective, pragmatic fixes. Tooling & Automation : Integrate security tools (e.g., SAST, DAST, SCA, secrets scanning) into developer workflows, ensuring automation is both scalable and developer-friendly. Cloud Security Collaboration : Work alongside infrastructure teams to ensure secure configuration of AWS and Azure More ❯
Leeds, West Yorkshire, United Kingdom Hybrid / WFH Options
FPSG
Security Engineer (Salesforce) Permanent Hybrid - 3 days p/w on-site Leeds area (Hands on recent career experience of Salesforce/Salesforce Industries/Vlocity is essential) FPSG have a fantastic opportunity to join a large-scale digital transformation programme aimed at uniting multiple internal business units under a new, secure, cloud-native digital platform. Ideal for a … subnets, zones) Experience with API security and integration-related platforms such as Auth0 or API Gateways Proficiency with security tools including SAST (e.g. Snyk, Checkmarx), SCA, and DAST (e.g. OpenZAP, Qualys DAST) Ability to manage secure operations of large-scale software estates, including deployment pipelines, rollback strategies, and uptime monitoring Practical experience building automated security test suites … Developer, Information Security Specialist, Salesforce, Salesforce Industries, Vlocity, Azure, OWASP CI/CD, DSOMM, SAMM, Cloud Security Posture Management, Prisma Cloud, Azure Defender, Snyk, Checkmarx, OpenZAP, Qualys, DAST, SAST, CI/CD, Infrastructure Security, Auth0, Secure APIs, Networking Protocols, DevSecOps, Secure Development, CRM Security Next Steps Please click "Apply now" and submit your up-to-date More ❯
Pre Sales Application Architect Salary: £70k basic + £6k car allowance + 15% bonus + 10% DV allowance (£83k - £93k total comp) Basingstoke: Hybrid circa 2/3 days a week on site Security Clearance: Needs SC Clearance to start and willingness to go through DV Clearance A global IT Consultancy are looking for a Pre Sales Application Architect to work on delivery opportunities taking place within their secure Defence and National Security sector. You will be responsible for the creation of design artefacts that enable the provision of Applications using industry standard methodologies. You will work closely with Solution Owners and Project Managers to ensure that solutions are in-line with approved designs and meet … Design/Configuration/Usage in a number of the following - CI/CD Pipelines, ideally Azure DevOps IaC code tooling, including Terraform, Ansible, Harbor SCA/IAST/DAST tooling, e.g. Black Duck, Coverity, Codesight, JFrog, Snyk Automated Test tooling, ideally Selenium/Robot Framework Test Management Tooling ideally Azure Test Plans Secure Secrets Management, ideally Azure DevOps and More ❯
North London, London, United Kingdom Hybrid / WFH Options
VERTECH GROUP (UK) LTD
/2 days in London Salary: Circa 65K 75K + Benefits Cybersecurity Engineer required by fast-growing, revolutionary tech company! This is a challenging, hands-on role leading the security of their applications, APIs, infrastructure, and data. Youll identify vulnerabilities, define best practices, and implement controls without slowing delivery Essential: At least 3yrs in cybersecurity, applicationsecurity, or cloud security … roles Strong knowledge of web/mobile security (OWASP Top 10, API security), cloud security (AWS), and CI/CD pipeline hardening Familiar with SAST/DAST tools, vulnerability scanners, penetration testing frameworks, and monitoring platforms (e.g. Splunk, ELK, Datadog) Understanding of GDPR and data privacy best practices Tremendous opportunity offering plenty of scope for career More ❯
/2 days in London Salary: Circa 65K – 75K + Benefits Cybersecurity Engineer required by fast-growing, revolutionary tech company! This is a challenging, hands-on role leading the security of their applications, APIs, infrastructure, and data. You’ll identify vulnerabilities, define best practices, and implement controls without slowing delivery Essential: At least 3yrs in cybersecurity, applicationsecurity, or cloud security … roles Strong knowledge of web/mobile security (OWASP Top 10, API security), cloud security (AWS), and CI/CD pipeline hardening Familiar with SAST/DAST tools, vulnerability scanners, penetration testing frameworks, and monitoring platforms (e.g. Splunk, ELK, Datadog) Understanding of GDPR and data privacy best practices Tremendous opportunity offering plenty of scope for career More ❯
Pre Sales Application Architect +Permanent opportunity +Hybrid 1 day on site in Bracknell/Basingstoke +SC cleared role + 70,000 - 90,000 You will be responsible for the creation of design artefacts that enable the provision of Applications using industry standard methodologies. You will work closely with Solution Owners and Project Managers to ensure that solutions are in … Capture techniques such as User Stories and Use Cases. AWS General/Usage Azure Cloud General/Usage VMWare General/Usage Technical Leadership & Design DevSecOps tooling and practices ApplicationSecurityTesting SAFe (scaled agile) Processes Data Integration Focused Data Pipeline Orchestration, and ELT tooling such as Apache Airflow, Apark, NiFi, Airbyte and Singer. Message Brokers, streaming … Design/Configuration/Usage in a number of the following - CI/CD Pipelines, ideally Azure DevOps IaC code tooling, including Terraform, Ansible, Harbor SCA/IAST/DAST tooling, e.g. Black Duck, Coverity, Codesight, JFrog, Snyk Automated Test tooling, ideally Selenium/Robot Framework Test Management Tooling ideally Azure Test Plans Secure Secrets Management, ideally Azure DevOps and More ❯
customers, partners, devices, services, infrastructure, and data. We work collaboratively, sharing insights and expertise to stay ahead of the curve. Join us, and you'll be part of a dynamic team that thrives on challenges and celebrates victories together. About the Role As a Senior Security Engineer on the Trust Cloud team, your role involves architecting, designing, and … implementing end-to-end security controls to impact the global user base. A key focus is on developing automated, scalable security solutions to enhance efficiency and protect Roku. This position requires expertise in creating and extending security automation tools, including detection and process automation. What you will be doing Cloud Designing and implementing scalable, automated security … controls in CI/CD pipelines using GitLab, Terraform, and policy-as-code approaches. Building and maintaining developer-friendly tools and workflows that integrate security checks (SAST, DAST, dependency scanning, container scanning) and secure secret management with Vault. Partnering with development, infrastructure, and platform teams to embed security into architecture, build processes, and deployment workflows as part More ❯
This is a huge opportunity for an experienced and driven Platform Security Engineer to join a rapidly growing fintech team! As a Platform Security Engineer, you will play a key role in protecting our clients systems, networks, and data while ensuring compliance with industry leading security standards such as ISO 27001. This role sits within the Platform … Engineering Team and requires a strong technical background, hands-on experience with security tools, and a collaborative mindset to work effectively across teams. What you'll do: Develop and implement proactive security strategies, policies, and procedures to protect our systems, networks, and data assets. Lead regular security assessments, including vulnerability scans and penetration tests, identifying risks and … technologies, including firewalls, intrusion detection/prevention systems (IDS/IPS), SIEM, antivirus solutions, encryption mechanisms, and vulnerability assessment tools. Hands-on experience in security tools (e.g., SAST, DAST, OWASP ZAP). Relevant security certifications, such as Security+, IAT II/III level, or equivalent. Strong capability in risk assessment, vulnerability management, and data informed decision -making. Solid More ❯
Lead the design and implementation of secure, scalable DevSecOps solutions across cloud, on-prem, and hybrid environments Advise customers on best practices for CI/CD, containerisation, and integrating security across the SDLC Collaborate with Sales and Consulting teams to develop technical proposals and bid responses Facilitate customer workshops, design reviews, and solution assurance activities Drive innovation and thought … Kanban, etc.) Deep expertise in Kubernetes (vanilla, EKS, AKS, OpenShift), CI/CD pipelines, and infrastructure as code (Terraform) Security integration experience across the DevSecOps lifecycle, including: SAST, DAST, SCA, and IAST tools (e.g., Checkmarx, Veracode, OWASP ZAP) Secrets management tools like HashiCorp Vault Vulnerability management solutions such as Prisma Cloud Testing frameworks like Selenium Familiarity with JIRA … are still areas of our business with clear hiring requirements - and we would like to bring talent like you on board! By the way, we have completely virtualised our application process and our recruiters remain available to you should you have any questions. We are still looking forward to getting to know you! About us Computacenter is a leading More ❯
Lead the design and implementation of secure, scalable DevSecOps solutions across cloud, on-prem, and hybrid environments Advise customers on best practices for CI/CD, containerisation, and integrating security across the SDLC Collaborate with Sales and Consulting teams to develop technical proposals and bid responses Facilitate customer workshops, design reviews, and solution assurance activities Drive innovation and thought … Kanban, etc.) Deep expertise in Kubernetes (vanilla, EKS, AKS, OpenShift), CI/CD pipelines, and infrastructure as code (Terraform) Security integration experience across the DevSecOps lifecycle, including: SAST, DAST, SCA, and IAST tools (e.g., Checkmarx, Veracode, OWASP ZAP) Secrets management tools like HashiCorp Vault Vulnerability management solutions such as Prisma Cloud Testing frameworks like Selenium Familiarity with JIRA … are still areas of our business with clear hiring requirements - and we would like to bring talent like you on board! By the way, we have completely virtualised our application process and our recruiters remain available to you should you have any questions. We are still looking forward to getting to know you! About us Computacenter is a leading More ❯
AMS is a global workforce solutions partner committed to creating inclusive, dynamic, and future-ready workplaces. We help organisations adapt, grow, and thrive in an ever-evolving world by building, shaping, and optimising diverse talent strategies. Our Contingent Workforce Solutions (CWS) is one of our service offerings. Acting as an extension of their recruitment teams, we connect them with … Back End services. Contribute to the design, development, and scaling of chatbots and agent frameworks. Collaborate with product owners, designers, and other engineers to prioritise and deliver features. Ensure security, compliance, and confidentiality of sensitive financial data. The skills you'll need: Professional software engineering experience. Full stack … development expertise (React, TypeScript, Python). Experience with FastAPI or similar Back End frameworks. Familiarity with agent frameworks and AI/ML integration. Experience working with APIs (REST/DAST). Strong understanding of Agile/Scrum delivery. Next steps This client will only accept workers operating via an Umbrella or PAYE engagement model. If you are interested in applying More ❯