Bristol, Avon, South West, United Kingdom Hybrid / WFH Options
Hargreaves Lansdown
The Head of Application and Product Security is a strategic leadership role responsible for safeguarding the application landscape and digital products within HL. This pivotal position ensures that security is embedded throughout the software development lifecycle and product innovation pipeline, providing assurance to clients, regulators, and stakeholders during a period of significant digital transformation and on … an ongoing basis. The role will champion secure-by-default/design principles, drive security best practices, and lead a high-performing team in the context of ambitious cloud adoption, agile delivery, and regulatory evolution. The role balances strategic vision with operational oversight, ensuring security resilience and enabling the firm's growth aspirations. What you'll be doing … applicationsecurity architecture, reference models, and automation in line with cloud-first and hybrid environments (AWS, Azure, etc). Commission and manage securitytesting (SAST, DAST, pen testing, Interactive testing, Mobile testing, bug bounties), triage vulnerabilities, and drive remediation efforts with development teams. Report to executive leadership and the board on applicationMore ❯
Employment Type: Permanent, Part Time, Work From Home
Bristol, Gloucestershire, United Kingdom Hybrid / WFH Options
Hargreaves Lansdown PLC
have most of the skills or experience we're looking for, please go ahead and apply. We'd love to hear from you!About the role# The Head of Application and Product Security is a strategic leadership role responsible for safeguarding the application landscape and digital products within HL. This pivotal position ensures that security is … assurance to clients, regulators, and stakeholders during a period of significant digital transformation and on an ongoing basis. The role will champion secure-by-default/design principles, drive security best practices, and lead a high-performing team in the context of ambitious cloud adoption, agile delivery, and regulatory evolution. The role balances strategic vision with operational oversight, ensuring … applicationsecurity architecture, reference models, and automation in line with cloud-first and hybrid environments (AWS, Azure, etc). Commission and manage securitytesting (SAST, DAST, pen testing, Interactive testing, Mobile testing, bug bounties), triage vulnerabilities, and drive remediation efforts with development teams. Report to executive leadership and the board on applicationMore ❯
Harmondsworth, West Drayton, Middlesex, England, United Kingdom Hybrid / WFH Options
Hays Specialist Recruitment Limited
team. Working closely with the Cyber team as well as the digital team to ensure cybersecurity is embedded across all digital platforms. Key skills & Responsibility Lead the integration of security into the software development lifecycle (SDLC) using DevSecOps principles. Define and implement release strategies with a strong emphasis on application security. Identify and remediate security vulnerabilities through … and automated tooling. Collaborate with cross-functional teams to establish secure coding standards and quality benchmarks. Provide expert consultancy and guidance to engineering teams, enabling them to meet strategic security goals. Drive adoption of security best practices across CI/CD pipelines and cloud-native environments. Accountabilities Provide technical cyber leadership across all development teams, focusing on application … or qualifications desirable. Deep technical expertise in security tools and methodologies, including: Static ApplicationSecurityTesting (SAST) DynamicApplicationSecurityTesting (DAST) Software Composition Analysis (SCA) Threat Modelling Demonstrated success in leading or advising teams on secure development practices. Senior-level experience with a solid understanding of cloud migration challenges and solutions. More ❯
and have most of the skills or experience we're looking for, please go ahead and apply. We'd love to hear from you! About the role As an ApplicationSecurity Engineer at HL, you will play a key role in strengthening the security of our products and services. Partnering with Engineering and other security functions … you'll embed and enhance security across the SDLC. You will help shape our security tooling strategy, drive automation to scale assurance across the business and provide expert guidance to engineers on vulnerabilities, threats and risk mitigation. This role is an opportunity to influence how HL builds secure products at pace, while supporting a culture of 'Secure by … prioritising work, and providing progress updates against plan. Supporting the Security Champions program at HL through developer enablement and training. About you Experience of SAST/SCA/DAST toolsets (e.g. Snyk, Gitlab Ultimate ApplicationSecurity, Rapid7). Experience of API scanning tools (e.g. Salt, 42Crunch). Strong understanding of vulnerability scoring frameworks such as CVSS and More ❯
and have most of the skills or experience we're looking for, please go ahead and apply. We'd love to hear from you! About the role As an ApplicationSecurity Engineer at HL, you will play a key role in strengthening the security of our products and services. Partnering with Engineering and other security functions … you'll embed and enhance security across the SDLC. You will help shape our security tooling strategy, drive automation to scale assurance across the business and provide expert guidance to engineers on vulnerabilities, threats and risk mitigation. This role is an opportunity to influence how HL builds secure products at pace, while supporting a culture of 'Secure by … prioritising work, and providing progress updates against plan. Supporting the Security Champions program at HL through developer enablement and training. About you Experience of SAST/SCA/DAST toolsets (e.g. Snyk, Gitlab Ultimate ApplicationSecurity, Rapid7). Experience of API scanning tools (e.g. Salt, 42Crunch). Strong understanding of vulnerability scoring frameworks such as CVSS and More ❯
Bristol, Avon, South West, United Kingdom Hybrid / WFH Options
Hargreaves Lansdown
and have most of the skills or experience we're looking for, please go ahead and apply. We'd love to hear from you! About the role As an ApplicationSecurity Engineer at HL, you will play a key role in strengthening the security of our products and services. Partnering with Engineering and other security functions … you'll embed and enhance security across the SDLC. You will help shape our security tooling strategy, drive automation to scale assurance across the business and provide expert guidance to engineers on vulnerabilities, threats and risk mitigation. This role is an opportunity to influence how HL builds secure products at pace, while supporting a culture of 'Secure by … prioritising work, and providing progress updates against plan. Supporting the Security Champions program at HL through developer enablement and training. About you Experience of SAST/SCA/DAST toolsets (e.g. Snyk, Gitlab Ultimate ApplicationSecurity, Rapid7). Experience of API scanning tools (e.g. Salt, 42Crunch). Strong understanding of vulnerability scoring frameworks such as CVSS and More ❯
Employment Type: Permanent, Part Time, Work From Home
Bradley Stoke, Gloucestershire, United Kingdom Hybrid / WFH Options
Hargreaves Lansdown
and have most of the skills or experience we're looking for, please go ahead and apply. We'd love to hear from you! About the role As an ApplicationSecurity Engineer at HL, you will play a key role in strengthening the security of our products and services. Partnering with Engineering and other security functions … you'll embed and enhance security across the SDLC. You will help shape our security tooling strategy, drive automation to scale assurance across the business and provide expert guidance to engineers on vulnerabilities, threats and risk mitigation. This role is an opportunity to influence how HL builds secure products at pace, while supporting a culture of 'Secure by … prioritising work, and providing progress updates against plan. Supporting the Security Champions program at HL through developer enablement and training. About you Experience of SAST/SCA/DAST toolsets (e.g. Snyk, Gitlab Ultimate ApplicationSecurity, Rapid7). Experience of API scanning tools (e.g. Salt, 42Crunch). Strong understanding of vulnerability scoring frameworks such as CVSS and More ❯
bath, south west england, united kingdom Hybrid / WFH Options
Hargreaves Lansdown
and have most of the skills or experience we're looking for, please go ahead and apply. We'd love to hear from you! About the role As an ApplicationSecurity Engineer at HL, you will play a key role in strengthening the security of our products and services. Partnering with Engineering and other security functions … you'll embed and enhance security across the SDLC. You will help shape our security tooling strategy, drive automation to scale assurance across the business and provide expert guidance to engineers on vulnerabilities, threats and risk mitigation. This role is an opportunity to influence how HL builds secure products at pace, while supporting a culture of 'Secure by … prioritising work, and providing progress updates against plan. Supporting the Security Champions program at HL through developer enablement and training. About you Experience of SAST/SCA/DAST toolsets (e.g. Snyk, Gitlab Ultimate ApplicationSecurity, Rapid7). Experience of API scanning tools (e.g. Salt, 42Crunch). Strong understanding of vulnerability scoring frameworks such as CVSS and More ❯
Central London, London, United Kingdom Hybrid / WFH Options
Halian Technology Limited
modelling exercises, and continually improve the organisations applicationsecurity posture. Key Responsibilities Secure Development Lifecycle (SDLC) Experience working with static and dynamic code analysis tools (SAST, DAST) is essentialwhile you dont need to have set them up, you should have collaborated with developers to ensure code is scanned and critical vulnerabilities are blocked in the pipeline. Integrate … security controls into CI/CD pipelines and development workflows. Manage and monitor SAST, DAST, and SCA tools to detect vulnerabilities early in the lifecycle. Conduct secure code reviews and support remediation efforts. Threat Modelling & Architecture Review Requirements (Primarily Essential) 2+ years of experience in applicationsecurity or secure software development. Strong knowledge of OWASP Top … secure coding principles, and threat modelling. Hands-on experience with SAST, DAST, SCA, and vulnerability management tools. Familiarity with cloud platforms (Azure or AWS), CI/CD pipelines, and DevOps processes. Strong communication skills and the ability to collaborate effectively across teams. Understanding of regulatory and security standards (ISO 27001, FCA, NIST). (Nice to have) Youll need to More ❯
Manchester, Lancashire, United Kingdom Hybrid / WFH Options
Moonpig
About the role We're looking for a Product Security Engineer to help us build secure-by-design products that customers can trust. This is a key role in our Technology team where you'll work across the business to protect data, reduce risk, and enable safe innovation. From engineering security tooling to empowering teams with best practices … cloud provider (AWS, Azure or GCP) Familiar with Infrastructure as Code (e.g. Terraform, CloudFormation) Confident working with microservices, APIs and secure coding principles Hands-on experience with SAST/DAST tools in CI/CD environments Awareness of security tooling such as WAFs and vulnerability scanners Solid understanding of cryptography, authentication and authorisation A great communicator with a collaborative … Environment Languages: Python, Go or similar Infrastructure: AWS, Azure, GCP Tools: Terraform, CloudFormation, WAFs, vulnerability scanners DevOps: CI/CD pipelines, IaC, security automation Security focus: SAST, DAST, secure coding, threat modelling How We Get There We build with security in mind from day one We balance safety and speed with pragmatic decision-making We foster a More ❯
Central London, London, United Kingdom Hybrid / WFH Options
Halian Technology Limited
A leading fintech company is seeking a Lead AppSec Engineer to join their established team. Youll be instrumental in embedding security into every stage of the software development lifecycleguiding engineers, shaping best practices, and driving secure, scalable solutions across our platform. Key Responsibilities: Security Advisory : Serve as the go-to expert for applicationsecurity across engineering … teamsproviding hands-on guidance, resolving concerns, and fostering a security-first mindset. DevSecOps Enablement : Promote and implement secure development practices across CI/CD pipelines, secrets and key management, dependency management … and secure design. Vulnerability Management : Lead vulnerability remediation effortstriaging findings, prioritizing risks, and partnering with teams to deliver effective, pragmatic fixes. Tooling & Automation : Integrate security tools (e.g., SAST, DAST, SCA, secrets scanning) into developer workflows, ensuring automation is both scalable and developer-friendly. Cloud Security Collaboration : Work alongside infrastructure teams to ensure secure configuration of AWS and Azure More ❯
Leeds, West Yorkshire, United Kingdom Hybrid / WFH Options
FPSG
Security Engineer (Salesforce) Permanent Hybrid - 3 days p/w on-site Leeds area (Hands on recent career experience of Salesforce/Salesforce Industries/Vlocity is essential) FPSG have a fantastic opportunity to join a large-scale digital transformation programme aimed at uniting multiple internal business units under a new, secure, cloud-native digital platform. Ideal for a … subnets, zones) Experience with API security and integration-related platforms such as Auth0 or API Gateways Proficiency with security tools including SAST (e.g. Snyk, Checkmarx), SCA, and DAST (e.g. OpenZAP, Qualys DAST) Ability to manage secure operations of large-scale software estates, including deployment pipelines, rollback strategies, and uptime monitoring Practical experience building automated security test suites … Developer, Information Security Specialist, Salesforce, Salesforce Industries, Vlocity, Azure, OWASP CI/CD, DSOMM, SAMM, Cloud Security Posture Management, Prisma Cloud, Azure Defender, Snyk, Checkmarx, OpenZAP, Qualys, DAST, SAST, CI/CD, Infrastructure Security, Auth0, Secure APIs, Networking Protocols, DevSecOps, Secure Development, CRM Security Next Steps Please click "Apply now" and submit your up-to-date More ❯
North London, London, United Kingdom Hybrid / WFH Options
VERTECH GROUP (UK) LTD
/2 days in London Salary: Circa 65K 75K + Benefits Cybersecurity Engineer required by fast-growing, revolutionary tech company! This is a challenging, hands-on role leading the security of their applications, APIs, infrastructure, and data. Youll identify vulnerabilities, define best practices, and implement controls without slowing delivery Essential: At least 3yrs in cybersecurity, applicationsecurity, or cloud security … roles Strong knowledge of web/mobile security (OWASP Top 10, API security), cloud security (AWS), and CI/CD pipeline hardening Familiar with SAST/DAST tools, vulnerability scanners, penetration testing frameworks, and monitoring platforms (e.g. Splunk, ELK, Datadog) Understanding of GDPR and data privacy best practices Tremendous opportunity offering plenty of scope for career More ❯
/2 days in London Salary: Circa 65K – 75K + Benefits Cybersecurity Engineer required by fast-growing, revolutionary tech company! This is a challenging, hands-on role leading the security of their applications, APIs, infrastructure, and data. You’ll identify vulnerabilities, define best practices, and implement controls without slowing delivery Essential: At least 3yrs in cybersecurity, applicationsecurity, or cloud security … roles Strong knowledge of web/mobile security (OWASP Top 10, API security), cloud security (AWS), and CI/CD pipeline hardening Familiar with SAST/DAST tools, vulnerability scanners, penetration testing frameworks, and monitoring platforms (e.g. Splunk, ELK, Datadog) Understanding of GDPR and data privacy best practices Tremendous opportunity offering plenty of scope for career More ❯
AMS is a global workforce solutions partner committed to creating inclusive, dynamic, and future-ready workplaces. We help organisations adapt, grow, and thrive in an ever-evolving world by building, shaping, and optimising diverse talent strategies. Our Contingent Workforce Solutions (CWS) is one of our service offerings. Acting as an extension of their recruitment teams, we connect them with … Back End services. Contribute to the design, development, and scaling of chatbots and agent frameworks. Collaborate with product owners, designers, and other engineers to prioritise and deliver features. Ensure security, compliance, and confidentiality of sensitive financial data. The skills you'll need: Professional software engineering experience. Full stack … development expertise (React, TypeScript, Python). Experience with FastAPI or similar Back End frameworks. Familiarity with agent frameworks and AI/ML integration. Experience working with APIs (REST/DAST). Strong understanding of Agile/Scrum delivery. Next steps This client will only accept workers operating via an Umbrella or PAYE engagement model. If you are interested in applying More ❯