Bristol, Avon, South West, United Kingdom Hybrid / WFH Options
Hargreaves Lansdown
The Head of Application and Product Security is a strategic leadership role responsible for safeguarding the application landscape and digital products within HL. This pivotal position ensures that security is embedded throughout the software development lifecycle and product innovation pipeline, providing assurance to clients, regulators, and stakeholders during a period of significant digital transformation and on … an ongoing basis. The role will champion secure-by-default/design principles, drive security best practices, and lead a high-performing team in the context of ambitious cloud adoption, agile delivery, and regulatory evolution. The role balances strategic vision with operational oversight, ensuring security resilience and enabling the firm's growth aspirations. What you'll be doing … applicationsecurity architecture, reference models, and automation in line with cloud-first and hybrid environments (AWS, Azure, etc). Commission and manage securitytesting (SAST, DAST, pen testing, Interactive testing, Mobile testing, bug bounties), triage vulnerabilities, and drive remediation efforts with development teams. Report to executive leadership and the board on applicationMore ❯
Employment Type: Permanent, Part Time, Work From Home
Bristol, Gloucestershire, United Kingdom Hybrid / WFH Options
Hargreaves Lansdown PLC
have most of the skills or experience we're looking for, please go ahead and apply. We'd love to hear from you!About the role# The Head of Application and Product Security is a strategic leadership role responsible for safeguarding the application landscape and digital products within HL. This pivotal position ensures that security is … assurance to clients, regulators, and stakeholders during a period of significant digital transformation and on an ongoing basis. The role will champion secure-by-default/design principles, drive security best practices, and lead a high-performing team in the context of ambitious cloud adoption, agile delivery, and regulatory evolution. The role balances strategic vision with operational oversight, ensuring … applicationsecurity architecture, reference models, and automation in line with cloud-first and hybrid environments (AWS, Azure, etc). Commission and manage securitytesting (SAST, DAST, pen testing, Interactive testing, Mobile testing, bug bounties), triage vulnerabilities, and drive remediation efforts with development teams. Report to executive leadership and the board on applicationMore ❯
and have most of the skills or experience we're looking for, please go ahead and apply. We'd love to hear from you! About the role As an ApplicationSecurity Engineer at HL, you will play a key role in strengthening the security of our products and services. Partnering with Engineering and other security functions … you'll embed and enhance security across the SDLC. You will help shape our security tooling strategy, drive automation to scale assurance across the business and provide expert guidance to engineers on vulnerabilities, threats and risk mitigation. This role is an opportunity to influence how HL builds secure products at pace, while supporting a culture of 'Secure by … prioritising work, and providing progress updates against plan. Supporting the Security Champions program at HL through developer enablement and training. About you Experience of SAST/SCA/DAST toolsets (e.g. Snyk, Gitlab Ultimate ApplicationSecurity, Rapid7). Experience of API scanning tools (e.g. Salt, 42Crunch). Strong understanding of vulnerability scoring frameworks such as CVSS and More ❯
and have most of the skills or experience we're looking for, please go ahead and apply. We'd love to hear from you! About the role As an ApplicationSecurity Engineer at HL, you will play a key role in strengthening the security of our products and services. Partnering with Engineering and other security functions … you'll embed and enhance security across the SDLC. You will help shape our security tooling strategy, drive automation to scale assurance across the business and provide expert guidance to engineers on vulnerabilities, threats and risk mitigation. This role is an opportunity to influence how HL builds secure products at pace, while supporting a culture of 'Secure by … prioritising work, and providing progress updates against plan. Supporting the Security Champions program at HL through developer enablement and training. About you Experience of SAST/SCA/DAST toolsets (e.g. Snyk, Gitlab Ultimate ApplicationSecurity, Rapid7). Experience of API scanning tools (e.g. Salt, 42Crunch). Strong understanding of vulnerability scoring frameworks such as CVSS and More ❯
Bristol, Avon, South West, United Kingdom Hybrid / WFH Options
Hargreaves Lansdown
and have most of the skills or experience we're looking for, please go ahead and apply. We'd love to hear from you! About the role As an ApplicationSecurity Engineer at HL, you will play a key role in strengthening the security of our products and services. Partnering with Engineering and other security functions … you'll embed and enhance security across the SDLC. You will help shape our security tooling strategy, drive automation to scale assurance across the business and provide expert guidance to engineers on vulnerabilities, threats and risk mitigation. This role is an opportunity to influence how HL builds secure products at pace, while supporting a culture of 'Secure by … prioritising work, and providing progress updates against plan. Supporting the Security Champions program at HL through developer enablement and training. About you Experience of SAST/SCA/DAST toolsets (e.g. Snyk, Gitlab Ultimate ApplicationSecurity, Rapid7). Experience of API scanning tools (e.g. Salt, 42Crunch). Strong understanding of vulnerability scoring frameworks such as CVSS and More ❯
Employment Type: Permanent, Part Time, Work From Home
Bradley Stoke, Gloucestershire, United Kingdom Hybrid / WFH Options
Hargreaves Lansdown
and have most of the skills or experience we're looking for, please go ahead and apply. We'd love to hear from you! About the role As an ApplicationSecurity Engineer at HL, you will play a key role in strengthening the security of our products and services. Partnering with Engineering and other security functions … you'll embed and enhance security across the SDLC. You will help shape our security tooling strategy, drive automation to scale assurance across the business and provide expert guidance to engineers on vulnerabilities, threats and risk mitigation. This role is an opportunity to influence how HL builds secure products at pace, while supporting a culture of 'Secure by … prioritising work, and providing progress updates against plan. Supporting the Security Champions program at HL through developer enablement and training. About you Experience of SAST/SCA/DAST toolsets (e.g. Snyk, Gitlab Ultimate ApplicationSecurity, Rapid7). Experience of API scanning tools (e.g. Salt, 42Crunch). Strong understanding of vulnerability scoring frameworks such as CVSS and More ❯
bath, south west england, united kingdom Hybrid / WFH Options
Hargreaves Lansdown
and have most of the skills or experience we're looking for, please go ahead and apply. We'd love to hear from you! About the role As an ApplicationSecurity Engineer at HL, you will play a key role in strengthening the security of our products and services. Partnering with Engineering and other security functions … you'll embed and enhance security across the SDLC. You will help shape our security tooling strategy, drive automation to scale assurance across the business and provide expert guidance to engineers on vulnerabilities, threats and risk mitigation. This role is an opportunity to influence how HL builds secure products at pace, while supporting a culture of 'Secure by … prioritising work, and providing progress updates against plan. Supporting the Security Champions program at HL through developer enablement and training. About you Experience of SAST/SCA/DAST toolsets (e.g. Snyk, Gitlab Ultimate ApplicationSecurity, Rapid7). Experience of API scanning tools (e.g. Salt, 42Crunch). Strong understanding of vulnerability scoring frameworks such as CVSS and More ❯