Security Architect in Bristol

Security Architect in Bristol

Bristol Full-Time 60750 - 74250 £ / year (est.) Home office (partial)
Hargreaves Lansdown Asset Management

At a Glance

  • Tasks: Lead security architecture for innovative applications and cloud-native services.
  • Company: Join Hargreaves Lansdown, the UK's top investment platform with a vibrant culture.
  • Benefits: Enjoy flexible working, competitive salary, and comprehensive health benefits.
  • Other info: Dynamic teams, continuous learning, and excellent career growth opportunities await you.
  • Why this job: Make a real impact on security in a fast-paced, transformative environment.
  • Qualifications: Experience in security architecture and application security is essential.

The predicted salary is between 60750 - 74250 £ per year.

Excited to grow your career?

Our purpose is to make it easy for people to save and invest for a better future.

We are looking for great people to join us, so please come and invest in YOUR future at Hargreaves Lansdown.

We know that sometimes people can be put off applying for a job if they don't tick every box.

If you're excited about working for us and have most of the skills or experience we're looking for, please go ahead and apply.

We’d love to hear from you!

About the role

This is a hands-on security architecture role with significant influence across engineering, architecture, cyber security, risk and product teams.

You’ll own application security architecture across a complex estate that includes new cloud-native services, mobile applications, REST and Graph QL APIs, AI-enabled features and a substantial legacy environment that remains live during transformation.

You’ll create the patterns, standards and guardrails that make the secure path the easy one for engineering teams.

You’ll also lead the design reviews that matter most, guide pragmatic risk decisions, and help ensure our digital services meet the expectations of clients, regulators and the business.

  • What you’ll be doing
  • Architecture and design
  • Own application security architecture across web, mobile, API and cloud-native services, and maintain the reference architectures and patterns engineering teams build against.
  • Design the patterns that carry the most weight i. e. authentication and authorisation, token architecture and service-to-service identity, secrets management, cryptography and secure data handling.
  • Define API security patterns for both REST and Graph QL, covering authorisation at object and field level, schema exposure, query cost and depth controls, rate limiting and gateway placement, recognising that Graph QL breaks many of the path-based controls that work for REST.
  • Set pragmatic security positions for legacy applications, including compensating controls, safe integration with newer services and how security debt is prioritised against the migration roadmap rather than deferred indefinitely.
  • Lead security design reviews for significant applications, integrations and client journeys, and take recommendations to the design authority / architecture review board as a technical advisor.
  • AI security
  • Define the security architecture for AI-enabled features built on Amazon Bedrock, covering model access controls, guardrails, prompt and output handling, data residency and cross-region inference, and logging that meets our regulatory retention needs.
  • Establish how agentic applications are secured: tool and action permissions, non-human identity and credential scoping, MCP and similar integration layers, human-in-the-loop checkpoints, and containment when an agent behaves unexpectedly.
  • Assure third-party and Saa S-embedded AI and set the guardrails for AI-assisted developer tooling used inside our own delivery pipelines.
  • Threat modelling and risk
  • Lead threat modelling for applications, APIs and AI features using STRIDE and OWASP methods, supported by appropriate HL TM tooling, driving the resulting mitigations to closure.
  • Assess the security implications of new products, technologies and third-party integrations, and translate emerging attack trends into changes to our patterns and controls.
  • Provide technical leadership on security exceptions and risk decisions, including the judgement about when a risk is acceptable.
  • Secure engineering
  • Define the security controls and assurance gates in our CI/CD pipelines, covering SAST, DAST, SCA, secrets scanning and container image assurance and how findings reach the teams who fix them.
  • Partner with engineering to build secure-by-default capabilities that teams adopt because they are useful, not because they are mandated.
  • Strengthen software supply chain controls across dependencies, build provenance and artefact integrity.
  • Work alongside So C, penetration testing and vulnerability management teams so that findings feed back into architecture rather than staying at the individual finding level.
  • Governance and regulation
  • Maintain the application security standards and architectural guardrails and keep them current as the platform changes.
  • Ensure designs meet FCA expectations, operational resilience requirements and Consumer Duty considerations for digital client journeys, working with Risk and Compliance where interpretation is needed.
  • What success looks like
  • Engineering teams are building against published patterns for authentication, authorisation, API security and secrets rather than solving those problems individually.
  • Threat modelling runs as a routine part of design for significant changes, not as an escalation.
  • We have a clear, agreed position on how AI and agentic features are secured and assured, and it is being applied.

About you

  • Substantial experience in security architecture with application security as your centre of gravity, at senior level or ready to step up to it.
  • You have designed secure architectures for cloud-native applications on AWS, and you understand containers and Kubernetes well enough to reason about the security model rather than only the tooling.
  • Real depth in identity and access: OAuth 2.0, Open ID Connect and SAML in practice, authorisation models beyond role checks, and service-to-service authentication.

FIDO2 and passwordless experience is a strong plus.

  • Practical API security experience across REST and Graph QL, including authorisation design and the failure modes each brings.
  • You have worked in a mixed estate and can secure legacy applications proportionately, without either ignoring them or blocking delivery over problems that will disappear at migration.
  • You have run complex threat modelling and design reviews as a regular discipline and can point to what changed as a result.
  • You have embedded security into Agile and CI/CD delivery in a way that engineers accepted.
  • You can influence without authority.

Getting a pattern adopted when nobody must adopt it, and saying no in a way that keeps delivery on your side, matters more here than formal sign-off rights.

  • You are comfortable in a fast-moving transformation where the target architecture is still being decided.

Desirable

Experience in financial services or another regulated sector; mobile application security; software supply chain and secure SDLC; hands-on experience with Amazon Bedrock or comparable managed model platforms; familiarity with the OWASP Top 10 for LLM and Agentic Applications; working knowledge of OWASP ASVS, Top 10 and API Security Top 10.

Azure exposure is useful, although our estate is AWS-first.

Certifications

CISSP, CCSP or AWS Security Specialty would be valuable, or equivalent demonstrable experience.

Other relevant certifications such as CSSLP, SABSA, SANS GCSA or Microsoft Cybersecurity Architect Expert are welcome but not essential.

Interview process

This will be a 2-stage interview process, consisting of an intro call, competency and behavioural based interview with technical assessment.

Working Schedule

We are based in Bristol, BS1 5HL. This role is permanent, full time, 37.5 hours per week, Monday to Friday. We have returned to the office 2 days a week.

Why us?

Here at HL, we’re the UK’s number 1 investment platform for private investors, based in Bristol.

For more than 40 years we’ve helped investors save time, tax and money on their investments.

To achieve our mission, we believe we have a workplace like no other, with constant learning, dynamic teams, and a great ethos.

We're steered by core values that promote service, quality, innovation, and opportunity in everything we do.

What's on offer?

  • Discretionary annual bonus* and annual pay review
  • 25 days* holiday plus bank holidays and 1-day additional Christmas closure
  • Option to purchase an additional 5 days holiday**
  • Flexible working options available, including hybrid working
  • Enhanced parental leave
  • Pension scheme up to 11% employer contribution
  • Income Protection and Life insurance (4 x salary core level of cover)
  • Private medical insurance*
  • Health care cash plans - including optical, dental, and outpatient care
  • Health screening programme
  • Help@hand - confidential support including mental health counselling and remote GP
  • Wellhub - unlimited access to fitness providers and wellness coach sessions
  • Variety of travel to work schemes with bike storage and shower facilities
  • Inhouse barista and deli serving subsidised coffee and sandwiches
  • Two paid volunteering days per year
  • dependant on role level
  • ** only available to select during our annual benefits window, in November each year

Hargreaves Lansdown is an inclusive employer that values diversity in its workforce.

We encourage applications from all individuals without regard to race, religion, gender, sexual orientation, national origin, disability or age.

This role may also be available on a flexible working or part time basis – please ask the Recruitment & Onboarding team for more information.

Please note, we are unable to provide employment sponsorship to candidates.

Security Architect in Bristol employer: Hargreaves Lansdown Asset Management

Hargreaves Lansdown is an exceptional employer, offering a dynamic work culture that prioritises continuous learning and innovation. Located in the vibrant city of Bristol, employees benefit from flexible working options, a comprehensive benefits package including enhanced parental leave and private medical insurance, and a strong commitment to diversity and inclusion. With a focus on employee growth and a supportive environment, Hargreaves Lansdown empowers its team members to thrive while making a meaningful impact in the financial services sector.

Hargreaves Lansdown Asset Management

Contact Details:

Hargreaves Lansdown Asset Management Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Security Architect in Bristol

Get Involved in the Cybersecurity Community

Diving into the cybersecurity community is key for landing that full-time gig. Join forums like Reddit's r/cybersecurity or attend local meetups to connect with industry veterans and other job seekers. Networking is everything in this field—don’t just be a passive lurker!

Show Off Your Skills with Capture the Flag Competitions

Participate in Capture the Flag (CTF) competitions; these are not just a fun way to boost your skills but also a chance to showcase your talent to potential employers. Many companies, including Hargreaves Lansdown Asset Management, love seeing candidates who actively engage in these challenges.

Tailor Your Online Presence

Make sure your LinkedIn and any professional profiles reflect your cybersecurity expertise. Share your projects, whether they’re personal or from a previous role, to catch the eye of hiring managers. This is how they’ll find your passion and commitment to the field!

Apply Directly Through Hargreaves Lansdown Asset Management

Don’t forget to head straight to our website and check out any openings for cybersecurity roles at Hargreaves Lansdown Asset Management. Applying directly can sometimes give you an edge, especially if you can mention that you've been following our work or engaging in the community.

We think you need these skills to ace Security Architect in Bristol

Security Architecture
Application Security
Cloud-Native Applications
AWS
Containers
Kubernetes
Identity and Access Management

Some tips for your application 🫡

Show off your technical skills:In cybersecurity, it's crucial to highlight your technical prowess. Make sure your CV showcases specific skills like network security, penetration testing, or threat analysis. If you have relevant certifications (like CEH or CISSP), pop those on the front page to grab attention!

Tailor your portfolio for the role:Even for a full-time role, a portfolio can set you apart. If you've worked on any cybersecurity projects—be it CTF challenges, security assessments, or research papers—include these in your application. This demonstrates not just your skills, but also your hands-on experience!

Use real-world examples:When writing your cover letter, don’t just stick to your qualifications. Share real-world examples of how you’ve tackled security issues or vulnerabilities. This gives the hiring team at Hargreaves Lansdown Asset Management insight into your practical problem-solving abilities and makes your application memorable.

Demonstrate your passion for cybersecurity:Cybersecurity is an ever-evolving field, so show us that you’re always learning! Mention any recent courses, webinars, or industry events you’ve attended. This not only exhibits your enthusiasm but also signals to Hargreaves Lansdown Asset Management that you’re committed to staying ahead in the game.

How to prepare for a job interview at Hargreaves Lansdown Asset Management

Sharpen Your Technical Skills

For a role in cybersecurity, it’s essential to be up-to-date with the latest tools and techniques. Brush up on your knowledge of firewalls, intrusion detection systems, and vulnerability assessment tools. Be ready to discuss specific scenarios where you’ve applied these skills, as hands-on experience can really set us apart in interviews.

Prepare for Scenario-Based Questions

Expect the interviewers at Hargreaves Lansdown Asset Management to throw in some hypothetical situations to see how you’d handle them. Think about common security breaches or incidents and be prepared to explain how you would respond. This not only shows your problem-solving skills but also your understanding of real-world cybersecurity challenges.

Highlight Your Certifications

Certifications like CompTIA Security+, CISSP, or CEH can give you a significant edge in a full-time role in cybersecurity. Make sure to mention these during your interview and be prepared to discuss what you learned through those certifications and how they relate to the position at Hargreaves Lansdown Asset Management.

Show Your Passion for Cybersecurity

Since you’re going for a full-time gig, showing genuine enthusiasm for the field can make all the difference. Share any personal projects, blogs, or communities you’re part of that relate to cybersecurity. This not only showcases your passion but also your commitment to staying engaged in this ever-evolving field.