Head of Application & Product Security in Bristol
Head of Application & Product Security in Bristol

Head of Application & Product Security in Bristol

Bristol Full-Time 43200 - 72000 £ / year (est.) No home office possible
H

At a Glance

  • Tasks: Lead and innovate in application and product security for a top investment platform.
  • Company: Join Hargreaves Lansdown, the UK's number 1 investment platform based in Bristol.
  • Benefits: Enjoy flexible working, competitive salary, and a range of health and wellness perks.
  • Why this job: Make a real impact on digital transformation while championing security best practices.
  • Qualifications: Extensive experience in application security and leadership in regulated environments.
  • Other info: Dynamic workplace with continuous learning and excellent career growth opportunities.

The predicted salary is between 43200 - 72000 £ per year.

The Head of Application and Product Security is a strategic leadership role responsible for safeguarding the application landscape and digital products within HL. This pivotal position ensures that security is embedded throughout the software development lifecycle and product innovation pipeline, providing assurance to clients, regulators, and stakeholders during a period of significant digital transformation and on an ongoing basis.

The role will champion secure-by-default/design principles, drive security best practices, and lead a high-performing team in the context of ambitious cloud adoption, agile delivery, and regulatory evolution. The role balances strategic vision with operational oversight, ensuring security resilience and enabling the firm\’s growth aspirations.

What you\’ll be doing

  • Provide strategic leadership, direction and vision for all aspects of application and product security across the firm\’s digital portfolio, products and services.
  • Establish, communicate, and maintain security policies, standards, and practices for code, applications, APIs, customer platforms, and digital products.
  • Embed security by design, threat modelling, and secure coding practices across agile and DevOps teams, ensuring alignment with regulatory requirements (FCA, GDPR, etc).
  • Oversee the secure development lifecycle, from requirements and design to testing, deployment, and ongoing operation, ensuring risk mitigation at every stage.
  • Lead, mentor, and develop a team of application and product security professionals, fostering a culture of continuous improvement and innovation.
  • Advocate for security across the product lifecycle by aligning strong security practices with strategic goals and user experience, while engaging with diverse teams to understand and support their needs.
  • Collaborate with product management, digital, and engineering functions to enable secure innovation and accelerate digital transformation.
  • Develop and maintain application security architecture, reference models, and automation in line with cloud-first and hybrid environments (AWS, Azure, etc).
  • Commission and manage security testing (SAST, DAST, pen testing, Interactive testing, Mobile testing, bug bounties), triage vulnerabilities, and drive remediation efforts with development teams.
  • Report to executive leadership and the board on application security posture, risk, compliance status, and improvement initiatives.
  • Champion employee awareness and secure coding education, both within technology teams and across the wider business.
  • Engage with external partners, vendors, and industry groups to benchmark best practice and represent the firm\’s interests.
  • Lead the offensive security function looking after penetration testing, red /purple team exercises and bug bounty programme.

About you

  • Extensive leadership experience in application and/or product security, ideally within the wealth management, financial services or fintech sectors.
  • Track record of building and leading security teams in complex, regulated, and digitally transforming environments.
  • Expertise in secure software development lifecycle (SSDLC) and experience embedding security into agile, DevOps, and CI/CD environments.
  • In-depth technical knowledge of application security architecture, cloud platforms (AWS, Azure, GCP), microservices, APIs, and identity/access management.
  • Strong familiarity with modern programming languages, frameworks, and security vulnerabilities (e.g., OWASP Top Ten, SANS 25).
  • Proven experience driving digital transformation initiatives, including migration of legacy applications to cloud-native platforms and adoption of SaaS/PaaS solutions.
  • Understanding of UK financial regulations, GDPR, and industry standards (ISO 27001, NIST, PCI DSS, etc).
  • Experience running risk assessments, threat modelling, and security testing programmes.
  • Ability to engage and influence senior stakeholders, balancing security with commercial and operational priorities.
  • Strong communication, coaching, and stakeholder management skills. Able to translate complex security concepts for both technical and non-technical audiences
  • Demonstrable commitment to ongoing professional development and keeping pace with the evolving security landscape.

Qualifications

  • Relevant degree in computer science, information security, or a related field (or equivalent professional experience).
  • Professional certifications such as CISSP, CSSLP, CASP+, CASE, CASS, CISM, CCSP, or SABSA preferred. Also, any OffSec certification would be advantageous.
  • Additional certifications in cloud security (CCSK, AWS/Azure Security Specialty) and agile/DevOps environments beneficial.

Interview process

3 stage interview process – CISO meet | Technical Interview | Leadership/ Culture.

Working Schedule

Based out of our Bristol office. This role is permanent, full time, 37.5 hours per week, Monday to Friday. Subject to location we could consider remote working with a trip to the office once a month.

Why us?

Here at HL, we\’re the UK\’s number 1 investment platform for private investors, based in Bristol. For more than 40 years we\’ve helped investors save time, tax and money on their investments.

To achieve our mission, we believe we have a workplace like no other, with constant learning, dynamic teams, and a great ethos. We\’re steered by core values that promote service, quality, innovation, and opportunity in everything we do.

What\’s on offer?

  • Discretionary annual bonus* and annual pay review
  • 25 days* holiday plus bank holidays and 1-day additional Christmas closure
  • Option to purchase an additional 5 days holiday**
  • Flexible working options available, including hybrid working
  • Enhanced parental leave
  • Pension scheme up to 11% employer contribution
  • Income Protection and Life insurance (4 x salary core level of cover)
  • Private medical insurance*
  • Health care cash plans – including optical, dental, and out patientcare
  • Health screening programme
  • Help@hand – confidential support including mental health counselling and remote GP
  • Wellhub – unlimited access to fitness providers and wellness coach sessions
  • Variety of travel to work schemes with bike storage and shower facilities
  • Inhouse barista and deli serving subsidised coffee and sandwiches
  • Two paid volunteering days per year

* dependant on role level

** only available to select during our annual benefits window, in November each year

Hargreaves Lansdown is an inclusive employer that values diversity in its workforce. We encourage applications from all individuals without regard to race, religion, gender, sexual orientation, national origin, disability or age.

This role may also be available on a flexible working or part time basis – please ask the Recruitment & Onboarding team for more information.

Please note, we are unable to provide employment sponsorship to candidates.

Head of Application & Product Security in Bristol employer: Hargreaves Lansdown

Hargreaves Lansdown is an exceptional employer, offering a dynamic work culture that prioritises continuous learning and innovation. Located in Bristol, the company provides extensive employee benefits, including flexible working options, generous holiday allowances, and a strong commitment to professional development, making it an ideal place for those seeking meaningful and rewarding careers in application and product security.
H

Contact Detail:

Hargreaves Lansdown Recruiting Team

StudySmarter Expert Advice 🤫

We think this is how you could land Head of Application & Product Security in Bristol

✨Tip Number 1

Network like a pro! Reach out to folks in your industry on LinkedIn or at local meetups. A friendly chat can lead to opportunities that aren’t even advertised yet.

✨Tip Number 2

Prepare for those interviews! Research the company and its culture, and be ready to discuss how your experience aligns with their goals. We want you to shine!

✨Tip Number 3

Showcase your skills! If you’ve got a portfolio or examples of your work, bring them along. It’s a great way to demonstrate your expertise in application and product security.

✨Tip Number 4

Don’t forget to apply through our website! It’s the best way to ensure your application gets seen by the right people. Plus, we love seeing candidates who are keen on joining us!

We think you need these skills to ace Head of Application & Product Security in Bristol

Leadership in Application Security
Secure Software Development Lifecycle (SSDLC)
Agile and DevOps Practices
Application Security Architecture
Cloud Platforms (AWS, Azure, GCP)
Microservices and APIs
Identity and Access Management
Risk Assessments and Threat Modelling
Security Testing (SAST, DAST, Pen Testing)
Stakeholder Engagement and Management
Communication Skills
Coaching and Mentoring
Understanding of UK Financial Regulations
Professional Certifications (CISSP, CSSLP, etc.)
Commitment to Professional Development

Some tips for your application 🫡

Tailor Your Application: Make sure to customise your CV and cover letter to highlight your experience in application and product security. Use keywords from the job description to show that you understand what we're looking for.

Showcase Your Leadership Skills: Since this is a strategic leadership role, don’t forget to emphasise your experience in leading teams and driving security initiatives. Share specific examples of how you've built high-performing teams in the past.

Demonstrate Technical Expertise: We want to see your technical know-how! Include details about your experience with secure software development lifecycles, cloud platforms, and any relevant certifications. This will help us gauge your fit for the role.

Apply Through Our Website: For the best chance of success, make sure to submit your application through our website. It’s the easiest way for us to keep track of your application and get back to you quickly!

How to prepare for a job interview at Hargreaves Lansdown

✨Know Your Stuff

Make sure you brush up on your knowledge of application security, especially in relation to the financial services sector. Familiarise yourself with key concepts like secure software development lifecycle (SSDLC) and cloud platforms like AWS and Azure. Being able to discuss these topics confidently will show that you're serious about the role.

✨Show Your Leadership Skills

As a Head of Application & Product Security, you'll need to demonstrate your leadership experience. Prepare examples of how you've built and led teams in complex environments. Think about times when you’ve championed security initiatives or mentored others, as this will highlight your ability to lead a high-performing team.

✨Align with Company Values

Research Hargreaves Lansdown's core values and think about how your personal values align with theirs. Be ready to discuss how you can contribute to their mission of service, quality, innovation, and opportunity. This will show that you’re not just a fit for the role, but also for the company culture.

✨Prepare for Technical Questions

Expect to face technical questions during the interview process. Brush up on your knowledge of security testing methods like SAST, DAST, and penetration testing. Be prepared to explain how you would implement security best practices in an agile environment, as this will demonstrate your practical understanding of the role.

Head of Application & Product Security in Bristol
Hargreaves Lansdown

Land your dream job quicker with Premium

You’re marked as a top applicant with our partner companies
Individual CV and cover letter feedback including tailoring to specific job roles
Be among the first applications for new jobs with our AI application
1:1 support and career advice from our career coaches
Go Premium

Money-back if you don't land a job in 6-months

H
Similar positions in other companies
UK’s top job board for Gen Z
discover-jobs-cta
Discover now
>