At a Glance
- Tasks: Safeguard products by leading security initiatives and collaborating with product teams.
- Company: Join the UK's number 1 investment platform, HL, based in vibrant Bristol.
- Benefits: Enjoy flexible working, generous holiday, and a range of health and wellness perks.
- Why this job: Make a real impact on product security while working with cutting-edge technologies.
- Qualifications: Experience in security roles, especially with cloud platforms like AWS, is essential.
- Other info: Dynamic team culture focused on continuous learning and innovation.
The predicted salary is between 36000 - 60000 £ per year.
As a Product Security Specialist (PSS) at HL, you will be a key member of a collaborative team of security professionals dedicated to safeguarding HL's products and services. In this role, you will serve as the primary security contact for assigned product teams/squads, providing expert guidance on security issues and requirements. You will champion secure development practices throughout the software development lifecycle, with a strong emphasis on 'shift-left' principles to embed security early in the process. You will facilitate threat modelling workshops to help product teams identify, assess, and mitigate potential threats. You will also collaborate closely with other functions within the CISO organisation, including Application Security, Offensive Security, and others to continuously improve HL's overall security posture.
This position offers the opportunity to work with modern technologies and influence the security of innovative products, while fostering a culture of security awareness and resilience across the organisation.
What you will be doing:
- Oversee security related issues across multiple product teams/squads.
- Be the single point of contact for security related matters ranging from daily significant change to complex Cloud serverless transformation projects.
- Work with infrastructure as code and understand complex architectures.
- Lead/facilitate threat modelling workshops with SMEs.
- Engage with key stakeholders to identify threats and recommend countermeasures.
- Participate in architectural reviews of Product cloud implementations against security best practice, relevant threats, and acceptable risks.
- Support in the creation and implementation of architecture blueprints and proof of concepts on Cloud platforms supporting best practice, secure by design.
About you:
- Demonstrable experience in a Security related role.
- A proven track record of working with one or more of the main cloud vendor platforms, specifically AWS.
- Certifications such as AWS Solutions/ Security Engineer, Azure Solutions/ Security Engineer are preferred.
- Excellent communication skills, including communicating complex technical concepts to non-technical stakeholders.
- Technical background across multiple security domains and familiarity with cloud security standards.
- Experience within an Agile ways of working and DevSecOps context.
- Problem solving skills - with the ability to use own experience to develop pragmatic solutions and resolve complex issues.
- Certifications such as CISSP, CEH, OSCP, or GSEC are preferred.
- Knowledge of security principles, practices, and frameworks, such as OWASP, NIST, and ISO.
- Awareness of security tools and technologies, such as SAST, DAST, IAST, SCA, WAF, IDS, IPS.
- Experience in conducting threat modelling and risk assessments.
Interview process: The interview process for this role is two stages including a technical competency-based question and a task.
Working Schedule: This role is based in Bristol head office, BS1 5HL. This role is permanent, full time, 37.5 hours per week, Monday to Friday. We have returned to the office, however for this role we offer a hybrid flexible working pattern.
Why us? Here at HL, we're the UK's number 1 investment platform for private investors, based in Bristol. For more than 40 years we've helped investors save time, tax and money on their investments. To achieve our mission, we believe we have a workplace like no other, with constant learning, dynamic teams, and a great ethos. We're steered by core values that promote service, quality, innovation, and opportunity in everything we do.
What's on offer?
- Discretionary annual bonus and annual pay review.
- 25 days holiday plus bank holidays and 1-day additional Christmas closure.
- Option to purchase an additional 5 days holiday.
- Flexible working options available, including hybrid working.
- Enhanced parental leave.
- Pension scheme up to 11% employer contribution.
- Income Protection and Life insurance (4 x salary core level of cover).
- Private medical insurance.
- Health care cash plans - including optical, dental, and outpatient care.
- Health screening programme.
- Help@hand - confidential support including mental health counselling and remote GP.
- Wellhub - unlimited access to fitness providers and wellness coach sessions.
- Variety of travel to work schemes with bike storage and shower facilities.
- Inhouse barista and deli serving subsidised coffee and sandwiches.
- Two paid volunteering days per year.
Hargreaves Lansdown is an inclusive employer that values diversity in its workforce. We encourage applications from all individuals without regard to race, religion, gender, sexual orientation, national origin, disability or age. This role may also be available on a flexible working or part time basis - please ask the Recruitment & Onboarding team for more information. Please note, we are unable to provide employment sponsorship to candidates.
Product Security Specialist in Newport employer: Hargreaves Lansdown
Contact Detail:
Hargreaves Lansdown Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Product Security Specialist in Newport
✨Tip Number 1
Network like a pro! Reach out to current employees at HL on LinkedIn or through mutual connections. A friendly chat can give you insider info and might just get your foot in the door.
✨Tip Number 2
Prepare for those technical questions! Brush up on your cloud security knowledge and be ready to discuss your experience with AWS or Azure. We want to see how you tackle real-world security challenges.
✨Tip Number 3
Show off your problem-solving skills! During interviews, share specific examples of how you've identified threats and implemented solutions. We love hearing about your hands-on experience!
✨Tip Number 4
Don’t forget to apply through our website! It’s the best way to ensure your application gets seen by the right people. Plus, it shows you’re genuinely interested in joining our team.
We think you need these skills to ace Product Security Specialist in Newport
Some tips for your application 🫡
Tailor Your Application: Make sure to customise your CV and cover letter for the Product Security Specialist role. Highlight your relevant experience with cloud security and any certifications you have that align with the job description.
Showcase Your Communication Skills: Since you'll be communicating complex security concepts to non-technical stakeholders, it's crucial to demonstrate your communication skills in your application. Use clear and concise language to convey your ideas.
Highlight Your Problem-Solving Abilities: We love candidates who can think on their feet! Share examples of how you've tackled complex security issues in the past, especially in an Agile or DevSecOps context. This will show us you're ready for the challenges ahead.
Apply Through Our Website: Don't forget to submit your application through our website! It’s the best way for us to receive your details and ensures you’re considered for the role. We can't wait to see what you bring to the table!
How to prepare for a job interview at Hargreaves Lansdown
✨Know Your Security Stuff
Make sure you brush up on your knowledge of security principles, practices, and frameworks like OWASP and NIST. Be ready to discuss how you've applied these in past roles, especially in cloud environments like AWS.
✨Show Off Your Communication Skills
Since you'll be communicating complex technical concepts to non-technical stakeholders, practice explaining your past projects in simple terms. Use examples that highlight your ability to bridge the gap between tech and business.
✨Prepare for Technical Questions
Expect competency-based questions that dive into your experience with threat modelling and risk assessments. Think of specific scenarios where you identified threats and implemented countermeasures, and be ready to share those stories.
✨Familiarise Yourself with Agile and DevSecOps
Since this role involves working within Agile teams, be prepared to discuss your experience in Agile methodologies and how you've integrated security into the development lifecycle. Highlight any relevant certifications or training you've completed.