Head of Application Security

Head of Application Security

Full-Time 63000 - 77000 £ / year (est.) Working from home possible
Harvey Nash

At a Glance

  • Tasks: Lead and evolve product security while driving DevSecOps strategy across the SDLC.
  • Company: High-growth cybersecurity product business with a strong technical DNA.
  • Benefits: Remote-first work with expenses covered for one day in London each month.
  • Other info: Opportunity to grow a high-calibre team and explore AI-driven security tooling.
  • Why this job: Own product security and influence key technical decisions in a dynamic environment.
  • Qualifications: Proven leadership in DevSecOps/AppSec and hands-on experience with security tools.

The predicted salary is between 63000 - 77000 £ per year.

Head of Dev Sec Ops / Security Engineering (1 day/month London - Expenses Covered)

We’re working with a high-growth cybersecurity product business looking to hire a Head of Dev Sec Ops to own and evolve their product security function.

This is a hands-on leadership role with real ownership, setting strategy whilst still being close enough to the detail to influence key technical decisions.

The role

  • Own product security posture end-to-end
  • Define and drive Dev Sec Ops strategy across the SDLC
  • Lead threat modelling, pen testing, and vulnerability management
  • Embed security into engineering teams and delivery pipelines
  • Own supply chain security and SBOM reporting
  • Lead and grow a small, high-calibre team
  • Act as a key voice in incident response and risk management
  • Explore and scale AI-driven / agentic security tooling

What they’re looking for

  • Proven leadership in Dev Sec Ops / App Sec
  • Strong hands-on experience with SAST, DAST, SCA in CI/CD
  • Deep understanding of modern product security
  • Experience balancing security with delivery in a product environment
  • Strong stakeholder skills across engineering and exec level

Nice to have

  • Cloud security (AWS / Azure / GCP)
  • Experience securing AI / ML or agent-based systems
  • Exposure to OWASP, NIST, ISO or similar
  • Security-first product business with strong technical DNA
  • Backed for growth and scaling
  • Remote-first with just 1 day per month in London (expenses covered)
  • #J-18808-Ljbffr

Head of Application Security employer: Harvey Nash

Join a leading organisation that values continuous improvement and offers a collaborative work culture, where you will be part of a dedicated team enhancing a complex Dynamics 365 CE and Power Platform environment. With opportunities for professional growth and exposure to enterprise-scale solutions, this role is perfect for those looking to expand their consulting capabilities while working closely with experienced professionals in Birmingham and remotely. Enjoy the flexibility of remote work combined with the chance to make meaningful contributions to a large user base.

Harvey Nash

Contact Details:

Harvey Nash Recruitment Team

We think you need these skills to ace Head of Application Security

DevSecOps
Application Security
Threat Modelling
Penetration Testing
Vulnerability Management
Security in CI/CD
Supply Chain Security