At a Glance
- Tasks: Lead application security and vulnerability management, ensuring security is integrated from the start.
- Company: Join Lloyds Banking Group, a leader in financial services with a commitment to diversity and inclusion.
- Benefits: Enjoy a competitive salary, generous pension, 30 days holiday, and flexible working options.
- Other info: Be part of a dynamic team focused on innovation and professional growth.
- Why this job: Make a real impact on security architecture while shaping the future of financial services.
- Qualifications: Deep experience in application security, vulnerability management, and strong communication skills.
We're looking for a technically deep and forward-thinking Senior Product Security Architect to join our Enterprise Security Architecture team. This is a role that combines application security engineering, vulnerability management and developer engagement into a unified product security capability. You will work alongside engineering, platform teams and product owners to ensure security is built in from the beginning, as well as own how we find, prioritise and drive the remediation of risk across the application estate and be security's primary voice inside engineering.
The Chief Security Office (CSO) is a vital part of delivering the Group's vision of putting customers at the heart of everything we do, helping Britain prosper and protecting the Group and customers from security threats. We define and communicate the Group's security strategy and provide critical enterprise security services that both protect the organisation and enable its digital transformation agenda. We are evolving rapidly by investing in our people, tools and practices to stay ahead of an increasingly complex threat landscape and a fast-paced technology estate. The security architecture function sits at the core of this to provide thought leadership and cross-cutting influence that keep the Group's security posture aligned to its ambitions.
What you'll be doing:
- Defining and being responsible for the target states for application security and vulnerability management and solving sophisticated architectural problems.
- Acting as a trusted security partner to engineering - proficient in their language and focused on unblocking rather than gatekeeping.
- Performing research and development in collaboration with other security teams to ensure the security architecture is staying ahead of challenges and the Group's technology transformation agenda.
- Describing and helping to lead the complexity of the Group's Enterprise Security Architecture and associated interlocks.
- Supporting strategic change within the Group, specifically security change where you'll take a leading architectural role in shaping and supervising initiatives.
- Staying ahead of emerging product security challenges - including AI-integrated application risk, software supply chain security and cloud-native attack surfaces.
- Representing the security architecture function with confidence in senior stakeholder forums.
- Producing your own artefacts and handling your own delivery dates; ensuring they integrate into the wider bank reference architecture and Group Security Architecture.
What we're looking for:
- Deep hands-on experience with application security capabilities and tooling and the ability to integrate them within modern CICD pipelines.
- Solid understanding of secure software development practices across the full SDLC, including agile and DevSecOps delivery models.
- Experience owning or significantly contributing to a vulnerability management programme at scale - including prioritisation methodology, metrics design and executive reporting.
- Proven ability to build trusted relationships with engineering and product teams - you are someone that engineering and developers want in the room, not someone they feel audited by.
- Experience with cloud-native application architectures - containers, microservices, serverless - and the security considerations specific to these environments.
- Familiarity with AI-integrated application risk - understanding the security implications of LLM integration, RAG architectures and AI-assisted development tooling.
- Strong written and verbal communication skills - able to translate technical risk into business language and vice versa.
We know that great talent comes from many backgrounds. Whilst this job advert may reference specific years of experience, we recognise that skills are developed in many ways, so if you have relevant, transferable experience, we encourage you to apply.
This is a place for you. Our ambition is to be the leading UK business for diversity, equity and inclusion supporting our customers, colleagues and communities, and we're committed to creating an environment in which everyone can thrive, learn and develop.
Benefits:
- A generous pension contribution of up to 15%.
- An annual performance-related bonus.
- Share schemes including free shares.
- Benefits you can adapt to your lifestyle, such as discounted shopping.
- 30 days' holiday, with bank holidays on top.
- A range of wellbeing initiatives and generous parental leave policies.
Ready to do the best work of your career? Apply today.
Senior Product Security Architect in Wellington employer: Lloyds Bank plc
Lloyds Banking Group is an exceptional employer, offering a dynamic work environment in Cardiff that fosters professional growth and collaboration. With a competitive salary package, generous benefits including a robust pension scheme and flexible working options, employees are empowered to thrive both personally and professionally. The company prioritises inclusivity and well-being, ensuring that all team members can achieve their full potential while making a meaningful impact in the SME banking sector.
StudySmarter Expert Advice🤫
We think this is how you could land Senior Product Security Architect in Wellington
✨Get Involved in the Cybersecurity Community
Diving into the cybersecurity community is key for landing that full-time gig. Join forums like Reddit's r/cybersecurity or attend local meetups to connect with industry veterans and other job seekers. Networking is everything in this field—don’t just be a passive lurker!
✨Show Off Your Skills with Capture the Flag Competitions
Participate in Capture the Flag (CTF) competitions; these are not just a fun way to boost your skills but also a chance to showcase your talent to potential employers. Many companies, including Lloyds Bank plc, love seeing candidates who actively engage in these challenges.
✨Tailor Your Online Presence
Make sure your LinkedIn and any professional profiles reflect your cybersecurity expertise. Share your projects, whether they’re personal or from a previous role, to catch the eye of hiring managers. This is how they’ll find your passion and commitment to the field!
✨Apply Directly Through Lloyds Bank plc
Don’t forget to head straight to our website and check out any openings for cybersecurity roles at Lloyds Bank plc. Applying directly can sometimes give you an edge, especially if you can mention that you've been following our work or engaging in the community.
We think you need these skills to ace Senior Product Security Architect in Wellington
Some tips for your application 🫡
Show off your technical skills:In cybersecurity, it's crucial to highlight your technical prowess. Make sure your CV showcases specific skills like network security, penetration testing, or threat analysis. If you have relevant certifications (like CEH or CISSP), pop those on the front page to grab attention!
Tailor your portfolio for the role:Even for a full-time role, a portfolio can set you apart. If you've worked on any cybersecurity projects—be it CTF challenges, security assessments, or research papers—include these in your application. This demonstrates not just your skills, but also your hands-on experience!
Use real-world examples:When writing your cover letter, don’t just stick to your qualifications. Share real-world examples of how you’ve tackled security issues or vulnerabilities. This gives the hiring team at Lloyds Bank plc insight into your practical problem-solving abilities and makes your application memorable.
Demonstrate your passion for cybersecurity:Cybersecurity is an ever-evolving field, so show us that you’re always learning! Mention any recent courses, webinars, or industry events you’ve attended. This not only exhibits your enthusiasm but also signals to Lloyds Bank plc that you’re committed to staying ahead in the game.
How to prepare for a job interview at Lloyds Bank plc
✨Sharpen Your Technical Skills
For a role in cybersecurity, it’s essential to be up-to-date with the latest tools and techniques. Brush up on your knowledge of firewalls, intrusion detection systems, and vulnerability assessment tools. Be ready to discuss specific scenarios where you’ve applied these skills, as hands-on experience can really set us apart in interviews.
✨Prepare for Scenario-Based Questions
Expect the interviewers at Lloyds Bank plc to throw in some hypothetical situations to see how you’d handle them. Think about common security breaches or incidents and be prepared to explain how you would respond. This not only shows your problem-solving skills but also your understanding of real-world cybersecurity challenges.
✨Highlight Your Certifications
Certifications like CompTIA Security+, CISSP, or CEH can give you a significant edge in a full-time role in cybersecurity. Make sure to mention these during your interview and be prepared to discuss what you learned through those certifications and how they relate to the position at Lloyds Bank plc.
✨Show Your Passion for Cybersecurity
Since you’re going for a full-time gig, showing genuine enthusiasm for the field can make all the difference. Share any personal projects, blogs, or communities you’re part of that relate to cybersecurity. This not only showcases your passion but also your commitment to staying engaged in this ever-evolving field.