Head of Product Security – CISO function - BPL

Head of Product Security – CISO function - BPL

Full-Time 80000 - 100000 £ / year (est.) No working from home possible
United States Digital Space LLC

At a Glance

  • Tasks: Lead product security to ensure everything we build is secure by design.
  • Company: Join a forward-thinking company focused on innovative security solutions.
  • Benefits: Competitive salary, flexible working, and opportunities for professional growth.
  • Other info: Dynamic role with excellent career advancement opportunities in a supportive environment.
  • Why this job: Make a real impact in securing cutting-edge products while collaborating with engineering teams.
  • Qualifications: Experience in application security and a strong understanding of developer needs.

The predicted salary is between 80000 - 100000 £ per year.

The Head of Product Security leads the pillar responsible for ensuring everything the company builds and ships is secure by design. This is the most agile-facing pillar in the CISO function — it must embed into product squads without becoming a bottleneck, own the shift-left programme, manage the developer security toolchain, and provide assurance that releases meet the organisation’s security and compliance requirements. The role requires a blend of technical depth, developer empathy, and pragmatic risk management. The ideal candidate is someone who understands application security at a hands-on level, has run a security champions programme in an agile engineering organisation, and knows how to make security a service that engineering teams want to use rather than a gate they try to avoid. You will work more closely with engineering leadership than with regulators — this is a builder’s role, not an auditor’s role.

Key Responsibilities

  • Own and drive the shift-left security programme, ensuring security is integrated into the earliest stages of the software development lifecycle through threat modelling, secure design patterns, and automated tooling.
  • Manage the security champions programme, recruiting, training, and supporting champions across all product squads.
  • Own the developer security toolchain (SAST, DAST, SCA, secrets scanning) and ensure it is integrated into all CI/CD pipelines with minimal developer friction and calibrated thresholds to avoid noise.
  • Establish and operate the vulnerability management lifecycle, including scanning orchestration, triage, prioritisation, SLA assignment, remediation tracking, and exception management.
  • Chair the weekly Vulnerability Review Board, making prioritisation decisions on critical and high-severity findings in collaboration with engineering leads.
  • Define and publish the security engagement model for product and engineering teams, including trigger points (new service, new integration, pre-release), SLAs, and escalation paths.
  • Oversee threat modelling for new services and major changes, ensuring threat models are completed before development progresses beyond initial design.
  • Own the security sign-off process for production releases, providing risk-based release decisions (approved, approved with conditions, deferred, escalated) rather than binary pass/fail gates.
  • Provide self-service security capabilities to product teams: threat model templates, security stories backlog, secure coding guides, and accessible tooling documentation.
  • Produce security assurance reporting for the CISO, including vulnerability trends, SDLC integration metrics, champion programme health, and developer satisfaction with security.
  • Collaborate with Security Architecture and Engineering on the “paved road” of secure defaults, patterns, and base images that product teams build upon.
  • Manage and develop the Product Security team, balancing deep technical capability with developer relations skills.

Key Deliverables

  • Security champions programme with training curriculum, monthly meetup cadence, and recognition framework.
  • Developer security toolchain fully operational and integrated into 100% of CI/CD pipelines.
  • Vulnerability management dashboard with SLA tracking, ageing analysis, and trend reporting.
  • Product security engagement model document (trigger points, SLAs, outputs, escalation paths).
  • Security release certification process with standardised decision framework.
  • Monthly product security report for CISO (vulnerability trends, tooling adoption, champion coverage, developer satisfaction).
  • Threat model register with completion tracking and findings remediation status.
  • Secure coding standards documentation for all primary programming languages.
  • Developer security training curriculum and workshop materials.

Required Skills and Experience

  • CSSLP, OSCP or similar certifications.
  • Experience with PCI Software Security Framework (SSF) and its application to payment processing software.
  • Previous career as a software engineer or developer before moving into security — you understand the developer experience from the inside.
  • Experience with bug bounty programme management.
  • Payments acquiring, FinTech, E-Pay - application security experience.
  • Contributions to open-source security tools, OWASP projects, or published security research.
  • Experience with security tooling for Kubernetes-native applications.
  • Several years of progressive experience in application security or product security, with a number of years in a leadership role managing a product security or AppSec team.
  • Deep understanding of modern application security: OWASP Top 10, API security (REST, gRPC, GraphQL), microservices security, container security, and secure coding practices.
  • Proven experience building and running a security champions programme in an agile engineering organisation.
  • Hands‑on experience with SAST, DAST, SCA, and secrets scanning tools and their integration into CI/CD pipelines (Jenkins, GitLab CI, GitHub Actions, or equivalent).
  • Experience managing a vulnerability management programme with defined SLAs, exception processes, and stakeholder reporting across multiple engineering teams.
  • Strong developer empathy — demonstrable ability to work with engineering teams as a partner, not an adversary.
  • Ideally you have a software development background yourself.
  • Experience operating a security function within agile or DevOps delivery models, including sprint‑aligned engagement and security backlog management.
  • Understanding of PCI DSS software security requirements and their practical application in a cloud‑native, microservices environment.
  • Experience with threat modelling frameworks (STRIDE, PASTA, attack trees) and their application to modern architectures.
  • Strong communication skills for influencing engineering leadership, presenting to executives, and writing clear guidance for developers.

Head of Product Security – CISO function - BPL employer: United States Digital Space LLC

As the Head of Product Security at BPL, you will join a forward-thinking organisation that prioritises security by design within an agile environment. Our collaborative work culture fosters innovation and empowers employees through continuous learning and development opportunities, ensuring that you can grow your skills while making a meaningful impact on product security. Located in a vibrant area, we offer unique advantages such as flexible working arrangements and a strong emphasis on work-life balance, making BPL an excellent employer for those seeking a rewarding career in cybersecurity.

United States Digital Space LLC

Contact Details:

United States Digital Space LLC Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Head of Product Security – CISO function - BPL

Get Involved in the Cybersecurity Community

Diving into the cybersecurity community is key for landing that full-time gig. Join forums like Reddit's r/cybersecurity or attend local meetups to connect with industry veterans and other job seekers. Networking is everything in this field—don’t just be a passive lurker!

Show Off Your Skills with Capture the Flag Competitions

Participate in Capture the Flag (CTF) competitions; these are not just a fun way to boost your skills but also a chance to showcase your talent to potential employers. Many companies, including United States Digital Space LLC, love seeing candidates who actively engage in these challenges.

Tailor Your Online Presence

Make sure your LinkedIn and any professional profiles reflect your cybersecurity expertise. Share your projects, whether they’re personal or from a previous role, to catch the eye of hiring managers. This is how they’ll find your passion and commitment to the field!

Apply Directly Through United States Digital Space LLC

Don’t forget to head straight to our website and check out any openings for cybersecurity roles at United States Digital Space LLC. Applying directly can sometimes give you an edge, especially if you can mention that you've been following our work or engaging in the community.

We think you need these skills to ace Head of Product Security – CISO function - BPL

CSSLP
OSCP
PCI Software Security Framework (SSF)
Application Security
Bug Bounty Programme Management
OWASP Top 10
API Security (REST, gRPC, GraphQL)

Some tips for your application 🫡

Show off your technical skills:In cybersecurity, it's crucial to highlight your technical prowess. Make sure your CV showcases specific skills like network security, penetration testing, or threat analysis. If you have relevant certifications (like CEH or CISSP), pop those on the front page to grab attention!

Tailor your portfolio for the role:Even for a full-time role, a portfolio can set you apart. If you've worked on any cybersecurity projects—be it CTF challenges, security assessments, or research papers—include these in your application. This demonstrates not just your skills, but also your hands-on experience!

Use real-world examples:When writing your cover letter, don’t just stick to your qualifications. Share real-world examples of how you’ve tackled security issues or vulnerabilities. This gives the hiring team at United States Digital Space LLC insight into your practical problem-solving abilities and makes your application memorable.

Demonstrate your passion for cybersecurity:Cybersecurity is an ever-evolving field, so show us that you’re always learning! Mention any recent courses, webinars, or industry events you’ve attended. This not only exhibits your enthusiasm but also signals to United States Digital Space LLC that you’re committed to staying ahead in the game.

How to prepare for a job interview at United States Digital Space LLC

Sharpen Your Technical Skills

For a role in cybersecurity, it’s essential to be up-to-date with the latest tools and techniques. Brush up on your knowledge of firewalls, intrusion detection systems, and vulnerability assessment tools. Be ready to discuss specific scenarios where you’ve applied these skills, as hands-on experience can really set us apart in interviews.

Prepare for Scenario-Based Questions

Expect the interviewers at United States Digital Space LLC to throw in some hypothetical situations to see how you’d handle them. Think about common security breaches or incidents and be prepared to explain how you would respond. This not only shows your problem-solving skills but also your understanding of real-world cybersecurity challenges.

Highlight Your Certifications

Certifications like CompTIA Security+, CISSP, or CEH can give you a significant edge in a full-time role in cybersecurity. Make sure to mention these during your interview and be prepared to discuss what you learned through those certifications and how they relate to the position at United States Digital Space LLC.

Show Your Passion for Cybersecurity

Since you’re going for a full-time gig, showing genuine enthusiasm for the field can make all the difference. Share any personal projects, blogs, or communities you’re part of that relate to cybersecurity. This not only showcases your passion but also your commitment to staying engaged in this ever-evolving field.