
Application Security Engineer
Hargreaves Lansdown plc11 days ago
Remote, WorldwideSenior
Responsibilities
- Design, build, and maintain automated application security checks, guardrails, and policy-as-code controls in developer workflows.
- Develop automation and API-based integrations connecting security tooling with CI/CD, source-code management, and internal platforms.
- Implement, operate, optimize, and measure security tooling across engineering platforms.
- Embed secure development practices and security testing into delivery pipelines, shared templates, and engineering standards.
- Create dashboards and metrics demonstrating the effectiveness and impact of security tools.
- Evaluate new security tools for integration, scalability, and developer experience.
- Support application security strategy, tooling, and technology decisions.
- Partner with Engineering and the CISO function to improve security processes and support Secure by Design practices.
- Support the Security Champions program through developer enablement and training.
- Prioritize work, meet deadlines, provide progress updates, and improve workflows based on feedback.
Requirements
- Strong experience integrating security tooling into CI/CD pipelines and engineering platforms.
- Ability to develop automation and API integrations using at least one programming or scripting language, such as Python or JavaScript.
- Broad knowledge of software development languages, frameworks, source-code tools, and build/deploy platforms such as GitHub, GitLab CI/CD, Harness, and Jenkins.
- Hands-on experience with application security tooling including SAST, DAST, SCA, vulnerability aggregation, and ASPM platforms.
- Hands-on experience with AWS or Azure, including containerized workloads such as Docker or lightweight services such as Lambda and ECS.
- Practical understanding of vulnerability scoring frameworks including CVSS and EPSS.
- Strong understanding of common security vulnerabilities and emerging threats.
- Ability to communicate security risk and help engineering teams understand and remediate vulnerabilities.
- Experience working in Agile environments with strong organizational skills and attention to detail.
- Awareness of or experience with developer-focused Security Champion programs.
Benefits
- Permanent, full-time role working 37.5 hours per week, Monday to Friday.
- Hybrid working with two days per week in the Bristol office; flexible and part-time options may be available.
- Discretionary annual bonus and annual pay review.
- 25 days of holiday plus bank holidays and one additional Christmas closure day, with the option to purchase five additional days subject to the stated benefits-window restriction.
- Enhanced parental leave and pension contributions of up to 11% from the employer.
- Income protection, life insurance with four times salary core cover, private medical insurance, health care cash plans, and a health screening programme.
- Help@hand confidential support, including mental health counselling and remote GP access.
- Wellhub fitness and wellness access, travel-to-work schemes, bike storage, shower facilities, an in-house barista and deli, and two paid volunteering days per year.