> Markdown version of [/jobs/ext/2277805-application-security-engineer](https://www.wearedevelopers.com/jobs/ext/2277805-application-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Application Security Engineer - **Company:** Hargreaves Lansdown - **Location:** Bristol, UK - **Contract:** Permanent contract - **Skills:** JavaScript (Programming Language), Agile Methodology, Amazon Web Services, Microsoft Azure, Continuous Integration, Github, Python (Programming Language), Systems Development Life Cycle, Security Software, Software Engineering, Scripting, Software Security, Gitlab-ci, Build Tools, Api Design, Software Version Control, Docker, Security Orchestration, Automation & Response, Jenkins, Static Application Security Testing, Dynamic Application Security Testing - **Published:** August 28, 2026 - **Apply:** https://www.totaljobs.com/job/application-security-engineer/hargreaves-lansdown-job107905990 ## About the Role * Strong experience integrating security tooling into CI/CD pipelines and engineering platforms. * Ability to develop automation and API-based integrations using at least one programming or scripting language (e.g. Python, JavaScript). * Broad knowledge of software development languages, frameworks, source code build/deploy tools (e.g. Github, Gitlab CI/CD, Harness, Jenkins). * Experience with common application security tooling (SAST, DAST, SCA) and vulnerability aggregation or ASPM Platforms to consolidate and prioritise findings across multiple sources. * Hands-on experience of cloud platforms (AWS, Azure), including deploying containerised workloads (e.g. Docker) or lightweight services (e.g., Lambda, ECS) to support security automation and integrations. * Practical understanding of vulnerability scoring frameworks such as CVSS and EPSS. * Strong understanding of common security vulnerabilities, with the ability to keep pace with emerging threats. * Ability to communicate security risk and support engineering teams in understanding and remediating vulnerabilities. * Experience working in Agile environments, with strong organisational skills and attention to detail. * · Experience improving workflows and processes based on feedback. * · Awareness of and/or experience with developer-focused Security Champion programs. ## Description As an Application Security Engineer at HL, you will play a key role in strengthening the security of our products and services. Partnering with Engineering and other security functions, you'll embed and enhance security across the SDLC. You will help shape our security tooling strategy, drive automation to scale assurance across the business, and create reusable components and support integrations that help reduce friction for engineering teams. This role is an opportunity to enable HL to build secure products at pace by embedding scalable, automated security controls into our SDLC whilst supporting a culture of Secure by Design. What you'll be doing * Design, build and maintain automated security checks and guardrails (including policy as code where appropriate) embedded into developer workflows. * Develop automation and API-based integrations to connect security tooling with CI/CD and Source Code Management platforms, and internal systems. * Implement and operationalise selected security tooling across engineering platforms, ensuring low friction adoption across teams. * Embed secure development practices and security testing into delivery pipelines, shared templates and engineering standards, supporting Shift Left and Secure by Design principles. * Maintain, optimise and measure the effectiveness of security tools, producing dashboards and providing metrics to demonstrate impact. * Evaluate new security tools, assessing integration, scalability and developer experience. * Support the Application Security Lead in defining the strategy, tools and technologies. * Build strong partnerships with Engineering teams and the CISO function to streamline and improve security processes. * Supporting the Security Champions program at HL through developer enablement and training. * Prioritise work effectively, meet agreed deadlines and provide clear progress updates. ## Related Videos - [The Road to MLOps: How Verivox Transitioned to AWS](https://www.wearedevelopers.com/videos/1050-the-road-to-mlops-how-verivox-transitioned-to-aws) - [Innovating Developer Tools with AI: Insights from GitHub Next](https://www.wearedevelopers.com/videos/1268-innovating-developer-tools-with-ai-insights-from-github-next) - [Docker Compose: Rediscovered](https://www.wearedevelopers.com/videos/1978-docker-compose-rediscovered) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Real-World Security for Busy Developers](https://www.wearedevelopers.com/videos/1545-real-world-security-for-busy-developers) - [Enterprise-Cloud-Native - Fast-Paced Development & Deployment in a Highly Secure Banking Environment](https://www.wearedevelopers.com/videos/671-enterprise-cloud-native-fast-paced-development-deployment-in-a-highly-secure-banking-environment) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [Software Engineer Salary London](https://www.wearedevelopers.com/magazine/252-software-engineer-salary-london) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks)