> Markdown version of [/jobs/ext/2434224-security-architect](https://www.wearedevelopers.com/jobs/ext/2434224-security-architect). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Architect - **Company:** Hargreaves Lansdown - **Location:** Bristol, UK - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Agile Methodology, Artificial Intelligence, Amazon Web Services, Software System Penetration Testing, Microsoft Azure, Software as a Service, Cyber Security, Continuous Integration, Data Security, Mobile Application Software, Information Systems Security Architecture Professional, Key Management, OAuth, Open Web Application Security, Openid Connect, Sherwood Applied Business Security Architecture, Security Assertion Markup Language (SAML), Software Vulnerability Management, Data Logging, Large Language Models, Software Security, Rate Limiting, Kubernetes, Graphql, Serverless Computing, Static Application Security Testing, Dynamic Application Security Testing - **Published:** August 7, 2026 - **Apply:** https://uk.indeed.com/viewjob?jk=daaa567f25ead452 ## About the Role * Substantial experience in security architecture with application security as your centre of gravity, at senior level or ready to step up to it. * You have designed secure architectures for cloud-native applications on AWS, and you understand containers and Kubernetes well enough to reason about the security model rather than only the tooling. * Real depth in identity and access: OAuth 2.0, OpenID Connect and SAML in practice, authorisation models beyond role checks, and service-to-service authentication. FIDO2 and passwordless experience is a strong plus. * Practical API security experience across REST and GraphQL, including authorisation design and the failure modes each brings. * You have worked in a mixed estate and can secure legacy applications proportionately, without either ignoring them or blocking delivery over problems that will disappear at migration. * You have run complex threat modelling and design reviews as a regular discipline and can point to what changed as a result. * You have embedded security into Agile and CI/CD delivery in a way that engineers accepted. * You can influence without authority. Getting a pattern adopted when nobody must adopt it, and saying no in a way that keeps delivery on your side, matters more here than formal sign-off rights. * You are comfortable in a fast-moving transformation where the target architecture is still being decided. Desirable Experience in financial services or another regulated sector; mobile application security; software supply chain and secure SDLC; hands-on experience with Amazon Bedrock or comparable managed model platforms; familiarity with the OWASP Top 10 for LLM and Agentic Applications; working knowledge of OWASP ASVS, Top 10 and API Security Top 10. Azure exposure is useful, although our estate is AWS-first. Certifications CISSP, CCSP or AWS Security Specialty would be valuable, or equivalent demonstrable experience. Other relevant certifications such as CSSLP, SABSA, SANS GCSA or Microsoft Cybersecurity Architect Expert are welcome but not essential. ## Description * Own application security architecture across web, mobile, API and cloud-native services, and maintain the reference architectures and patterns engineering teams build against. * Design the patterns that carry the most weight i.e. authentication and authorisation, token architecture and service-to-service identity, secrets management, cryptography and secure data handling. * Define API security patterns for both REST and GraphQL, covering authorisation at object and field level, schema exposure, query cost and depth controls, rate limiting and gateway placement, recognising that GraphQL breaks many of the path-based controls that work for REST. * Set pragmatic security positions for legacy applications, including compensating controls, safe integration with newer services and how security debt is prioritised against the migration roadmap rather than deferred indefinitely. * Lead security design reviews for significant applications, integrations and client journeys, and take recommendations to the design authority / architecture review board as a technical advisor. AI security * Define the security architecture for AI-enabled features built on Amazon Bedrock, covering model access controls, guardrails, prompt and output handling, data residency and cross-region inference, and logging that meets our regulatory retention needs. * Establish how agentic applications are secured: tool and action permissions, non-human identity and credential scoping, MCP and similar integration layers, human-in-the-loop checkpoints, and containment when an agent behaves unexpectedly. * Assure third-party and SaaS-embedded AI and set the guardrails for AI-assisted developer tooling used inside our own delivery pipelines. Threat modelling and risk * Lead threat modelling for applications, APIs and AI features using STRIDE and OWASP methods, supported by appropriate HL TM tooling, driving the resulting mitigations to closure. * Assess the security implications of new products, technologies and third-party integrations, and translate emerging attack trends into changes to our patterns and controls. * Provide technical leadership on security exceptions and risk decisions, including the judgement about when a risk is acceptable. Secure engineering * Define the security controls and assurance gates in our CI/CD pipelines, covering SAST, DAST, SCA, secrets scanning and container image assurance and how findings reach the teams who fix them. * Partner with engineering to build secure-by-default capabilities that teams adopt because they are useful, not because they are mandated. * Strengthen software supply chain controls across dependencies, build provenance and artefact integrity. * Work alongside SoC, penetration testing and vulnerability management teams so that findings feed back into architecture rather than staying at the individual finding level. Governance and regulation * Maintain the application security standards and architectural guardrails and keep them current as the platform changes. * Ensure designs meet FCA expectations, operational resilience requirements and Consumer Duty considerations for digital client journeys, working with Risk and Compliance where interpretation is needed. What success looks like * Engineering teams are building against published patterns for authentication, authorisation, API security and secrets rather than solving those problems individually. * Threat modelling runs as a routine part of design for significant changes, not as an escalation. * We have a clear, agreed position on how AI and agentic features are secured and assured, and it is being applied. ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Putting the Graph In GraphQL With The Neo4j GraphQL Library](https://www.wearedevelopers.com/videos/257-putting-the-graph-in-graphql-with-the-neo4j-graphql-library) - [Understanding Kubernetes in a visual way](https://www.wearedevelopers.com/videos/100085-understanding-kubernetes-in-a-visual-way) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) - [Software Security 101: Secure Coding Basics](https://www.wearedevelopers.com/videos/220-software-security-101-secure-coding-basics) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Security Basics for Vibe Coders](https://www.wearedevelopers.com/magazine/598-security-basics-for-vibe-coders) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers)