> Markdown version of [/jobs/ext/332841-lead-product-security-specialist](https://www.wearedevelopers.com/jobs/ext/332841-lead-product-security-specialist). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Lead Product Security Specialist - **Company:** Hargreaves Lansdown - **Location:** Bristol, UK - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Agile Methodology, Amazon Web Services, Microsoft Azure, Cloud Computing, Cloud Computing Security, Intrusion Detection Systems, Open Web Application Security, Software Security, Devsecops, Serverless Computing, Static Application Security Testing, Dynamic Application Security Testing - **Published:** June 6, 2026 - **Apply:** https://uk.indeed.com/viewjob?jk=5817ed2ba8be69d1 ## About the Role Do you have experience in Negotiation?, * Demonstrable experience in a Security related role. * A proven track record, of working with one or more of the main cloud vendor platforms, specifically AWS. * Certifications such as AWS Solutions Architect, Azure Solutions Architect are desirable. * Previous management experience. * Excellent communication skills, including communicating complex technical concepts to non-technical stakeholders. * Technical background across multiple security domains and familiarity with cloud security standards * Experience within an Agile and DevSecOps context. * Problem solving skills - with the ability to use own experience to develop pragmatic solutions and resolve complex issues. * Accomplished in forging effective relationships at all levels, skilled at influencing and negotiating. * Certifications such as CISSP, CEH, OSCP, or GSEC are preferrable. * Knowledge of security principles, practices, and frameworks, such as OWASP, NIST, and ISO. * Awareness of security tools and technologies, such as SAST, DAST, IAST, SCA, WAF, IDS, IPS. * Experience in conducting threat modelling and risk assessments. ## Description As the Lead Security Specialist at HL, you will join a team of security experts working with various modern technologies to ensure the security of HL's products. You will oversee security issues and requirements for all product teams, dealing with complex projects daily and serving as the escalation point for the Product Security Specialist (PSS). You will lead threat modelling workshops and engage with key stakeholders to identify threats and recommend countermeasures. Additionally, you will lead a team of Product Security Specialists, providing leadership, technical guidance, and support in tailoring their development to meet their individual needs. What you'll be doing * Overseeing security issues and requirements for all product teams/squads. * Working within Product teams, you will be the single point of contact for security related matters ranging from daily significant change to complex Cloud serverless transformation projects. * Leading a team of Product Security Specialist (PSS). * Providing leadership, technical guidance, and support to the Product Security Specialists. * You will lead/facilitate threat modelling workshops with SMEs. * Engaging with key stakeholders to identify threats and recommend countermeasures. * Collaborating with strategy, transformation, and digital engineering parts of HL to develop and manage the implementation of secure cloud architectures. * Supporting in the creation and implementation of architecture blueprints and proof of concepts on Cloud platforms supporting best practice, secure by design. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [Developer Tools for Microsoft Azure](https://www.wearedevelopers.com/videos/450-developer-tools-for-microsoft-azure) - [Green Cloud Computing](https://www.wearedevelopers.com/videos/592-green-cloud-computing) - [Organizational Change Through The Power Of Why - DevSecOps Enablement](https://www.wearedevelopers.com/videos/478-organizational-change-through-the-power-of-why-devsecops-enablement) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers)