Application Security Lead
Quick Summary
About us Halfords is on a journey - building the future of motoring and cycling and looking for people who want to help shape what comes next.
Halfords is on a journey - building the future of motoring and cycling and looking for people who want to help shape what comes next. We’re a place for cocreators: people who want to make a real impact, take ownership and be part of something that’s still evolving.
Technology at Halfords is at a turning point. We’re modernising our foundations, sharpening our delivery, and ensuring every technology decision is connected to real commercial and customer outcomes.
We're looking for people who act as trusted advisors to the business, take end-to-end accountability for outcomes, and can balance pace with long-term architectural integrity. Innovation here means practical, scalable solutions, not ideas that stay on whiteboards.
About the Role
~2 min readAs an Application Security Lead, you'll own and shape Halfords' application security capability, ensuring security is embedded into every stage of the software development lifecycle rather than being treated as a final checkpoint before release. Working across a diverse technology estate spanning customer-facing applications, websites, APIs, integrations, mobile platforms, and internal systems, you'll help engineering teams build secure solutions from the outset through effective standards, tooling, guardrails, and governance.
You'll work closely with development teams, architects, product owners, and third-party suppliers to implement secure-by-design principles, conduct threat modelling and security reviews, and ensure appropriate controls are built into delivery processes. This role combines technical application security expertise with strong stakeholder engagement, helping teams understand vulnerabilities, interpret testing results, and implement proportionate solutions that balance security, business value, and delivery pace.
This is an excellent opportunity to join Halfords during a significant period of technology transformation and growing security maturity. With substantial investment and increased focus on cyber security, you'll have the opportunity to establish best practice, influence how applications are designed and delivered across the organisation, and make a lasting impact on a large and complex technology environment. This isn't simply about identifying vulnerabilities after the fact, it's about helping define how we build secure applications, APIs, and digital services in the future.
Responsibilities
~1 min read- →
Own and develop the organisation's application security practice, embedding secure-by-design principles and security controls throughout the software development lifecycle
- →
Lead threat modelling exercises and security design reviews for new applications, APIs, integrations, and significant technology changes
- →
Select, implement, and manage application security tooling including SAST, DAST, SCA, and secrets detection platforms
- →
Review security testing results, assess risk, and provide clear recommendations to engineering teams on remediation and resolution activities
- →
Act as an application security release gate, making risk-based go/no-go decisions and escalating where appropriate
- →
Coordinate penetration testing activities, managing suppliers, tracking findings, and ensuring remediation activities are completed effectively
- →
Work closely with architects, developers, engineering teams, and third-party providers to establish practical security standards, controls, and guardrails
-
Proven experience leading or owning application security activities within a modern software development environment
-
Strong knowledge of application security principles, secure coding practices, and common vulnerability classes including the OWASP Top 10
-
Hands-on experience with application security tooling including SAST, DAST, SCA, secrets management, and vulnerability assessment tools
-
Experience integrating security controls into CI/CD pipelines and cloud-native development environments
-
Strong understanding of API security, authentication, authorisation, and technologies such as OAuth 2.0, OIDC, and SAML
-
Knowledge of PCI DSS requirements and their application within software development and digital platforms
-
Relevant security certifications such as OSCP, OSCE, or equivalent practical application security expertise would be highly advantageous
What We Offer
~1 min readLocation & Eligibility
Listing Details
- First seen
- October 7, 2026
- Last seen
- October 7, 2026
Posting Health
- Days active
- 0
- Repost count
- 0
- Trust Level
- 56%
- Scored at
- October 7, 2026
Signal breakdown
4 other jobs at
View all →Browse Similar Jobs
Stay ahead of the market
Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.
No spam. Unsubscribe at any time.