Application Security Lead
- Hiring from
- United Kingdom
- Work type
- Hybrid
- Posted
Show job descriptionHide job description
About us
Halfords is on a journey - building the future of motoring and cycling and looking for people who want to help shape what comes next. We’re a place for cocreators: people who want to make a real impact, take ownership and be part of something that’s still evolving.
Technology at Halfords is at a turning point. We’re modernising our foundations, sharpening our delivery, and ensuring every technology decision is connected to real commercial and customer outcomes.
We're looking for people who act as trusted advisors to the business, take end-to-end accountability for outcomes, and can balance pace with long-term architectural integrity. Innovation here means practical, scalable solutions, not ideas that stay on whiteboards.
Halfords operates a hybrid working policy – this position will be based 3 days per week at our support centre in Redditch, West Midlands.
About the role
As an Application Security Lead, you'll own and shape Halfords' application security capability, ensuring security is embedded into every stage of the software development lifecycle rather than being treated as a final checkpoint before release. Working across a diverse technology estate spanning customer-facing applications, websites, APIs, integrations, mobile platforms, and internal systems, you'll help engineering teams build secure solutions from the outset through effective standards, tooling, guardrails, and governance.
You'll work closely with development teams, architects, product owners, and third-party suppliers to implement secure-by-design principles, conduct threat modelling and security reviews, and ensure appropriate controls are built into delivery processes. This role combines technical application security expertise with strong stakeholder engagement, helping teams understand vulnerabilities, interpret testing results, and implement proportionate solutions that balance security, business value, and delivery pace.
This is an excellent opportunity to join Halfords during a significant period of technology transformation and growing security maturity. With substantial investment and increased focus on cyber security, you'll have the opportunity to establish best practice, influence how applications are designed and delivered across the organisation, and make a lasting impact on a large and complex technology environment. This isn't simply about identifying vulnerabilities after the fact, it's about helping define how we build secure applications, APIs, and digital services in the future.
Key responsibilities
-
Own and develop the organisation's application security practice, embedding secure-by-design principles and security controls throughout the software development lifecycle
-
Lead threat modelling exercises and security design reviews for new applications, APIs, integrations, and significant technology changes
-
Select, implement, and manage application security tooling including SAST, DAST, SCA, and secrets detection platforms
-
Review security testing results, assess risk, and provide clear recommendations to engineering teams on remediation and resolution activities
-
Act as an application security release gate, making risk-based go/no-go decisions and escalating where appropriate
-
Coordinate penetration testing activities, managing suppliers, tracking findings, and ensuring remediation activities are completed effectively
-
Work closely with architects, developers, engineering teams, and third-party providers to establish practical security standards, controls, and guardrails
About you
-
Proven experience leading or owning application security activities within a modern software development environment
-
Strong knowledge of application security principles, secure coding practices, and common vulnerability classes including the OWASP Top 10
-
Hands-on experience with application security tooling including SAST, DAST, SCA, secrets management, and vulnerability assessment tools
-
Experience integrating security controls into CI/CD pipelines and cloud-native development environments
-
Strong understanding of API security, authentication, authorisation, and technologies such as OAuth 2.0, OIDC, and SAML
-
Knowledge of PCI DSS requirements and their application within software development and digital platforms
-
Relevant security certifications such as OSCP, OSCE, or equivalent practical application security expertise would be highly advantageous
Reward & benefits
-
A fair and competitive salary evaluated against market data, car allowance, annual discretionary bonus scheme, pension, life assurance, 25 days annual leave plus bank holidays and enhanced family leave.
-
Commitment and dedication to your ongoing personal and professional development. We help you to own and grow your potential so you can be at your best in your current role and to support your future career aspirations.
-
We offer hybrid working with a blend of working in our Support Centre and from home.
-
You will have access to a wealth of employee discounts across the Halfords suite of products and services.
-
Wellbeing and inclusion are at the heart of our colleague experience. We offer resources and ongoing support to enhance your wellbeing at work and active Colleague Networks supporting inclusion initiatives across Halfords.
Not sure you meet all the criteria? We'd encourage you to take the wheel and apply anyway! At Halfords we are committed to creating an inclusive workplace for our colleagues. We're an equal opportunities employer and proud to welcome applications from all backgrounds and embrace diversity within our one Halfords Family.
Note: Halfords operates a hybrid working policy – this position will be based 3 days per week at our support centre in Redditch, West Midlands.