The Team
Product Security sits within Information Security and works closely with Engineering, Product, Architecture, Platform and Risk. The function enables teams across Zopa to deliver change while managing Product Security risk and protecting the bank and its customers. As Head of Product Security, you'll lead the function through its next stage of maturity, setting the multi-year direction, scaling the operating model and helping Zopa respond to a security landscape increasingly shaped by cloud technology, automation and AI.
A Day In The Life:
-
Own and deliver the multi-year Product Security strategy, investment roadmap and priorities.
-
Define the Product Security operating model, including team structure, capacity planning, senior hiring and succession.
-
Lead, grow and develop a high-performing Product Security function.
-
Own Product Security risk appetite, control effectiveness, executive KPIs and regulatory/audit assurance.
-
Act as senior Product Security adviser to the CISO and executive Engineering, Product and Risk stakeholders.
-
Set Product Security standards and drive their adoption across multiple engineering domains.
-
Embed Secure by Design principles into engineering and software delivery.
-
Prioritise investment and engineering effort according to security risk and business impact.
-
Use AI, automation and modern security platforms to reduce manual effort and improve security workflows.
-
Demonstrate improvements in security posture, risk reduction, engineering enablement and operational scalability.
About You:
-
Proven track record defining and delivering enterprise Product Security strategy across a complex engineering organisation.
-
Significant experience leading and scaling a Product or Application Security function.
-
Experience operating in a complex, regulated technology business.
-
Strong people leadership with experience designing teams, hiring senior talent and developing capability.
-
Deep knowledge of modern Application Security, Secure SDLC, DevSecOps and cloud security.
-
Experience owning and communicating Product Security risk, controls and executive-level metrics.
-
Able to influence senior Engineering, Product, Risk and Security leaders.
-
Proven ability to lead change and drive adoption across engineering teams you don't directly manage.
-
Able to demonstrate measurable improvements in security and engineering outcomes.
-
Pragmatic, forward-thinking and comfortable balancing security risk with business and customer outcomes.
Added Bonus:
-
Experience with Wiz, Orca, Prisma Cloud, Microsoft Defender for Cloud, GitHub Advanced Security or equivalent platforms.
-
Experience automating security processes, using AI to assist with vulnerability triage and remediation, and developing LLM-enabled security tooling.
-
Experience reducing manual patching and repetitive security work through automation.
At Zopa we value flexible ways of working.
We value face-to-face collaboration and a good work-life balance. This hybrid role requires you to come to our London office 2-3 days a week.
You'll also have the option of working from abroad for up to 120 days a year!* But no matter where you are, we’ll make sure you’ve got everything you need to thrive, both in your work and home life, from day one.
*Subject to having the right to work in the country of choice
Diversity Statement
Zopa is proud to offer a workplace free from discrimination. Diversity of experience, perspectives, and backgrounds leads to better products for our customers and a unique company culture for our people. We are made up of nearly 50 nationalities, have a DE&I forum made up of Zopians wanting to make a difference and we are proud of our culture where everyone can bring their full self to work. Our approach to DE&I is reflected in our hiring process so please let us know if you require any reasonable adjustments.
Our approach to AI in interviews
At Zopa, AI isn't something we're testing out — it's part of how we work every day. As a proud partner of Jobs 2030, we're committed to building AI fluency across our workforce, and we expect Zopians to use AI as part of how they do their jobs.
Because of that, we want to be transparent about how we think about AI use during our hiring process.
Behavioural and competency-based interviews: please don't use AI. These conversations are designed to understand you — your experiences, your judgment, and how you've approached real situations. An AI-generated answer can't tell us that. What it can do is get in the way of us finding out whether we're the right fit for each other.
Technical interviews: it depends on the role. Some technical stages actively welcome AI use, others don't. Your Talent Partner will let you know what's expected at each stage. Where AI is part of the assessment, we'll be interested not just in the outcome, but in how you used it – the tools you chose, your reasoning, and the decisions you made along the way.