New

Application Security Lead

West Midlands
OtherApplication
2 views0 saves0 applied

Quick Summary

Overview

About us Halfords is on a journey - building the future of motoring and cycling and looking for people who want to help shape what comes next.

Technical Tools
OtherApplication

Halfords is on a journey - building the future of motoring and cycling and looking for people who want to help shape what comes next. We’re a place for cocreators: people who want to make a real impact, take ownership and be part of something that’s still evolving. 

Technology at Halfords is at a turning point. We’re modernising our foundations, sharpening our delivery, and ensuring every technology decision is connected to real commercial and customer outcomes. 

We're looking for people who act as trusted advisors to the business, take end-to-end accountability for outcomes, and can balance pace with long-term architectural integrity. Innovation here means practical, scalable solutions, not ideas that stay on whiteboards. 

About the Role

~2 min read

As an Application Security Lead, you'll own and shape Halfords' application security capability, ensuring security is embedded into every stage of the software development lifecycle rather than being treated as a final checkpoint before release. Working across a diverse technology estate spanning customer-facing applications, websites, APIs, integrations, mobile platforms, and internal systems, you'll help engineering teams build secure solutions from the outset through effective standards, tooling, guardrails, and governance. 

You'll work closely with development teams, architects, product owners, and third-party suppliers to implement secure-by-design principles, conduct threat modelling and security reviews, and ensure appropriate controls are built into delivery processes. This role combines technical application security expertise with strong stakeholder engagement, helping teams understand vulnerabilities, interpret testing results, and implement proportionate solutions that balance security, business value, and delivery pace. 

This is an excellent opportunity to join Halfords during a significant period of technology transformation and growing security maturity. With substantial investment and increased focus on cyber security, you'll have the opportunity to establish best practice, influence how applications are designed and delivered across the organisation, and make a lasting impact on a large and complex technology environment. This isn't simply about identifying vulnerabilities after the fact, it's about helping define how we build secure applications, APIs, and digital services in the future. 

Responsibilities

~1 min read
  • →

    Own and develop the organisation's application security practice, embedding secure-by-design principles and security controls throughout the software development lifecycle 

  • →

    Lead threat modelling exercises and security design reviews for new applications, APIs, integrations, and significant technology changes 

  • →

    Select, implement, and manage application security tooling including SAST, DAST, SCA, and secrets detection platforms 

  • →

    Review security testing results, assess risk, and provide clear recommendations to engineering teams on remediation and resolution activities 

  • →

    Act as an application security release gate, making risk-based go/no-go decisions and escalating where appropriate 

  • →

    Coordinate penetration testing activities, managing suppliers, tracking findings, and ensuring remediation activities are completed effectively 

  • →

    Work closely with architects, developers, engineering teams, and third-party providers to establish practical security standards, controls, and guardrails 
     

  • Proven experience leading or owning application security activities within a modern software development environment 

  • Strong knowledge of application security principles, secure coding practices, and common vulnerability classes including the OWASP Top 10 

  • Hands-on experience with application security tooling including SAST, DAST, SCA, secrets management, and vulnerability assessment tools 

  • Experience integrating security controls into CI/CD pipelines and cloud-native development environments 

  • Strong understanding of API security, authentication, authorisation, and technologies such as OAuth 2.0, OIDC, and SAML 

  • Knowledge of PCI DSS requirements and their application within software development and digital platforms 

  • Relevant security certifications such as OSCP, OSCE, or equivalent practical application security expertise would be highly advantageous 
     

What We Offer

~1 min read

Location & Eligibility

Where is the job
West Midlands
On-site at the office
Who can apply
Same as job location

Listing Details

First seen
October 7, 2026
Last seen
October 7, 2026

Posting Health

Days active
0
Repost count
0
Trust Level
56%
Scored at
October 7, 2026

Signal breakdown

freshnesssource trustcontent trustemployer trust

4 other jobs at

View all →

Explore open roles at .

Newsletter

Stay ahead of the market

Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.

A
B
C
D
Join 12,000+ marketers

No spam. Unsubscribe at any time.

Application Security Lead