Head of Application Security

Harvey Nash

Greater London

On-site

GBP 120,000 - 180,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Expenses covered for London visits

Job summary

Harvey Nash partners with a high-growth cybersecurity product business to hire a Head of DevSecOps who will own and evolve the product security function. This is a hands-on leadership role with strategic impact across engineering, security, and product teams.

You will drive security across the SDLC, lead threat modelling, pen testing, vulnerability management, and incident response, while mentoring a small security engineering team.

Qualifications

  • Leadership experience in DevSecOps / AppSec.
  • Hands-on with SAST, DAST, SCA in CI/CD.
  • Deep understanding of modern product security.
  • Experience balancing security with delivery in a product environment.
  • Strong stakeholder skills across engineering and exec level.

Responsibilities

  • Own product security posture end-to-end.
  • Define and drive DevSecOps strategy across the SDLC.
  • Lead threat modelling, pen testing, and vulnerability management.
  • Embed security into engineering teams and delivery pipelines.
  • Own supply chain security and SBOM reporting.
  • Lead and grow a small, high-calibre team.
  • Act as a key voice in incident response and risk management.
  • Explore and scale AI-driven / agentic security tooling.

Skills

Leadership DevSecOps / AppSec
SAST, DAST, SCA in CI/CD
Product security strategy
Security-delivery balance
Stakeholder management

Tools

SAST
DAST
SCA

Job description

Head of DevSecOps / Security Engineering (1 day/month London - Expenses Covered)

We’re working with a high-growth cybersecurity product business looking to hire a Head of DevSecOps to own and evolve their product security function.

This is a hands-on leadership role with real ownership, setting strategy whilst still being close enough to the detail to influence key technical decisions.

The role:
  • Own product security posture end-to-end
  • Define and drive DevSecOps strategy across the SDLC
  • Lead threat modelling, pen testing, and vulnerability management
  • Embed security into engineering teams and delivery pipelines
  • Own supply chain security and SBOM reporting
  • Lead and grow a small, high-calibre team
  • Act as a key voice in incident response and risk management
  • Explore and scale AI-driven / agentic security tooling
What they’re looking for:
  • Proven leadership in DevSecOps / AppSec
  • Strong hands-on experience with SAST, DAST, SCA in CI/CD
  • Deep understanding of modern product security
  • Experience balancing security with delivery in a product environment
  • Strong stakeholder skills across engineering and exec level
Nice to have:
  • Cloud security (AWS / Azure / GCP)
  • Experience securing AI / ML or agent-based systems
  • Exposure to OWASP, NIST, ISO or similar
  • Security-first product business with strong technical DNA
  • Backed for growth and scaling
  • Remote-first with just 1 day per month in London (expenses covered)
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Lead Software Security Engineer
Lead Software Security Engineer

United States Digital Space LLC • Greater London

Hybrid
GBP 120,000 - 150,000
Pension scheme
Generous holiday allowance
Ongoing learning and professional development
Security Engineer
Security Engineer

Copello • Uxbridge

Hybrid
GBP 85,000 - 120,000
Senior Application Security Consultant
Senior Application Security Consultant

Salt • Greater London

Hybrid
GBP 90,000 - 120,000
Security Engineering Lead
Security Engineering Lead

United States Digital Space LLC • Greater London

On-site
GBP 120,000 - 150,000
Equity in an early-stage tech company
25 days holiday plus local public hols
Apple hardware
+4
Senior Security Engineer
Senior Security Engineer

Data Science Festival • Greater London

Hybrid
GBP 100,000 - 135,000
Generous holiday allowance
Pension scheme
Ongoing learning and professional development
+2
Senior Application Security Consultant (SAST/DAST/OWASP )
Senior Application Security Consultant (SAST/DAST/OWASP )

Salt • City Of London

Hybrid
GBP 66,000 - 111,000
DevSecOps Engineer
DevSecOps Engineer

Trust In SODA • Greater London

Remote
Senior Application Security Specialist
Senior Application Security Specialist

La Fosse • Greater London

Hybrid
Application Security Engineer (Cyber)
Application Security Engineer (Cyber)

Source Technology Limited • Greater London

Hybrid
GBP 90,000 - 120,000
Software Security Engineer
Software Security Engineer

Data Science Festival • Greater London

Hybrid
GBP 90,000 - 150,000
Hybrid working model
Pension scheme
Generous holiday allowance