Excited to grow your career? Our purpose is to make it easy for people to save and invest for a better future. We are looking for great people to join us, so please come and invest in YOUR future at Hargreaves Lansdown. …
We are the Information Intelligence Group (IIG) of CACI UK, a specialist software consultancy providing new bespoke solutions to solve our customers complex operational problems. As our business continues to grow, we are…
Software Developer – Embedded Systems Location: Bristol 3-4 days/week on customer site Clearance: Must be eligible for DV clearance (British Citizen, UK residency last 10 years). Are you an experienced software developer…
Skills: C++, Python, Embedded systems, ESP32, Raspberry Pi
Digital Catapult is a technology innovation organisation. We accelerate the practical application of deep technologies to equip the UK to be future ready. We partner with businesses, investors and academia to identify va…
Skills: Artificial intelligence, Technology strategy, Horizon scanning, Research and development, Stakeholder management
Business Development Representative Department: Sales Employment Type: Permanent Location: Bristol, UK Reporting To: Raj Shah Compensation: £35,000-£42,000 (£52,000-£62,000 OTE) Description The headlines... Start Date: F…
About Ping Identity: At Ping Identity, we believe in making digital experiences both secure and seamless for all users, without compromise. We call this digital freedom. And it's not just something we provide our custome…
Are you excited by the idea of using data science to tackle real-world challenges and drive meaningful impact? We are looking for a Senior Data Science Innovator to join our Strategy, Innovation & Partnerships (SIP) team…
Skills: Data Science, Python, Machine Learning, Statistical Methods, Timeseries Analysis
About this Opportunity Vinarchy is redefining wine as a newly formed global wine company, bringing together the heritage, scale and ambition of Accolade Wines and Pernod Ricard Winemakers. As part of our continued global…
Skills: PowerApps, Power Automate, AI Implementation, Workflow Automation, Low Code Development
About AXA: AXA is a global leader in insurance and financial services, dedicated to helping customers protect what matters most to them. As the sixth-largest insurance company in the world, we provide a wide range of ser…
Skills: GenAI, Solution Architecture, LLMs, Agentic AI, AI Governance
AI Security Research Engineer Description - We have an exciting opportunity to join the HP Security Lab. The role will be focused on AI security in edge architectures. More specifically combining knowledge of ML and syst…
We are the Information Intelligence Group (IIG) of CACI UK, a specialist software consultancy providing new bespoke solutions to solve our customers complex operational problems. As our business continues to grow, we are…
This is a unique opportunity to be part of a brand new team tackling a companywide issue that will have enormous impact as the initiative is progressed. Job Title: Asset Co-ordinator Please note: Automatic promotion is n…
Skills: Asset management, Data analysis, Change management, Continuous improvement, ISO 55000
Cybersecurity Consultant (Discovery, Threat and Requirements)
Bristol, England, United Kingdom · Hybrid
Senior
Overview Expleo is a trusted partner for end-to-end, integrated engineering, quality services, and management consulting for digital transformation. We help businesses harness technological change to successfully deliver…
About Us: We are the Information Intelligence Group (IIG) of CACI UK, a specialist software consultancy providing new bespoke solutions to solve our customers complex operational problems. As our business continues to gr…
Job Description: SECURITY CLEARANCE: You will be subject to a BPSS check (including a criminal record check) TRAVEL REQUIRED: Occasional travel within UK and internationally LOCATION: Filton (80% of your working week mus…
Skills: Landing gear systems, Test strategy development, Data analysis, Validation and verification, Project management
Excited to grow your career? Our purpose is to make it easy for people to save and invest for a better future. We are looking for great people to join us, so please come and invest in YOUR future at Hargreaves Lansdown. …
Weapon System Equipment Project Engineer (RMO) - Laser Source
Bolton, England, United Kingdom · Hybrid
Senior
Are you prepared to join an outstanding team that is at the forefront of advanced technology? If you are a driven and experienced engineer looking for a chance to contribute to top-tier Laser Directed Energy Weapon (LDEW…
Skills: Systems engineering, Interface management, Technical statement of work, Stakeholder engagement, Project management
Job Description Product Design - Structures and Transmissions Full Time Bristol - Hybrid – minimum 3 days on site per week Why join Rolls-Royce? At Rolls-Royce we are proud to be a business that has truly helped to shape…
Job Description Product Design - Structures and Transmissions Full Time Bristol - Hybrid – minimum 3 days on site per week Why join Rolls-Royce? At Rolls-Royce we are proud to be a business that has truly helped to shape…
Skills: Product design, Structures and transmissions, Engineering design, Design for manufacture, Manufacturing robustness
Sign up with Clera and we'll reach out the moment a role actually fits you — no more spraying applications into the void.
Full-time
professional certificate
Discretionary annual bonus, Annual pay review, 25 days holiday plus bank holidays, Additional Christmas closure, Flexible working options, Hybrid working
Posted 6d ago
Apply by Aug 23
~38 hrs/week
Responsibilities
You will own the application security architecture across a complex estate, including cloud-native services, mobile applications, and AI-enabled features. You will also define security patterns, lead design reviews, and partner with engineering teams to ensure secure-by-default capabilities.
Requirements
The role requires substantial experience in security architecture with a focus on application security and cloud-native environments. Candidates should possess deep knowledge of identity protocols, API security, and the ability to influence engineering teams within a regulated financial environment.
Full job description
Excited to grow your career?
Our purpose is to make it easy for people to save and invest for a better future. We are looking for great people to join us, so please come and invest in YOUR future at Hargreaves Lansdown.
We know that sometimes people can be put off applying for a job if they don't tick every box. If you're excited about working for us and have most of the skills or experience we're looking for, please go ahead and apply. We’d love to hear from you!
About the role
This is a hands-on security architecture role with significant influence across engineering, architecture, cyber security, risk and product teams. You’ll own application security architecture across a complex estate that includes new cloud-native services, mobile applications, REST and GraphQL APIs, AI-enabled features and a substantial legacy environment that remains live during transformation.
You’ll create the patterns, standards and guardrails that make the secure path the easy one for engineering teams. You’ll also lead the design reviews that matter most, guide pragmatic risk decisions, and help ensure our digital services meet the expectations of clients, regulators and the business.
What you’ll be doing
Architecture and design
Own application security architecture across web, mobile, API and cloud-native services, and maintain the reference architectures and patterns engineering teams build against.
Design the patterns that carry the most weight i.e. authentication and authorisation, token architecture and service-to-service identity, secrets management, cryptography and secure data handling.
Define API security patterns for both REST and GraphQL, covering authorisation at object and field level, schema exposure, query cost and depth controls, rate limiting and gateway placement, recognising that GraphQL breaks many of the path-based controls that work for REST.
Set pragmatic security positions for legacy applications, including compensating controls, safe integration with newer services and how security debt is prioritised against the migration roadmap rather than deferred indefinitely.
Lead security design reviews for significant applications, integrations and client journeys, and take recommendations to the design authority / architecture review board as a technical advisor.
AI security
Define the security architecture for AI-enabled features built on Amazon Bedrock, covering model access controls, guardrails, prompt and output handling, data residency and cross-region inference, and logging that meets our regulatory retention needs.
Establish how agentic applications are secured: tool and action permissions, non-human identity and credential scoping, MCP and similar integration layers, human-in-the-loop checkpoints, and containment when an agent behaves unexpectedly.
Assure third-party and SaaS-embedded AI and set the guardrails for AI-assisted developer tooling used inside our own delivery pipelines.
Threat modelling and risk
Lead threat modelling for applications, APIs and AI features using STRIDE and OWASP methods, supported by appropriate HL TM tooling, driving the resulting mitigations to closure.
Assess the security implications of new products, technologies and third-party integrations, and translate emerging attack trends into changes to our patterns and controls.
Provide technical leadership on security exceptions and risk decisions, including the judgement about when a risk is acceptable.
Secure engineering
Define the security controls and assurance gates in our CI/CD pipelines, covering SAST, DAST, SCA, secrets scanning and container image assurance and how findings reach the teams who fix them.
Partner with engineering to build secure-by-default capabilities that teams adopt because they are useful, not because they are mandated.
Strengthen software supply chain controls across dependencies, build provenance and artefact integrity.
Work alongside SoC, penetration testing and vulnerability management teams so that findings feed back into architecture rather than staying at the individual finding level.
Governance and regulation
Maintain the application security standards and architectural guardrails and keep them current as the platform changes.
Ensure designs meet FCA expectations, operational resilience requirements and Consumer Duty considerations for digital client journeys, working with Risk and Compliance where interpretation is needed.
What success looks like
Engineering teams are building against published patterns for authentication, authorisation, API security and secrets rather than solving those problems individually.
Threat modelling runs as a routine part of design for significant changes, not as an escalation.
We have a clear, agreed position on how AI and agentic features are secured and assured, and it is being applied.
About you
Substantial experience in security architecture with application security as your centre of gravity, at senior level or ready to step up to it.
You have designed secure architectures for cloud-native applications on AWS, and you understand containers and Kubernetes well enough to reason about the security model rather than only the tooling.
Real depth in identity and access: OAuth 2.0, OpenID Connect and SAML in practice, authorisation models beyond role checks, and service-to-service authentication. FIDO2 and passwordless experience is a strong plus.
Practical API security experience across REST and GraphQL, including authorisation design and the failure modes each brings.
You have worked in a mixed estate and can secure legacy applications proportionately, without either ignoring them or blocking delivery over problems that will disappear at migration.
You have run complex threat modelling and design reviews as a regular discipline and can point to what changed as a result.
You have embedded security into Agile and CI/CD delivery in a way that engineers accepted.
You can influence without authority. Getting a pattern adopted when nobody must adopt it, and saying no in a way that keeps delivery on your side, matters more here than formal sign-off rights.
You are comfortable in a fast-moving transformation where the target architecture is still being decided.
Desirable
Experience in financial services or another regulated sector; mobile application security; software supply chain and secure SDLC; hands-on experience with Amazon Bedrock or comparable managed model platforms; familiarity with the OWASP Top 10 for LLM and Agentic Applications; working knowledge of OWASP ASVS, Top 10 and API Security Top 10. Azure exposure is useful, although our estate is AWS-first.
Certifications
CISSP, CCSP or AWS Security Specialty would be valuable, or equivalent demonstrable experience. Other relevant certifications such as CSSLP, SABSA, SANS GCSA or Microsoft Cybersecurity Architect Expert are welcome but not essential.
Interview process
This will be a 2-stage interview process, consisting of an intro call, competency and behavioural based interview with technical assessment.
Working Schedule
We are based in Bristol, BS1 5HL. This role is permanent, full time, 37.5 hours per week, Monday to Friday. We have returned to the office 2 days a week.
Why us?
Here at HL, we’re the UK’s number 1 investment platform for private investors, based in Bristol. For more than 40 years we’ve helped investors save time, tax and money on their investments.
To achieve our mission, we believe we have a workplace like no other, with constant learning, dynamic teams, and a great ethos. We're steered by core values that promote service, quality, innovation, and opportunity in everything we do.
What's on offer?
Discretionary annual bonusand annual pay review
25 days holiday plus bank holidays and 1-day additional Christmas closure
Option to purchase an additional 5 days holiday
Flexible working options available, including hybrid working
Enhanced parental leave
Pension scheme up to 11% employer contribution
Income Protection and Life insurance (4 x salary core level of cover)
Private medical insurance
Health care cash plans - including optical, dental, and outpatient care
Health screening programme
Help@hand- confidential support including mental health counselling and remote GP
Wellhub - unlimited access to fitness providers and wellness coach sessions
Variety of travel to work schemes with bike storage and shower facilities
Inhouse barista and deli serving subsidised coffee and sandwiches
Two paid volunteering days per year
dependant on role level
only available to select during our annual benefits window, in November each year
Hargreaves Lansdown is an inclusive employer that values diversity in its workforce. We encourage applications from all individuals without regard to race, religion, gender, sexual orientation, national origin, disability or age.
This role may also be available on a flexible working or part time basis – please ask the Recruitment & Onboarding team for more information.
Please note, we are unable to provide employment sponsorship to candidates.
The UK’s number one investment and savings platform.
Industry
Financial Services
Company size
1,001-5,000 employees
Founded
1981
Headquarters
Bristol
LinkedIn followers
62,140
We’re the UK’s number 1 investment platform for private investors, based in Bristol. For more than 40 years we’ve helped investors save time, tax and money on their investments. Today we're trusted by over 2 million clients.
Offices: One College Square South, Anchor Road, Bristol, BS1 5HL, GB
How many Technology jobs are open in Bristol, United Kingdom right now?
There are currently 453 open technology positions in Bristol, United Kingdom listed on Clera. New openings are added daily as companies post roles.
Which companies are hiring for Technology roles in Bristol, United Kingdom?
Companies currently hiring include Graphcore, Capgemini, Boeing, Leonardo, Hargreaves Lansdown, among others. Browse the listings above to see every active employer.
Are there remote or hybrid Technology jobs in Bristol, United Kingdom?
Yes — 351 of the 453 open technology positions offer remote or hybrid work (17 remote, 334 hybrid).
How do I apply for Technology jobs in Bristol, United Kingdom?
Each listing links directly to the employer's application page. Apply early — fresh listings get the most recruiter attention in the first two weeks.