Head of Product Security
- city of westminster, england, United Kingdom
- Permanent·On-site
- Full time
- £120 - £180 Per Day
Job Description
Product Security sits within Information Security and works closely with Engineering, Product, Architecture, Platform and Risk. The function enables teams across Zopa to deliver change while managing Product Security risk and protecting the bank and its customers. As Head of Product Security, you'll lead the function through its next stage of maturity, setting the multi-year direction, scaling the operating model and helping Zopa respond to a security landscape increasingly shaped by cloud technology, automation and AI.A Day In The Life:
- Own and deliver the multi-year Product Security strategy, investment roadmap and priorities.
- Define the Product Security operating model, including team structure, capacity planning, senior hiring and succession.
- Lead, grow and develop a high-performing Product Security function.
- Own Product Security risk appetite, control effectiveness, executive KPIs and regulatory/audit assurance.
- Act as senior Product Security adviser to the CISO and executive Engineering, Product and Risk stakeholders.
- Set Product Security standards and drive their adoption across multiple engineering domains.
- Embed Secure by Design principles into engineering and software delivery.
- Prioritise investment and engineering effort according to security risk and business impact.
- Use AI, automation and modern security platforms to reduce manual effort and improve security workflows.
- Demonstrate improvements in security posture, risk reduction, engineering enablement and operational scalability.
- Proven track record defining and delivering enterprise Product Security strategy across a complex engineering organisation.
- Significant experience leading and scaling a Product or Application Security function.
- Experience operating in a complex, regulated technology business.
- Strong people leadership with experience designing teams, hiring senior talent and developing capability.
- Deep knowledge of modern Application Security, Secure SDLC, DevSecOps and cloud security.
- Experience owning and communicating Product Security risk, controls and executive-level metrics.
- Able to influence senior Engineering, Product, Risk and Security leaders.
- Proven ability to lead change and drive adoption across engineering teams you don't directly manage.
- Able to demonstrate measurable improvements in security and engineering outcomes.
- Pragmatic, forward-thinking and comfortable balancing security risk with business and customer outcomes.
- Experience with Wiz, Orca, Prisma Cloud, Microsoft Defender for Cloud, GitHub Advanced Security or equivalent platforms.
- Experience automating security processes, using AI to assist with vulnerability triage and remediation, and developing LLM-enabled security tooling.
- Experience reducing manual patching and repetitive security work through automation.
- But no matter where you are, we'll make sure you've got everything you need to thrive, both in your work and home life, from day one.
- Subject to having the right to work in the country of choice
Diversity Statement
Zopa is proud to offer a workplace free from discrimination. Diversity of experience, perspectives and backgrounds leads to better products for our customers and a unique company culture for our people. We are made up of nearly 50 nationalities, have a DE&I forum made up of Zopians wanting to make a difference and we are proud of our culture where everyone can bring their full self to work. Our approach to DE&I is reflected in our hiring process so please let us know if you require any reasonable adjustments.
Our approach to AI in interviews
At Zopa, AI isn't something we're testing out - it's part of how we work every day. As a proud partner of Jobs 2030, we're committed to building AI fluency across our workforce, and we expect Zopians to use AI as part of how they do their jobs. Because of that, we want to be transparent about how we think about AI use during our hiring process. Behavioural and competency-based interviews: please don't use AI. These conversations are designed to understand you - your experiences, your judgment, and how you've approached real situations.
#J-18808-Ljbffr

