Jobless Developer
Zopa logo

Posted 1 month ago

Open

Head of Product Security

LondonHybrid

AI Summary

Leads the Product Security function at Zopa Bank, setting the multi-year strategy, scaling the operating model, and embedding secure-by-design principles across engineering domains while managing risk and regulatory assurance.

About this role

Our Story
Hello there. We’re Zopa.
We started our journey back in 2005, building the first ever peer-to-peer lending company. Fast forward to 2020 and we launched Zopa Bank. A bank that listens to what our customers don’t like about finance and does the opposite. We’re redefining what it feels like to work in finance. Our vision for a new era of banking puts people front and centre — we’ve built a business that empowers everyone to aim high, every day, to move finance forward. Find out more about our fantastic offerings at Zopa.com!
We’re incredibly proud of our achievements and none of it would be possible without the amazing team here. It’s not just industry awards we’re winning, we’ve also been named in the top three UK’s Most Loved Workplaces.
If you embrace unconventional challenges, are unafraid to think differently and are driven to make an outsized impact, you’ll thrive here at Zopa, so join us, and make it count. Want to see us in action? Follow us on Instagram @zopalife

The Team

Product Security sits within Information Security and works closely with Engineering, Product, Architecture, Platform and Risk. The function enables teams across Zopa to deliver change while managing Product Security risk and protecting the bank and its customers. As Head of Product Security, you'll lead the function through its next stage of maturity, setting the multi-year direction, scaling the operating model and helping Zopa respond to a security landscape increasingly shaped by cloud technology, automation and AI.

A Day In The Life:

  • Own and deliver the multi-year Product Security strategy, investment roadmap and priorities.

  • Define the Product Security operating model, including team structure, capacity planning, senior hiring and succession.

  • Lead, grow and develop a high-performing Product Security function.

  • Own Product Security risk appetite, control effectiveness, executive KPIs and regulatory/audit assurance.

  • Act as senior Product Security adviser to the CISO and executive Engineering, Product and Risk stakeholders.

  • Set Product Security standards and drive their adoption across multiple engineering domains.

  • Embed Secure by Design principles into engineering and software delivery.

  • Prioritise investment and engineering effort according to security risk and business impact.

  • Use AI, automation and modern security platforms to reduce manual effort and improve security workflows.

  • Demonstrate improvements in security posture, risk reduction, engineering enablement and operational scalability.

About You:

  • Proven track record defining and delivering enterprise Product Security strategy across a complex engineering organisation.

  • Significant experience leading and scaling a Product or Application Security function.

  • Experience operating in a complex, regulated technology business.

  • Strong people leadership with experience designing teams, hiring senior talent and developing capability.

  • Deep knowledge of modern Application Security, Secure SDLC, DevSecOps and cloud security.

  • Experience owning and communicating Product Security risk, controls and executive-level metrics.

  • Able to influence senior Engineering, Product, Risk and Security leaders.

  • Proven ability to lead change and drive adoption across engineering teams you don't directly manage.

  • Able to demonstrate measurable improvements in security and engineering outcomes.

  • Pragmatic, forward-thinking and comfortable balancing security risk with business and customer outcomes.

Added Bonus:

  • Experience with Wiz, Orca, Prisma Cloud, Microsoft Defender for Cloud, GitHub Advanced Security or equivalent platforms.

  • Experience automating security processes, using AI to assist with vulnerability triage and remediation, and developing LLM-enabled security tooling.

  • Experience reducing manual patching and repetitive security work through automation.

Skills

AI-assisted SecurityApplication SecurityCloud SecurityDevSecOpsGitHub Advanced SecurityKPI ReportingLLM-enabled Security ToolingMicrosoft Defender For CloudOrcaPatching AutomationPrisma CloudRegulatory AssuranceRisk ManagementSecure-by-designSecure SDLCSecurity AutomationVulnerability TriageWiz

Explore related jobs

Browse these categories

Market data for this role

All reports →