Halfords is on a journey - building the future of motoring and cycling and looking for people who want to help shape what comes next. We’re a place for cocreators: people who want to make a real impact, take ownership and be part of something that’s still evolving.
Technology at Halfords is at a turning point. We’re modernising our foundations, sharpening our delivery, and ensuring every technology decision is connected to real commercial and customer outcomes.
We're looking for people who act as trusted advisors to the business, take end-to-end accountability for outcomes, and can balance pace with long-term architectural integrity. Innovation here means practical, scalable solutions, not ideas that stay on whiteboards.
Halfords operates a hybrid working policy – this position will be based 3 days per week at our support centre in Redditch, West Midlands.
As an Application Security Lead, you'll own and shape Halfords' application security capability, ensuring security is embedded into every stage of the software development lifecycle rather than being treated as a final checkpoint before release. Working across a diverse technology estate spanning customer-facing applications, websites, APIs, integrations, mobile platforms, and internal systems, you'll help engineering teams build secure solutions from the outset through effective standards, tooling, guardrails, and governance.
You'll work closely with development teams, architects, product owners, and third-party suppliers to implement secure-by-design principles, conduct threat modelling and security reviews, and ensure appropriate controls are built into delivery processes. This role combines technical application security expertise with strong stakeholder engagement, helping teams understand vulnerabilities, interpret testing results, and implement proportionate solutions that balance security, business value, and delivery pace.
This is an excellent opportunity to join Halfords during a significant period of technology transformation and growing security maturity. With substantial investment and increased focus on cyber security, you'll have the opportunity to establish best practice, influence how applications are designed and delivered across the organisation, and make a lasting impact on a large and complex technology environment. This isn't simply about identifying vulnerabilities after the fact, it's about helping define how we build secure applications, APIs, and digital services in the future.
-
Lead threat modelling exercises and security design reviews for new applications, APIs, integrations, and significant technology changes
-
Select, implement, and manage application security tooling including SAST, DAST, SCA, and secrets detection platforms
-
Coordinate penetration testing activities, managing suppliers, tracking findings, and ensuring remediation activities are completed effectively
-
Work closely with architects, developers, engineering teams, and third-party providers to establish practical security standards, controls, and guardrails