Application Security Leader

RELX Group
Richmond, UK
1 day ago
Apply on relx.wd3.myworkdayjobs.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Working hours
Shift work

Tech stack

Kubernetes Security Application Programming Interfaces (APIs) Amazon Web Services Software System Penetration Testing Architectural Patterns Microsoft Azure Software as a Service Cloud Computing Cyber Security Continuous Integration Corona (Software Development Kit) Information Security Management
+11 more
Open Web Application Security Systems Development Life Cycle Secure Coding Software Engineering Systems Integration Software Vulnerability Management Software Security Serverless Computing Static Application Security Testing Microservices Dynamic Application Security Testing

Job description

We are seeking an experienced Principal Application Security Engineer to lead application security across RX’s global technology estate.

Reporting directly to the Chief Information Security Officer (CISO), this role will serve as the senior technical authority for application security and secure software delivery practices. The successful candidate will partner closely with engineering leadership to ensure security is embedded throughout the software development lifecycle while enabling teams to deliver business value quickly and safely.

This is a highly visible individual contributor role with enterprise-wide influence across Digital, Global Business Systems, cloud platforms, APIs, integrations, and customer-facing applications.

The role combines technical leadership, application security expertise, engineering engagement, threat modelling, secure-by-design governance, and application security posture management.

Responsibilities

  • Lead the RX Application Security programme, defining and maintaining strategy, roadmap, standards, controls, and security maturity objectives.

  • Drive adoption of Secure by Design principles by embedding security throughout the Secure Development Lifecycle (SDLC), including threat modelling and security architecture reviews.

  • Own and mature the Application Security Posture Management capability, including management and optimisation of Aikido and related security tooling.

  • Develop KPIs, dashboards, and reporting for engineering and executive stakeholders, while identifying opportunities for automation and continuous improvement.

  • Oversee vulnerability management activities across applications and platforms, including findings from SAST, DAST, Software Composition Analysis, container security, Infrastructure as Code security, CI/CD security, API security reviews, and penetration testing.

  • Partner with Engineering Directors, Architects, Product Leaders, and Software Engineers to promote secure coding, secure design, and developer-friendly security practices.

  • Provide security guidance for cloud-native environments and modern architectures, including AWS, Azure, microservices, APIs, containers, serverless technologies, and SaaS platforms.

  • Support governance, audit, compliance, risk assessment, and assurance activities while providing technical leadership and mentoring across engineering and security communities.

Requirements

Are you passionate about building secure software and driving security excellence across a global technology landscape?

Do you enjoy partnering with engineering leaders to embed security by design and enable teams to deliver secure, innovative solutions at scale?, * Significant experience in Application Security, Product Security, or Security Engineering.

  • Strong understanding of modern software development methodologies and engineering practices.

  • Experience implementing Secure Development Lifecycle programmes.

  • Experience conducting threat modelling and architecture security reviews.

  • Deep understanding of application security principles, attack techniques, and risk management.

  • Hands-on experience with OWASP Top 10, SAST, DAST, SCA, Container Security, Infrastructure as Code Security, CI/CD Security, and API Security.

  • Experience securing cloud-native environments, particularly AWS and Azure.

  • Strong stakeholder management, communication, influencing, leadership, coaching, and mentoring skills.

Benefits & conditions

We promote a healthy work/life balance across the organisation. We offer an appealing working prospect for our people. With numerous wellbeing initiatives, shared parental leave, study assistance, and sabbaticals, we will help you meet your immediate responsibilities and your long-term goals.

Working Pattern

Working flexible hours - flexing the times when you work in the day to help you fit everything in and work when you are the most productive.

About the company

RX is a global leader in events and exhibitions, leveraging industry expertise, data, and technology to build businesses for individuals, communities, and organisations. With a presence in 25 countries across 41 industry sectors, RX hosts approximately 350 events annually. RX is committed to creating an inclusive work environment for all our people. RX empowers businesses to thrive by leveraging data-driven insights and digital solutions. RX is part of RELX, a global provider of information-based analytics and decision tools for professional and business customers. For more information, visit http://www.rxglobal.com

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on relx.wd3.myworkdayjobs.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

3:07 min

Transitioning architecture to microservices at Netflix

Steve Upton Steve Upton · World Congress 2022

2:59 min

Applying secure coding practices and proactive system monitoring

Mihaela-Roxana Ghidersa · LIVE

26:47 min

Exploring pathways to application security careers and research workflows

Vandana Verma Sehgal · LIVE

10:35 min

Teaching and coaching security concepts for lasting impact

Tanya Janca · World Congress 2021

3:38 min

Shifting from monolithic architectures to microservices and containers

Markus Kett Markus Kett · World Congress 2022

Videos

See all

Related articles

See all