> Markdown version of [/jobs/ext/3059237-application-security-leader](https://www.wearedevelopers.com/jobs/ext/3059237-application-security-leader). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Application Security Leader - **Company:** RELX Group - **Location:** Richmond, UK - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Kubernetes Security, Application Programming Interfaces (APIs), Amazon Web Services, Software System Penetration Testing, Architectural Patterns, Microsoft Azure, Software as a Service, Cloud Computing, Cyber Security, Continuous Integration, Corona (Software Development Kit), Information Security Management, Open Web Application Security, Systems Development Life Cycle, Secure Coding, Software Engineering, Systems Integration, Software Vulnerability Management, Software Security, Serverless Computing, Static Application Security Testing, Microservices, Dynamic Application Security Testing - **Published:** September 25, 2026 - **Apply:** https://relx.wd3.myworkdayjobs.com/en-US/relx/details/Richmond/Application-Security-Leader_R117943-1 ## About the Role Are you passionate about building secure software and driving security excellence across a global technology landscape? Do you enjoy partnering with engineering leaders to embed security by design and enable teams to deliver secure, innovative solutions at scale?, * Significant experience in Application Security, Product Security, or Security Engineering. * Strong understanding of modern software development methodologies and engineering practices. * Experience implementing Secure Development Lifecycle programmes. * Experience conducting threat modelling and architecture security reviews. * Deep understanding of application security principles, attack techniques, and risk management. * Hands-on experience with OWASP Top 10, SAST, DAST, SCA, Container Security, Infrastructure as Code Security, CI/CD Security, and API Security. * Experience securing cloud-native environments, particularly AWS and Azure. * Strong stakeholder management, communication, influencing, leadership, coaching, and mentoring skills. ## Description We are seeking an experienced Principal Application Security Engineer to lead application security across RX's global technology estate. Reporting directly to the Chief Information Security Officer (CISO), this role will serve as the senior technical authority for application security and secure software delivery practices. The successful candidate will partner closely with engineering leadership to ensure security is embedded throughout the software development lifecycle while enabling teams to deliver business value quickly and safely. This is a highly visible individual contributor role with enterprise-wide influence across Digital, Global Business Systems, cloud platforms, APIs, integrations, and customer-facing applications. The role combines technical leadership, application security expertise, engineering engagement, threat modelling, secure-by-design governance, and application security posture management. Responsibilities * Lead the RX Application Security programme, defining and maintaining strategy, roadmap, standards, controls, and security maturity objectives. * Drive adoption of Secure by Design principles by embedding security throughout the Secure Development Lifecycle (SDLC), including threat modelling and security architecture reviews. * Own and mature the Application Security Posture Management capability, including management and optimisation of Aikido and related security tooling. * Develop KPIs, dashboards, and reporting for engineering and executive stakeholders, while identifying opportunities for automation and continuous improvement. * Oversee vulnerability management activities across applications and platforms, including findings from SAST, DAST, Software Composition Analysis, container security, Infrastructure as Code security, CI/CD security, API security reviews, and penetration testing. * Partner with Engineering Directors, Architects, Product Leaders, and Software Engineers to promote secure coding, secure design, and developer-friendly security practices. * Provide security guidance for cloud-native environments and modern architectures, including AWS, Azure, microservices, APIs, containers, serverless technologies, and SaaS platforms. * Support governance, audit, compliance, risk assessment, and assurance activities while providing technical leadership and mentoring across engineering and security communities. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Microservices: how to get started with Spring Boot and Kubernetes](https://www.wearedevelopers.com/videos/242-microservices-how-to-get-started-with-spring-boot-and-kubernetes) - [How to Cause (or Prevent) a Massive Data Breach- Secure Coding and IDOR](https://www.wearedevelopers.com/videos/39-how-to-cause-or-prevent-a-massive-data-breach-secure-coding-and-idor) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Building Security Champions](https://www.wearedevelopers.com/videos/193-building-security-champions) - [Cloud Chaos and Microservices Mayhem](https://www.wearedevelopers.com/videos/104-cloud-chaos-and-microservices-mayhem) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers)