Application Security Leader

RELX International

Richmond (VA)

On-site

USD 150,000 - 190,000

Full time

6 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

RELX International seeks a Principal Application Security Engineer to lead security across its global technology estate. You will serve as the senior technical authority for application security, embedding secure software delivery and threat modelling across the SDLC while enabling rapid, safe delivery of business value.

You will partner with engineering leadership to promote secure coding, govern security posture, and drive maturity across AWS, Azure, APIs, and container-based environments.

Qualifications

  • Extensive experience leading application security programs.
  • Strong knowledge of secure software development lifecycle.
  • Proven ability to influence engineering leadership and teams.

Responsibilities

  • Lead the RX Application Security programme, defining strategy, roadmap, standards, controls, and maturity objectives.
  • Drive Secure by Design principles within the SDLC, including threat modelling and security architecture reviews.
  • Oversee vulnerability management across applications and platforms (SAST/DAST/SCA, container, IaC, CI/CD, API security, pentest).
  • Partner with engineering leaders to promote secure coding and design practices.
  • Develop KPIs, dashboards, and reporting for executives; identify opportunities for automation and improvement.
  • Provide security guidance for cloud-native environments (AWS/Azure, microservices, containers, serverless, SaaS).

Skills

Application Security
Threat Modelling
Secure SDLC
Cloud Security
Vulnerability Management
Security Governance
Leadership
Mentoring

Tools

OWASP Top 10
SAST
DAST
SCA
Container Security
CI/CD Security
API Security

Job description

  • We are seeking an experienced Principal Application Security Engineer to lead application security across RX’s global technology estate
  • Reporting directly to the Chief Information Security Officer (CISO), this role will serve as the senior technical authority for application security and secure software delivery practices
  • The successful candidate will partner closely with engineering leadership to ensure security is embedded throughout the software development lifecycle while enabling teams to deliver business value quickly and safely
  • This is a highly visible individual contributor role with enterprise-wide influence across Digital, Global Business Systems, cloud platforms, APIs, integrations, and customer-facing applications
  • The role combines technical leadership, application security expertise, engineering engagement, threat modelling, secure-by-design governance, and application security posture management
  • Lead the RX Application Security programme, defining and maintaining strategy, roadmap, standards, controls, and security maturity objectives
  • Drive adoption of Secure by Design principles by embedding security throughout the Secure Development Lifecycle (SDLC), including threat modelling and security architecture reviews
  • Own and mature the Application Security Posture Management capability, including management and optimisation of Aikido and related security tooling
  • Develop KPIs, dashboards, and reporting for engineering and executive stakeholders, while identifying opportunities for automation and continuous improvement
  • Oversee vulnerability management activities across applications and platforms, including findings from SAST, DAST, Software Composition Analysis, container security, Infrastructure as Code security, CI/CD security, API security reviews, and penetration testing
  • Partner with Engineering Directors, Architects, Product Leaders, and Software Engineers to promote secure coding, secure design, and developer-friendly security practices
  • Provide security guidance for cloud-native environments and modern architectures, including AWS, Azure, microservices, APIs, containers, serverless technologies, and SaaS platforms
  • Support governance, audit, compliance, risk assessment, and assurance activities while providing technical leadership and mentoring across engineering and security communities

Significant experience in Application Security, Product Security, or Security EngineeringExperience implementing Secure Development Lifecycle programmesStrong understanding of modern software development methodologies and engineering practicesStrong stakeholder management, communication, influencing, leadership, coaching, and mentoring skillsExperience conducting threat modelling and architecture security reviewsExperience securing cloud-native environments, particularly AWS and AzureDeep understanding of application security principles, attack techniques, and risk managementHands-on experience with OWASP Top 10, SAST, DAST, SCA, Container Security, Infrastructure as Code Security, CI/CD Security, and API Security

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Principal Application Security Engineer
Principal Application Security Engineer

Reed Exhibitions Australia Pty Ltd • Richmond (VA), Northern (KY)

Hybrid
USD 150,000 - 230,000
Application Security Leader
Application Security Leader

Relx Plc • Richmond (VA), Northern (KY)

Hybrid
USD 140,000 - 170,000
Application Security Leader
Application Security Leader

Reed Exhibitions Australia Pty Ltd • Richmond (VA), Northern (KY)

Hybrid
USD 150,000 - 230,000
Global Application Security Leader — Secure-by-Design Advocate
Global Application Security Leader — Secure-by-Design Advocate

Relx Plc • Richmond (VA), Northern (KY)

Hybrid
USD 140,000 - 170,000
Lead Application Security Engineer - Cloud-Native & AI
Lead Application Security Engineer - Cloud-Native & AI

Web: • Charlotte (NC)

On-site
USD 150,000 - 200,000
Medical benefits
Dental & Vision
401(k) match
+4
Lead Application Security Engineer - AI & Cloud
Lead Application Security Engineer - AI & Cloud

RXO • Charlotte (NC)

Hybrid
USD 140,000 - 190,000
Health plans
401(k)
Pre-tax accounts
+4
Principal AppSec Leader: Secure SDLC & Cloud
Principal AppSec Leader: Secure SDLC & Cloud

RELX International • Richmond (VA)

On-site
USD 150,000 - 190,000
Principal Application Security Engineer
Principal Application Security Engineer

Cboe • Chicago (IL)

Hybrid
USD 150,000 - 230,000
Lead Engineer, Information Security (Application Security)
Lead Engineer, Information Security (Application Security)

RXO • Charlotte (NC)

Hybrid
USD 140,000 - 190,000
Health plans
401(k)
Pre-tax accounts
+4
Application Security & Red Team - Lead Engineer, Information Security
Application Security & Red Team - Lead Engineer, Information Security

RXO, Inc. • Charlotte (NC)

On-site
USD 90,000 - 150,000