- We are seeking an experienced Principal Application Security Engineer to lead application security across RX’s global technology estate
- Reporting directly to the Chief Information Security Officer (CISO), this role will serve as the senior technical authority for application security and secure software delivery practices
- The successful candidate will partner closely with engineering leadership to ensure security is embedded throughout the software development lifecycle while enabling teams to deliver business value quickly and safely
- This is a highly visible individual contributor role with enterprise-wide influence across Digital, Global Business Systems, cloud platforms, APIs, integrations, and customer-facing applications
- The role combines technical leadership, application security expertise, engineering engagement, threat modelling, secure-by-design governance, and application security posture management
- Lead the RX Application Security programme, defining and maintaining strategy, roadmap, standards, controls, and security maturity objectives
- Drive adoption of Secure by Design principles by embedding security throughout the Secure Development Lifecycle (SDLC), including threat modelling and security architecture reviews
- Own and mature the Application Security Posture Management capability, including management and optimisation of Aikido and related security tooling
- Develop KPIs, dashboards, and reporting for engineering and executive stakeholders, while identifying opportunities for automation and continuous improvement
- Oversee vulnerability management activities across applications and platforms, including findings from SAST, DAST, Software Composition Analysis, container security, Infrastructure as Code security, CI/CD security, API security reviews, and penetration testing
- Partner with Engineering Directors, Architects, Product Leaders, and Software Engineers to promote secure coding, secure design, and developer-friendly security practices
- Provide security guidance for cloud-native environments and modern architectures, including AWS, Azure, microservices, APIs, containers, serverless technologies, and SaaS platforms
- Support governance, audit, compliance, risk assessment, and assurance activities while providing technical leadership and mentoring across engineering and security communities
Significant experience in Application Security, Product Security, or Security EngineeringExperience implementing Secure Development Lifecycle programmesStrong understanding of modern software development methodologies and engineering practicesStrong stakeholder management, communication, influencing, leadership, coaching, and mentoring skillsExperience conducting threat modelling and architecture security reviewsExperience securing cloud-native environments, particularly AWS and AzureDeep understanding of application security principles, attack techniques, and risk managementHands-on experience with OWASP Top 10, SAST, DAST, SCA, Container Security, Infrastructure as Code Security, CI/CD Security, and API Security