RELX Logo

RELX

Application Security Leader

Posted 2 Days Ago
Be an Early Applicant
In-Office
Richmond, CA, USA
Expert/Leader
In-Office
Richmond, CA, USA
Expert/Leader
Leads the enterprise application security program, strategy, roadmap, standards, and maturity objectives. Embeds secure-by-design practices throughout the SDLC through threat modeling and architecture reviews. Oversees application security posture management, vulnerability management, security tooling, KPIs, and reporting. Partners with engineering, architecture, product, and development teams across cloud-native environments to improve secure coding and design. Provides governance, audit, risk, compliance, mentoring, and technical leadership.
The summary above was generated by AI

Are you passionate about building secure software and driving security excellence across a global technology landscape? 


Do you enjoy partnering with engineering leaders to embed security by design and enable teams to deliver secure, innovative solutions at scale? 

 

About our Team 

RX Global aims to create unforgettable experiences for attendees and exhibitors through organizing events. Innovation, creativity, and collaboration drive the company to offer exceptional services to clients. 

 

About the Role 

We are seeking an experienced Principal Application Security Engineer to lead application security across RX's global technology estate.  

Reporting directly to the Chief Information Security Officer (CISO), this role will serve as the senior technical authority for application security and secure software delivery practices. The successful candidate will partner closely with engineering leadership to ensure security is embedded throughout the software development lifecycle while enabling teams to deliver business value quickly and safely.  

This is a highly visible individual contributor role with enterprise-wide influence across Digital, Global Business Systems, cloud platforms, APIs, integrations, and customer-facing applications.  

The role combines technical leadership, application security expertise, engineering engagement, threat modelling, secure-by-design governance, and application security posture management. 

 

Responsibilities 

  • Lead the RX Application Security programme, defining and maintaining strategy, roadmap, standards, controls, and security maturity objectives. 
  • Drive adoption of Secure by Design principles by embedding security throughout the Secure Development Lifecycle (SDLC), including threat modelling and security architecture reviews. 
  • Own and mature the Application Security Posture Management capability, including management and optimisation of Aikido and related security tooling. 
  • Develop KPIs, dashboards, and reporting for engineering and executive stakeholders, while identifying opportunities for automation and continuous improvement. 
  • Oversee vulnerability management activities across applications and platforms, including findings from SAST, DAST, Software Composition Analysis, container security, Infrastructure as Code security, CI/CD security, API security reviews, and penetration testing. 
  • Partner with Engineering Directors, Architects, Product Leaders, and Software Engineers to promote secure coding, secure design, and developer-friendly security practices. 
  • Provide security guidance for cloud-native environments and modern architectures, including AWS, Azure, microservices, APIs, containers, serverless technologies, and SaaS platforms. 
  • Support governance, audit, compliance, risk assessment, and assurance activities while providing technical leadership and mentoring across engineering and security communities. 

 

Requirements 

  • Significant experience in Application Security, Product Security, or Security Engineering. 
  • Strong understanding of modern software development methodologies and engineering practices. 
  • Experience implementing Secure Development Lifecycle programmes. 
  • Experience conducting threat modelling and architecture security reviews. 
  • Deep understanding of application security principles, attack techniques, and risk management. 
  • Hands-on experience with OWASP Top 10, SAST, DAST, SCA, Container Security, Infrastructure as Code Security, CI/CD Security, and API Security. 
  • Experience securing cloud-native environments, particularly AWS and Azure. 
  • Strong stakeholder management, communication, influencing, leadership, coaching, and mentoring skills. 

 

Work in a Way That Works for You 

We promote a healthy work/life balance across the organisation. We offer an appealing working prospect for our people. With numerous wellbeing initiatives, shared parental leave, study assistance, and sabbaticals, we will help you meet your immediate responsibilities and your long-term goals. 

 

Working Pattern 

Working flexible hours - flexing the times when you work in the day to help you fit everything in and work when you are the most productive. 

About the Business 

RX is a global leader in events and exhibitions, leveraging industry expertise, data, and technology to build businesses for individuals, communities, and organisations. With a presence in 25 countries across 41 industry sectors, RX hosts approximately 350 events annually. RX is committed to creating an inclusive work environment for all our people. RX empowers businesses to thrive by leveraging data-driven insights and digital solutions. RX is part of RELX, a global provider of information-based analytics and decision tools for professional and business customers. For more information, visit http://www.rxglobal.com 

 

We know your well-being and happiness are key to a long and successful career. We are delighted to offer country specific benefits. Click here to access benefits specific to your location.

We are committed to providing a fair and accessible hiring process. If you have a disability or other need that requires accommodation or adjustment, please let us know by completing our Applicant Request Support Form or please contact 1-855-833-5120.

Criminals may pose as recruiters asking for money or personal information. We never request money or banking details from job applicants. Learn more about spotting and avoiding scams here.

Please read our Candidate Privacy Policy.

We are an equal opportunity employer: qualified applicants are considered for and treated during employment without regard to race, color, creed, religion, sex, national origin, citizenship status, disability status, protected veteran status, age, marital status, sexual orientation, gender identity, genetic information, or any other characteristic protected by law.

USA Job Seekers:

EEO Know Your Rights.

Similar Jobs

An Hour Ago
In-Office
106K-232K Annually
Senior level
106K-232K Annually
Senior level
Aerospace • Information Technology • Software • Cybersecurity • Design • Defense • Manufacturing
Designs, integrates, tests, debugs, and leads development of embedded flight software for satellite and payload systems. Responsibilities include software-hardware integration, requirements analysis, cyber vulnerability analysis, cyber monitoring algorithms, configuration automation, documentation, quality assurance, and delivery coordination. The role interfaces with multidisciplinary engineering teams and supports safety, security, and performance objectives for commercial and government space programs.
Top Skills: BitbucketCC++ConfluenceCyber Monitoring AlgorithmsDevOpsEmbedded SystemsGitlabJavaJIRAPythonReal-Time SoftwareWireshark
An Hour Ago
In-Office
177K-239K Annually
Expert/Leader
177K-239K Annually
Expert/Leader
Aerospace • Information Technology • Software • Cybersecurity • Design • Defense • Manufacturing
Leads electrophysics and radar engineering for air and space payloads across the product lifecycle. Responsibilities include radar performance and trade studies, signal and image processing, RWR integration, mission design, payload effectiveness analysis, technical leadership of teams and subcontractors, anomaly resolution, and capability roadmap development. The role requires advanced radar or signal-intelligence expertise, systems integration experience, and active Top Secret/SCI clearance.
Top Skills: Image ProcessingMatlabRadar SystemsRadar Warning Receivers (Rwr)Rf SystemsRfi MitigationSignal ProcessingStkSynthetic Aperture Radar (Sar)
An Hour Ago
In-Office
120K-198K Annually
Senior level
120K-198K Annually
Senior level
Aerospace • Information Technology • Software • Cybersecurity • Design • Defense • Manufacturing
Design and validate ASIC and mixed-signal subsystem architectures for space-based digital communication systems. Responsibilities include requirements derivation, verification planning, ADC/DAC performance analysis, technical trade studies, supplier coordination, hardware and software integration, qualification, unit sell-off, and risk mitigation. The role supports the full subsystem lifecycle and requires collaboration across engineering, program management, suppliers, and customers.
Top Skills: AdcAsicCDacI2CJesdJtagMatlabPythonSerdesSpiVlsi

What you need to know about the San Francisco Tech Scene

San Francisco and the surrounding Bay Area attracts more startup funding than any other region in the world. Home to Stanford University and UC Berkeley, leading VC firms and several of the world’s most valuable companies, the Bay Area is the place to go for anyone looking to make it big in the tech industry. That said, San Francisco has a lot to offer beyond technology thanks to a thriving art and music scene, excellent food and a short drive to several of the country’s most beautiful recreational areas.

Key Facts About San Francisco Tech

  • Number of Tech Workers: 365,500; 13.9% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Google, Apple, Salesforce, Meta
  • Key Industries: Artificial intelligence, cloud computing, fintech, consumer technology, software
  • Funding Landscape: $50.5 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Sequoia Capital, Andreessen Horowitz, Bessemer Venture Partners, Greylock Partners, Khosla Ventures, Kleiner Perkins
  • Research Centers and Universities: Stanford University; University of California, Berkeley; University of San Francisco; Santa Clara University; Ames Research Center; Center for AI Safety; California Institute for Regenerative Medicine

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account