21 hours ago
Richmond, VA, USAStaff+
Responsibilities
- Lead the RX Application Security program by defining and maintaining its strategy, roadmap, standards, controls, and security maturity objectives.
- Embed Secure by Design principles throughout the software development lifecycle through threat modeling and security architecture reviews.
- Own and mature the Application Security Posture Management capability, including management and optimization of Aikido and related security tooling.
- Develop KPIs, dashboards, and reporting for engineering and executive stakeholders, and identify automation and continuous-improvement opportunities.
- Oversee application and platform vulnerability management, including SAST, DAST, software composition analysis, container security, infrastructure-as-code security, CI/CD security, API security reviews, and penetration testing.
- Partner with engineering directors, architects, product leaders, and software engineers to promote secure coding, secure design, and developer-friendly security practices.
- Provide security guidance for cloud-native environments and modern architectures, including AWS, Azure, APIs, containers, serverless technologies, and SaaS platforms.
- Support governance, audit, compliance, risk assessment, and assurance activities while providing technical leadership, coaching, and mentoring.
Requirements
- Significant experience in application security, product security, or security engineering.
- Strong understanding of modern software development methodologies and engineering practices.
- Experience implementing Secure Development Lifecycle programs.
- Experience conducting threat modeling and architecture security reviews.
- Deep understanding of application security principles, attack techniques, and risk management.
- Hands-on experience with OWASP Top 10, SAST, DAST, software composition analysis, container security, infrastructure-as-code security, CI/CD security, and API security.
- Experience securing cloud-native environments, particularly AWS and Azure.
- Strong stakeholder management, communication, influencing, leadership, coaching, and mentoring skills.
Benefits
- Flexible working hours that allow employees to adjust their schedules during the day.
- Wellbeing initiatives, shared parental leave, study assistance, and sabbaticals.
- Country-specific benefits and support for workplace accommodations during the hiring process.
About RELX
RELX provides information-based analytics, research content, and decision tools for scientists, legal and risk professionals, insurers, and governments. Through segments including Elsevier (STM), LexisNexis (legal and risk), and RX (exhibitions), it sells subscriptions, data services, and software platforms used in 180+ countries. Headquartered in London, it is a public company listed in London and Amsterdam.