At a Glance
- Tasks: Build secure applications and enhance CI/CD pipelines with innovative security practices.
- Company: Join a global leader in information and analytics, making a real impact in healthcare.
- Benefits: Enjoy flexible hours, wellbeing initiatives, and support for your personal and professional growth.
- Other info: Work-life balance is a priority, with opportunities for study assistance and sabbaticals.
- Why this job: Shape the future of secure software delivery while collaborating with talented teams.
- Qualifications: 5+ years in application security or software engineering; strong collaboration and problem-solving skills.
Are you a software engineer who is passionate about building secure applications with an interest in moving into application security? Do you enjoy collaborating with engineering teams to drive practical, secure-by-design solutions that reduce risk and improve delivery outcomes?
About the Role
As a Senior Application Security Engineer, you will contribute to strengthening secure software delivery across engineering teams by embedding security practices, tools, and automation into development workflows. This role focuses on enabling teams to build secure applications and CI/CD pipelines through practical guidance, reusable solutions, and improved processes. You will work across teams to reduce risk, improve reliability, and support secure-by-default delivery at scale.
Responsibilities
- Partner with development teams to improve secure software delivery practices across applications and CI/CD pipelines
- Support triage and remediation of application security findings through practical guidance and secure refactoring recommendations
- Facilitate threat modelling activities and translate outcomes into actionable improvements and risk reduction measures
- Design and maintain secure-by-default delivery patterns, reusable templates, and reference implementations
- Support adoption of centrally managed tooling and automated security controls
- Develop integrations and automation to enable security validation, audit evidence generation, and operational metrics
- Collaborate with platform, architecture, and security teams to improve processes, tooling, and delivery capabilities
- Communicate security guidance, standards, and best practices to stakeholders
Requirements
- Experience in application security, software engineering, or product security
- Knowledge of application security principles, common vulnerabilities, and secure coding practices across multiple technology stacks
- 5+ years of application security, software engineering, or product security experience. BS Engineering/Computer Science or equivalent experience required.
- Understanding of CI/CD security, including pipeline controls, identity and access management, and secrets handling
- Experience integrating automated security tooling into software delivery workflows
- Experience developing reusable templates, standards, and reference implementations
- Familiarity with security automation, compliance support, and audit evidence generation
- Awareness of industry security standards and best practices
- Strong collaboration, communication, analytical, troubleshooting, and problem-solving skills
Work in a way that works for you
We promote a healthy work/life balance across the organization. We offer an appealing working prospect for our people. With numerous wellbeing initiatives, shared parental leave, study assistance and sabbaticals, we will help you meet your immediate responsibilities and your long-term goals.
Working flexible hours - flexing the times when you work in the day to help you fit everything in and work when you are the most productive.
About the Business
A global leader in information and analytics, we help researchers and healthcare professionals advance science and improve health outcomes for the benefit of society. Building on our publishing heritage, we combine quality information and vast data sets with analytics to support visionary science and research, health education and interactive learning, as well as exceptional healthcare and clinical practice. At Elsevier, your work contributes to the world's grand challenges and a more sustainable future. We harness innovative technologies to support science and healthcare to partner for a better world.
We are committed to providing a fair and accessible hiring process. If you have a disability or other need that requires accommodation or adjustment, please let us know by completing our Applicant Request Support Form or please contact 1-855-833-5120.
We are an equal opportunity employer: qualified applicants are considered for and treated during employment without regard to race, color, creed, religion, sex, national origin, citizenship status, disability status, protected veteran status, age, marital status, sexual orientation, gender identity, genetic information, or any other characteristic protected by law.
Please read our Candidate Privacy Policy.
Senior Application Security Engineer in Oxford employer: RELX Group plc
At Elsevier, we pride ourselves on being an excellent employer, offering a dynamic work culture that prioritises collaboration and innovation in the field of application security. Our commitment to employee growth is evident through our flexible working hours, numerous wellbeing initiatives, and opportunities for professional development, ensuring that you can thrive both personally and professionally while contributing to meaningful advancements in science and healthcare.