IT & Software

Secure Development Manager

Ricoh

London · Greater London · United Kingdom

Overview

As a Secure Development Specialist, you drive a shift-left security approach by embedding security into design and delivery. You’ll align across engineering, architecture, product, and security teams to mature secure SDLC practices and governance across Europe. You influence practical security within DevOps and CI/CD, shaping reusable controls and secure design patterns. This role offers impact at scale within a large European organisation and emphasizes collaboration, learning, and meaningful work.

Pay / Benefits
  • fair rewards
  • flexible working
  • wellbeing resources
  • learning pathways
  • mentoring and career opportunities
  • volunteering and sustainability initiatives
Responsibilities
  • Develop and maintain secure SDLC policies, standards, and guidance
  • Embed a consistent SDLC operating model across multiple European entities
  • Champion secure development frameworks (NIST SSDF) and align with OWASP SAMM, ASVS and internal requirements
  • Define secure development baselines, reusable controls and design patterns
  • Integrate security controls into CI/CD pipelines and DevOps workflows
  • Support engineering teams to incorporate security early in design and delivery
  • Define security quality gates and acceptance criteria
  • Lead or support threat modelling, security reviews and risk assessments
  • Translate risks into actionable security requirements for architects and engineers
  • Provide security input into architectural decisions and reference designs
  • Support privacy/regulatory considerations including DPIA input
  • Establish and contribute to a Secure Development Community of Practice
  • Support integration and effective use of SAST, DAST, and SCA tooling
  • Monitor SDLC maturity and identify opportunities for improvement
Key requirements
  • Background in software engineering, application security or DevSecOps
  • Experience with secure SDLC practices and governance
  • Agile/DevOps and modern software delivery methodologies
  • Knowledge of OWASP Top 10 and threat modelling (e.g., STRIDE)
  • DevSecOps and CI/CD security integration
  • Experience with application security tooling (SAST, DAST, SCA)
  • Secure coding principles and one major programming language ecosystem
  • API, microservices, and distributed application security
  • Software supply chain security and dependency management
  • Identity, authentication, and cryptographic controls
  • Cloud security fundamentals (Azure and/or AWS)
  • Security frameworks such as NIST SSDF, OWASP SAMM, ASVS
  • Effective cross-functional collaboration
  • Ability to translate technical risks into actionable requirements
  • Analytical thinking balanced with practical delivery focus
  • Secure SDLC governance
  • Threat modelling (STRIDE)
  • CI/CD security integration

Reference: WJ-747_30157054

Apply now

Continue on the employer's official application - the same link they use for every candidate.

More jobs

Find more on GigBlows

This role is listed on GigBlows for discovery and search. Hiring decisions and applications are handled by the employer or their chosen application system.