Consulting/Principal Security Engineer
AI summary of the role
This is a senior/principal-level security engineering role focused on shaping application security strategy, with a strong emphasis on AI/LLM security.
No longer in the current catalog. Last included 2026-09-09. Check the employer’s posting for availability.
What you’ll do
- Provide strategic and tactical technical guidance on security across the organization
- Design and evolve the secure software development lifecycle including threat modeling and security tooling integration
- Lead security reviews and threat modeling for AI-powered features (LLMs, RAG pipelines, agentic workflows)
- Define internal standards for building AI-integrated applications responsibly
What you’ll bring
- 7+ years in application security or security-focused software engineering
- Real experience with threat modeling (STRIDE, PASTA, etc.) applied to complex distributed systems
- Hands-on experience embedding SAST, DAST, SCA, and secrets scanning into developer workflows
- Coding ability in Python, Java, Go, TypeScript or similar for security code review and automation
Technologies
SAST · DAST · SCA · secrets detection · CI/CD · STRIDE · PASTA · Python · Java · Go · TypeScript · AWS
About RELX
Provides analytics, decision tools, and workflow products for legal, risk, scientific, health, and events customers, built on proprietary data and trusted content.
Public · 5000+ people
Source and classification
Internal deployment & tooling · Evidence for this classification:
What You’ll Actually Be Doing Setting Direction, Not Just Following It Provide strategic and tactical technical guidance that shapes how we approach security across the organization — with real input into leadership decisions Research emerging threats, new attack techniques, and novel mitigation approaches, then translate that research into actionable guidance before those threats hit our doorstep Own escalations that require deep expertise — you’re the person the team calls when things get interesting Secure SDLC & AppSec Program Design and evolve our secure software development lifecycle — threat modeling, security design reviews, developer enablement, and the toolchain that ties it all together Integrate modern security tooling (SAST, DAST, SCA, secrets detection) into CI/CD pipelines in ways engineers actually embrace rather than route around Build and run security champions
More from the job description
What You’ll Actually Be Doing Setting Direction, Not Just Following It Provide strategic and tactical technical guidance that shapes how we approach security across the organization — with real input into leadership decisions Research emerging threats, new attack techniques, and novel mitigation approaches, then translate that research into actionable guidance before those threats hit our doorstep Own escalations that require deep expertise — you’re the person the team calls when things get interesting Secure SDLC & AppSec Program Design and evolve our secure software development lifecycle — threat modeling, security design reviews, developer enablement, and the toolchain that ties it all together Integrate modern security tooling (SAST, DAST, SCA, secrets detection) into CI/CD pipelines in ways engineers actually embrace rather than route around Build and run security champions programs that make developers your allies, not your adversaries Track what’s working with real metrics and communicate risk clearly to technical and non-technical audiences alike AI / LLM Security Lead security reviews and threat modeling for AI-powered features — LLMs, RAG pipelines, vector databases, agentic workflows, the works Get hands-on with the OWASP, NIST, and the latest research on prompt injection, model supply chain risks, inference-based data leakage, and insecure tool use Eval [... source excerpt omitted ...] o, TypeScript, etc.) to meaningfully review code for security issues and build lightweight automation Experience working in or alongside a regulated industry with real compliance requirements The ability to write a clear, compelling security finding — and explain it to a VP without losing them Strong collaboration ethos. The security team is an enabler of the business, not a hindrance. Strong Differentiators Practical experience securing AI/ML systems or LLM-integrated applications — this is increasingly central to the role Familiarity with agentic AI security risks: tool misuse, prompt injection chains, privilege escalation via agents Experience building developer security ed
Employer postings · Data from · Sources