Secure Development Manager
About RicohA global leader in digital services, recognised for innovation, sustainability and a people-first culture. We feature in the Gartner Magic Quadrant, are listed in the Global 100 Most Sustainable Companies, and have been named one of Forbes' World's Best Employers 2025. At Ricoh, we believe people do their best work when they feel valued and supported. We create inclusive workplaces where you can grow, contribute, and make a positive impact while helping to build a more sustainable future.
Find your place. Transform your futureOur purpose is centred on understanding and improving how people work. By focusing on real working experiences, we support individuals to develop their skills, realise their potential and do work that feels meaningful.
People transform when they Love What They DoThis belief sits at the heart of The Ricoh Promise. It guides how we recruit, how we support our people, and how we work together every day, creating an environment where you can grow, feel valued and make a difference.
When you join us, you are encouraged to share your ideas, challenge the way things are done, and work with others to build something better. If you are looking for a place where your voice is heard, your development is supported, and your work feels meaningful, you will feel at home at Ricoh.#Ricoh-EuropeWhat you will be doingAs a Secure Development Specialist, you'll help drive a measurable shift-left approach to security, ensuring security is considered from the earliest stages of design and development rather than being treated as an afterthought.
Working across engineering, architecture, product and cyber security teams, you'll develop and improve secure software development lifecycle (SDLC) practices, standards and governance. You'll combine strong technical knowledge with the ability to influence and guide teams, helping make secure development practical, scalable and embedded into everyday delivery.
This is an excellent opportunity for someone with a background in software engineering, application security or DevSecOps who wants to make a broader impact across a large, complex European organisation.
Your responsibilities will include:
Developing and maintaining secure SDLC policies, standards, processes and guidance.
Helping define and embed a consistent SDLC operating model across multiple European entities.
Championing secure development frameworks, including NIST SSDF, and aligning practices with OWASP SAMM, ASVS and internal security requirements.
Defining secure development baselines, reusable controls and secure design patterns.
Embedding security controls into CI/CD pipelines and DevOps workflows.
Supporting engineering teams to integrate security requirements early into design and delivery.
Defining security quality gates and acceptance criteria.
Leading or supporting threat modelling, security reviews and risk assessments for key platforms and services. Translating technical risks into practical, actionable security requirements.
Providing security input into architectural decisions, patterns and reference designs.
Supporting privacy and regulatory considerations, including input into DPIA requirements and secure design activities.
Establishing and contributing to a Secure Development Community of Practice, supporting knowledge sharing and capability development across the organisation.
Supporting the integration and effective use of application security tooling, including SAST, DAST and SCA.Monitoring SDLC maturity and identifying opportunities for continuous improvement.
You will ideally haveYou'll be a technically credible security professional who can work effectively with developers, engineers, architects and product teams. You'll have strong experience in areas such as: Secure software development lifecycle practices and governance.
Agile, DevOps and modern software delivery methodologies.
Application security and common vulnerability classes, including the OWASP Top 10.Threat modelling methodologies, such as STRIDE.DevSecOps and integrating security controls into CI/CD pipelines.
Application security tooling, including SAST, DAST and Software Composition Analysis (SCA).Secure coding principles and the ability to engage with at least one major programming language ecosystem. API, microservices and distributed application security.
Software supply chain security and dependency management.
Identity, authentication and cryptographic controls.
Cloud security fundamentals across Azure and/or AWS.Security frameworks such as NIST SSDF, OWASP SAMM and ASVS.You'll also be comfortable analysing complex technical environments, balancing risk against practical delivery requirements and translating security requirements into actions that engineering teams can implement.
In return for your commitment, you can expectAt Ricoh, work should feel meaningful, supportive and fulfilling. The Ricoh Promise shapes your experience through four pillars that bring our culture to life.
Love to ConnectYou become part of a global community built on openness, inclusion and genuine collaboration.
Across teams, countries and roles, you'll find people who listen, involve and encourage you - helping you feel valued and able to be yourself every day. Love to GrowYour development truly matters to us. With access to learning pathways, mentoring and career opportunities across functions and countries, you'll be supported to stretch your skills, explore new directions and stay future-ready in a changing world.
Love to Give BackPurpose is part of how we work. You'll have opportunities to make a difference through volunteering, sustainability initiatives and community programmes that reflect our shared values and commitment to positive impact. Love to SucceedSuccess at Ricoh is something we pursue together. You'll benefit from fair rewards, flexible working, wellbeing resources and real recognition - including programmes such as the Imagine. Change. Awards, where colleagues celebrate each other's achievements.
We are an equal opportunities employerWe believe that diverse perspectives make us stronger, and we welcome applications from people of all backgrounds, identities, and experiences. Our hiring decisions are based on skills, experience and potential, and we are committed to creating a fair and inclusive recruitment process. If you require any reasonable adjustments at any stage of the recruitment journey, please let us know and we will support you to bring your best self forward. Ready to love what you do? Apply now and help us shape what comes next.
Job SummaryJob number: RE02690Profession: Information TechnologyEmployment type: Full time