Ricoh Europe
Application Security Consultant

How your CV stacks up
Upload your CV to see how well it fits this job role
?%
About Ricoh
A global leader in digital services, recognised for innovation, sustainability and a people-first culture. We feature in the Gartner Magic Quadrant, are listed in the Global 100 Most Sustainable Companies, and have been named one of Forbes’ World’s Best Employers 2025. At Ricoh, we believe people do their best work when they feel valued and supported. We create inclusive workplaces where you can grow, contribute, and make a positive impact while helping to build a more sustainable future.
Find your place. Transform your future
Our purpose is centred on understanding and improving how people work. By focusing on real working experiences, we support individuals to develop their skills, realise their potential and do work that feels meaningful. People transform when they Love What They Do
This belief sits at the heart of The Ricoh Promise. It guides how we recruit, how we support our people, and how we work together every day, creating an environment where you can grow, feel valued and make a difference. When you join us, you are encouraged to share your ideas, challenge the way things are done, and work with others to build something better. If you are looking for a place where your voice is heard, your development is supported, and your work feels meaningful, you will feel at home at Ricoh.
We're looking for an Application Security Consultant to join our Cyber, Risk & Security team and play a key role in strengthening application security across Ricoh Europe. This is an opportunity to work at the intersection of software engineering, cybersecurity and risk, helping our teams adopt a genuine shift-left approach and making security part of the development lifecycle from design through to deployment.
You'll work across both our internal IT environment and customer-facing products and services, helping protect solutions that are used by thousands of people every day and supporting the security of products delivered to customers across Europe. #Ricoh-Europe
What you will be doing
As our Application Security Consultant, you'll act as a technical authority and trusted advisor to engineering and product teams.
You'll:
- Lead application security reviews for high-risk products and services.
- Conduct and oversee SAST, DAST, API security, fuzz testing and architecture-level assessments.
- Assess applications against the OWASP Top 10 and other relevant security standards.
- Identify vulnerabilities, understand their root causes and translate findings into practical remediation plans.
- Provide secure design and coding guidance throughout the development lifecycle.
- Help establish and evolve a pan-European Application Security capability within our Secure Development Centre of Excellence.
- Develop and promote consistent application security methodologies, standards and best practices.
- Support secure coding standards across technologies including Java, C, C++ and other relevant languages.
- Integrate security controls and automated testing into CI/CD pipelines, including SAST, DAST and SCA.
- Support threat modelling and vulnerability management across products and services.
- Work closely with developers, architects, DevOps teams and product owners to embed security into their everyday workflows.
- Deliver security awareness sessions, secure coding workshops and practical training for development teams.
- Help shape our approach to secure AI development, including risks around AI models, data handling and misuse.
- Monitor emerging application security threats and recommend improvements to our processes, tooling and development practices.
Reasons to use Rodeo
I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?
Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.
Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.
Start with a chat, not a search bar
Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.
Graduate Consultant — 2026 Scheme
Why you're a good match
StrongYour economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.
See breakdownIt searches the market for you
Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.
Why you're a good match
You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.
Experience fit
Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.
Only hits
No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.
This is more than finding vulnerabilities
We're looking for someone who can go beyond identifying a security issue and explain why it matters, how it happened and what we can do differently next time. You'll need to be comfortable challenging established practices while building strong relationships with engineering teams. Your ability to translate complex security concepts into practical, developer-friendly guidance will be just as important as your technical expertise. You'll have the opportunity to influence security practices across multiple teams and geographies, helping create a more consistent and mature approach to secure development across Ricoh Europe.
You will ideally have
You'll bring a strong software engineering and application security foundation, with:
- Extensive experience in application security, secure development or software engineering with a security focus.
- Hands-on experience conducting application security reviews.
- Strong knowledge of application security principles and common vulnerability classes.
- Experience with SAST, DAST and Software Composition Analysis (SCA) tools.
- Experience implementing security within CI/CD and DevSecOps environments.
- The ability to read and understand code in at least one major language such as Java, C, C++, C#, Python or similar.
- Knowledge of secure software development lifecycles and shift-left security practices.
- Experience with threat modelling, such as STRIDE or similar approaches.
- Understanding of application, API and web security.
- Experience interpreting security findings, identifying false positives and prioritising genuine risk.
- The ability to communicate technical vulnerabilities clearly and turn them into actionable recommendations.
- Strong stakeholder management skills, with confidence working with engineers, architects and product owners.
- An understanding of how technical vulnerabilities translate into business, regulatory, financial and reputational risk.


Get help with your application
Your very own career expert that helps elevate your application to the next level.
Desired:
- Experience with fuzz testing, advanced dynamic testing or manual code review.
- Experience securing APIs, microservices or distributed systems.
- Experience integrating SAST, DAST, SCA or secrets scanning into CI/CD pipelines.
- Knowledge of secure architecture patterns across cloud-native, microservices or serverless environments.
- Awareness of AI security, including model, data and prompt/model manipulation risks.
- Experience delivering developer-focused security training or workshops.
- Knowledge of frameworks such as OWASP SAMM, ASVS, NIST CSF or NIST SSDF.
- Relevant application security, cloud security or offensive security certifications.
- Experience working across multiple teams, countries or business entities.
In return for your commitment, you can expect
At Ricoh, work should feel meaningful, supportive and fulfilling. The Ricoh Promise shapes your experience through four pillars that bring our culture to life.
Love to Connect
You become part of a global community built on openness, inclusion and genuine collaboration. Across teams, countries and roles, you'll find people who listen, involve and encourage you - helping you feel valued and able to be yourself every day.
Love to Grow
Your development truly matters to us. With access to learning pathways, mentoring and career opportunities across functions and countries, you'll be supported to stretch your skills, explore new directions and stay future-ready in a changing world.
Love to Give Back
Purpose is part of how we work. You'll have opportunities to make a difference through volunteering, sustainability initiatives and community programmes that reflect our shared values and commitment to positive impact.
Love to Succeed
Success at Ricoh is something we pursue together. You'll benefit from fair rewards, flexible working, wellbeing resources and real recognition - including programmes such as the Imagine. Change. Awards, where colleagues celebrate each other's achievements.
We are an equal opportunities employer
We believe that diverse perspectives make us stronger, and we welcome applications from people of all backgrounds, identities, and experiences. Our hiring decisions are based on skills, experience and potential, and we are committed to creating a fair and inclusive recruitment process. If you require any reasonable adjustments at any stage of the recruitment journey, please let us know and we will support you to bring your best self forward. Ready to love what you do? Apply now and help us shape what comes next.
“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”
Jessica, London
Skills
Location