Lead Application Security Engineer

Posted 3 Days Ago
Be an Early Applicant
St. Petersburg, FL, USA
In-Office
Senior level
Financial Services
The Role
Leads application security engineering across web, API, mobile, cloud-native, container, and CI/CD environments. Designs automated security testing and vulnerability-management workflows, performs threat modeling and manual assessments, validates exploitability, and provides remediation guidance. Partners with engineering and cloud teams to embed secure development practices, applies AI-assisted vulnerability analysis, supports cybersecurity incidents, mentors engineers, and drives application security strategy.
Summary Generated by Built In

Job Description Summary

The financial services industry is continuously targeted by sophisticated cyber adversaries ranging from criminal organizations to nation-state actors. Raymond James relies on the Cyber Threat Center (CTC) to identify, assess, and reduce technology risk across the enterprise. The Lead Application Security Engineer will be a hands-on technical leader responsible for integrating security into the software development lifecycle, assessing application and API risk, and enabling development teams to deliver resilient software at scale.
This role combines application security engineering, software security assessment, vulnerability analysis, secure software development practices, and cybersecurity architecture. The engineer will build and automate security controls across CI/CD pipelines; perform risk-based testing and threat modeling; and responsibly apply AI-assisted techniques to accelerate vulnerability discovery, triage, validation, and remediation

Job Description

This position follows a hybrid work model, with an expectation to be in the office 3 days per week at the St. Petersburg, FL Corporate Office location.


Please note: This role is not eligible for Work Visa sponsorship, either currently or in the future.


Responsibilities:

  • Lead application security engineering activities across web applications, APIs, mobile applications, cloud-native services, containers, and supporting platforms.
  • Embed security controls throughout the software development lifecycle (SDLC), including requirements, architecture, design, development, build, test, release, and post-production monitoring.
  • Design, implement, tune, and govern automated security testing in CI/CD pipelines, including static application security testing (SAST), dynamic application security testing (DAST), interactive application security testing (IAST), software composition analysis (SCA), secrets detection, infrastructure-as-code scanning, container image scanning, API security testing, and mobile application testing.
  • Develop reusable automation, integrations, and security-as-code using Python, PowerShell, JavaScript, shell scripting, APIs, webhooks, and pipeline platforms to reduce manual effort and improve control coverage.
  • Build automated workflows that normalize, correlate, enrich, deduplicate, prioritize, ticket, route, retest, and close application vulnerability findings across security tools and engineering systems.
  • Leverage AI-assisted application vulnerability analysis to summarize evidence, identify code-to-vulnerability relationships, propose test cases, prioritize likely exploit paths, explain findings to developers, and draft remediation guidance.
  • Perform manual and tool-assisted application and API security assessments, validate exploitability, eliminate false positives, create proof-of-concept evidence when appropriate, and provide clear, actionable remediation guidance.
  • Lead application threat modeling and architecture risk reviews using practical methods such as abuse cases, data-flow analysis, trust-boundary analysis, and attack-path modeling.
  • Partner with software engineers, architects, product owners, DevOps/platform teams, cloud teams, and risk stakeholders to translate security requirements into pragmatic engineering solutions.
  • Develop and maintain secure coding standards, reusable security patterns, guardrails, reference implementations, and developer enablement materials aligned with OWASP guidance and recognized industry practices.
  • Serve as a technical escalation point for complex application vulnerabilities and major cybersecurity incidents; participate in an on-call rotation as required.
  • Mentor application security engineers and developers, contribute to technical strategy and roadmaps, and remain current with emerging attack techniques, defensive technologies, and AI-enabled software development risks.

Knowledge, Skills, and Abilities:

  • Demonstrated expertise identifying, validating, explaining, and remediating application and API vulnerabilities, including vulnerability classes represented in the OWASP Top 10 and OWASP API Security Top 10.
  • Advanced understanding of authentication, authorization, session management, cryptography, input handling, deserialization, server-side request forgery, business-logic abuse, and modern client/server attack surfaces.
  • Hands-on experience with SAST, DAST, IAST, SCA, API testing, secrets detection, container scanning, infrastructure-as-code scanning, and penetration-testing tools; ability to tune controls and validate tool output rather than rely solely on scanner severity.
  • Strong automation and software engineering capability in Python and at least one of PowerShell, JavaScript/TypeScript, Go, Java, C#, or shell; experience consuming REST/GraphQL APIs, processing structured data, writing tests, and maintaining production-quality code.
  • Experience integrating security tools with CI/CD and engineering platforms such as GitHub, GitLab, Azure DevOps, Jenkins, Jira, or comparable technologies.
  • Demonstrated experience applying AI-assisted or machine-learning-enabled security tooling to source-code review, vulnerability triage, exploit-path analysis, test generation, remediation support, or finding correlation.
  • Experience securing cloud-native applications on Microsoft Azure, Amazon Web Services, and/or Google Cloud Platform, including identity, secrets, workloads, APIs, containers, serverless services, and Kubernetes.
  • Ability to communicate technical risk clearly to developers, architects, executives, auditors, and non-technical stakeholders, and to translate findings into prioritized engineering actions.
  • Ability to lead through influence, exercise sound judgment under uncertainty, mentor others, and balance security outcomes with client and business needs.

Previous Experience:

  • Typically requires 3 or more years of hands-on application security, product security, penetration testing, secure software development, or software security assessment experience.
  • Demonstrated experience developing security automation and integrating application security controls into CI/CD workflows.

Certifications:

One or more of the following certifications, or the ability to obtain a relevant certification within one year, is preferred:

  • GIAC Web Application Penetration Tester (GWAPT), GIAC Certified Web Application Defender (GWEB), or comparable application security certification.
  • Offensive Security Web Expert (OSWE) or comparable advanced assessment certification.
  • AWS, Microsoft Azure, Google Cloud, Kubernetes, or DevSecOps certification relevant to the assigned environment.

Education

High School (HS) (Required)

Work Experience

General Experience - 6 to 10 years

Certifications

Travel

Less than 25%

Workstyle

Hybrid

The total compensation for this position includes base salary or wages, and may include components such as additional compensation (cash or equity), discretionary bonuses, or commissions. This position is eligible for a benefits package that may include medical, dental, and vision; life insurance; critical illness insurance and accident insurance; disability benefits; retirement savings; paid time off (including vacation, holidays, and sick leave); and parental leave.  Eligibility for benefits and specific offerings may vary based on position and employment status. To view more details of the benefits offered, visit Myrjbenefits.com.



At Raymond James our associates use five guiding behaviors (Develop, Collaborate, Decide, Deliver, Improve) to deliver on the firm's core values of client-first, integrity, independence and a conservative, long-term view. 
We expect our associates at all levels to:
•  Grow professionally and inspire others to do the same
•  Work with and through others to achieve desired outcomes
•  Make prompt, pragmatic choices and act with the client in mind
•  Take ownership and hold themselves and others accountable for delivering results that matter
•  Contribute to the continuous evolution of the firm

At Raymond James – as part of our people-first culture, we honor, value, and respect the uniqueness, experiences, and backgrounds of all of our Associates.  When associates bring their best authentic selves, our organization, clients, and communities thrive. The Company is an equal opportunity employer and makes all employment decisions on the basis of merit and business needs. 

#LI-TC1

Skills Required

  • High school diploma or equivalent
  • Typically 3 or more years of hands-on application security, product security, penetration testing, secure software development, or software security assessment experience
  • General work experience of 6 to 10 years
  • Experience developing security automation and integrating application security controls into CI/CD workflows
  • Expertise identifying, validating, explaining, and remediating application and API vulnerabilities, including OWASP Top 10 and OWASP API Security Top 10 vulnerabilities
  • Advanced knowledge of authentication, authorization, session management, cryptography, input handling, deserialization, SSRF, business-logic abuse, and client/server attack surfaces
  • Hands-on experience with SAST, DAST, IAST, SCA, API testing, secrets detection, container scanning, infrastructure-as-code scanning, and penetration-testing tools
  • Strong Python automation and software engineering skills, plus proficiency in at least one of PowerShell, JavaScript/TypeScript, Go, Java, C#, or shell scripting
  • Experience consuming REST or GraphQL APIs, processing structured data, writing tests, and maintaining production-quality code
  • Experience integrating security tools with GitHub, GitLab, Azure DevOps, Jenkins, Jira, or comparable engineering platforms
  • Experience applying AI-assisted or machine-learning-enabled security tooling to code review, vulnerability triage, exploit-path analysis, test generation, remediation, or finding correlation
  • Experience securing cloud-native applications on Microsoft Azure, Amazon Web Services, and/or Google Cloud Platform, including identity, secrets, workloads, APIs, containers, serverless services, and Kubernetes
  • Ability to communicate technical risk to developers, architects, executives, auditors, and non-technical stakeholders
  • Ability to lead through influence, mentor others, exercise sound judgment, and balance security outcomes with business needs
  • GWAPT, GWEB, OSWE, comparable application security certification, or relevant cloud, Kubernetes, or DevSecOps certification
  • Ability to obtain a relevant certification within one year
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: St. Petersburg, FL
14,491 Employees
Year Founded: 1962

What We Do

Founded in 1962 and a public company since 1983, Raymond James Financial, Inc. is a Florida-based diversified holding company providing financial services to individuals, corporations and municipalities through its subsidiary companies engaged primarily in investment and financial planning, in addition to capital markets and asset management. The firm's stock is traded on the New York Stock Exchange (RJF). Through its three broker/dealer subsidiaries, Raymond James Financial has approximately 8,400 financial advisors throughout the United States, Canada and overseas. Total client assets are $1.18 trillion (as of 9/30/2021). Raymond James has been recognized nationally for its community support and corporate philanthropy. The company has been ranked as one of the best in the country in customer service, as a great place to work and as a national leader in support of the arts.

Similar Jobs

Zeta Global Logo Zeta Global

Application Security Engineer

AdTech • Artificial Intelligence • Marketing Tech • Software • Analytics
Easy Apply
Remote or Hybrid
United States
2429 Employees
140K-180K Annually

Comcast Logo Comcast

Senior Account Executive

Digital Media • Information Technology • News + Entertainment
Hybrid
Orlando, FL, USA
115000 Employees
55K-105K Annually

Tapestry - Coach and Kate Spade Logo Tapestry - Coach and Kate Spade

Lead Supervisor I

eCommerce • Fashion • Retail • Sales • Wearables • Design
Hybrid
West Palm Beach, FL, USA
16000 Employees
17-28 Hourly

Tapestry - Coach and Kate Spade Logo Tapestry - Coach and Kate Spade

Seasonal Stylist - Kate Spade Vineland Outlet Location

eCommerce • Fashion • Retail • Sales • Wearables • Design
Hybrid
Orlando, FL, USA
16000 Employees
15-20 Hourly

Similar Companies Hiring

Granted Thumbnail
Artificial Intelligence • Healthtech • Insurance • Mobile • Financial Services
New York, New York
23 Employees
Hanover Park Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
42 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account