Lead Application Security Engineer, IT Security

Raymond James


Job Location:

Pinellas County, FL - USA

Monthly Salary: Not Disclosed
Posted on: 15 hours ago
Vacancies: 1 Vacancy

Job Summary

Job Description Summary

The financial services industry is continuously targeted by sophisticated cyber adversaries ranging from criminal organizations to nation-state actors. Raymond James relies on the Cyber Threat Center (CTC) to identify assess and reduce technology risk across the enterprise. The Lead Application Security Engineer will be a hands-on technical leader responsible for integrating security into the software development lifecycle assessing application and API risk and enabling development teams to deliver resilient software at scale.
This role combines application security engineering software security assessment vulnerability analysis secure software development practices and cybersecurity architecture. The engineer will build and automate security controls across CI/CD pipelines; perform risk-based testing and threat modeling; and responsibly apply AI-assisted techniques to accelerate vulnerability discovery triage validation and remediation

Job Description

This position follows a hybrid work model with an expectation to be in the office 3 days per week at the St. Petersburg FL Corporate Office location.

Please note: This role is not eligible for Work Visa sponsorship either currently or in the future.

Responsibilities

  • Lead application security engineering activities across web applications APIs mobile applications cloud-native services containers and supporting platforms.

  • Embed security controls throughout the software development lifecycle (SDLC) including requirements architecture design development build test release and post-production monitoring.

  • Design implement tune and govern automated security testing in CI/CD pipelines including static application security testing (SAST) dynamic application security testing (DAST) interactive application security testing (IAST) software composition analysis (SCA) secrets detection infrastructure-as-code scanning container image scanning API security testing and mobile application testing.

  • Develop reusable automation integrations and security-as-code using Python PowerShell JavaScript shell scripting APIs webhooks and pipeline platforms to reduce manual effort and improve control coverage.

  • Build automated workflows that normalize correlate enrich deduplicate prioritize ticket route retest and close application vulnerability findings across security tools and engineering systems.

  • LeverageAI-assisted application vulnerability analysis to summarize evidenceidentifycode-to-vulnerability relationships propose test cases prioritizelikely exploitpaths explain findings to developers and draft remediation guidance.

  • Evaluate and govern AI-assisted security capabilities for accuracy privacy data handling prompt-injection resistance model and supply-chain risk reproducibility auditability and human oversight; measure false-positive false-negative and remediation-quality outcomes.

  • Perform manual and tool-assisted application and API security assessmentsvalidateexploitabilityeliminatefalse positives create proof-of-concept evidence whenappropriate and provide clear actionable remediation guidance.

  • Lead application threat modeling and architecture risk reviews using practical methods such as abuse cases data-flow analysis trust-boundary analysis and attack-path modeling.

  • Partner with software engineers architects product owners DevOps/platform teams cloud teams and risk stakeholders to translate security requirements into pragmatic engineering solutions.

  • Develop andmaintainsecure coding standards reusable security patterns guardrails reference implementations and developer enablement materials aligned with OWASP guidance and recognized industry practices.

  • Create risk-based service-levelobjectivesand prioritization models that account for exploitability reachability business criticality data sensitivity compensating controls threat intelligence and exposure.

  • Define and report meaningful program metrics including coverage control adoption vulnerability aging recurrence escape rate mean time to remediate automation effectiveness and risk reduction.

  • Conduct root-cause analysis for recurring vulnerability classes and drive systemic prevention through framework changes paved-road patterns automated controls and targeted education.

  • Serve as a technical escalation point for complex application vulnerabilities and major cybersecurity incidents;participatein an on-call rotation asrequired.

  • Mentor application security engineers and developers contribute to technical strategy and roadmaps and remain current with emerging attack techniques defensive technologies and AI-enabled software development risks.

Qualifications

Knowledge Skills and Abilities:

  • Demonstratedexpertiseidentifyingvalidating explaining and remediating application and API vulnerabilities including vulnerability classes represented in the OWASP Top 10 and OWASP API Security Top 10.

  • Advanced understanding of authentication authorization session management cryptography input handling deserialization server-side request forgery business-logic abuse and modern client/server attack surfaces.

  • Hands-on experience with SAST DAST IAST SCA API testing secrets detection container scanning infrastructure-as-code scanning and penetration-testing tools; ability to tune controls andvalidatetool output rather than rely solely on scanner severity.

  • Strong automation and software engineering capability in Python and at least one of PowerShell JavaScript/TypeScript Go Java C# or shell; experience consuming REST/GraphQLAPIs processing structured data writing tests andmaintainingproduction-quality code.

  • Experience integrating security tools with CI/CD and engineering platforms such as GitHub GitLab Azure DevOps Jenkins Jira or comparable technologies.

  • Demonstratedexperience applying AI-assisted or machine-learning-enabled security tooling to source-code review vulnerability triage exploit-path analysis test generation remediation support or finding correlation.

  • Ability to critically evaluate AI output recognize hallucinations and insecure recommendations protect sensitive source code and data design human-in-the-loop validation andestablishmeasurable quality and governance controls.

  • Knowledge of secure AI-assisted development risks including prompt injection insecure output handling excessive agency sensitive information disclosure model or dependency supply-chain concerns and misuse of generated code.

  • Experience securing cloud-native applications on Microsoft Azure Amazon Web Services and/or Google Cloud Platform including identity secrets workloads APIs containers serverless services and Kubernetes.

  • Working knowledge of threat modeling secure architecture principles softwaresupply-chainsecurity SBOM/VEX concepts artifact integrity dependency governance and provenance or attestation practices.

  • Ability to communicate technical risk clearly to developers architects executives auditors and non-technical stakeholders and to translate findings into prioritized engineering actions.

  • Ability to lead through influence exercise sound judgment under uncertainty mentor others and balance security outcomes with client and business needs.

Education/Previous Experience:

  • Typically requires aBachelors degree in computer science software engineering cybersecurity information systems or a related field and 5 or more years of relevant experience; an equivalent combination of education training and experience may be considered.

  • Typically requires 3 or more years of hands-on application security product security penetration testing secure software development or software security assessment experience.

  • Demonstratedexperience developing security automation and integrating application security controls into CI/CD workflows.

  • Practical experience using AI-assisted capabilities for application vulnerability analysis with evidence of validation governance and measurable improvement in security outcomes.

  • One or more of the following certifications or the ability to obtain a relevant certification within one year is preferred:

  • GIACWeb Application Penetration Tester (GWAPT) GIAC Certified Web Application Defender (GWEB) or comparable application security certification.

  • Offensive SecurityWeb Expert (OSWE) or comparable advanced assessment certification.

  • AWS Microsoft Azure Google Cloud Kubernetes orDevSecOpscertification relevant to the assigned environment.

Education

Bachelors: Information Technology Bachelors (Required)

Work Experience

General Experience - 6 to 10 years

Certifications

Travel

Workstyle

Hybrid

The total compensation for this position includes base salary or wages and may include components such as additional compensation (cash or equity) discretionary bonuses or commissions. This position is eligible for a benefits package that may include medical dental and vision; life insurance; critical illness insurance and accident insurance; disability benefits; retirement savings; paid time off (including vacation holidays and sick leave); and parental leave. Eligibility for benefits and specific offerings may vary based on position and employment status. To view more details of the benefits offered visit .

At Raymond James our associates use five guiding behaviors (Develop Collaborate Decide Deliver Improve) to deliver on the firms core values of client-first integrity independence and a conservative long-term view.

We expect our associates at all levels to:
Grow professionally and inspire others to do the same
Work with and through others to achieve desired outcomes
Make prompt pragmatic choices and act with the client in mind
Take ownership and hold themselves and others accountable for delivering results that matter
Contribute to the continuous evolution of the firm

At Raymond James as part of our people-first culture we honor value and respect the uniqueness experiences and backgrounds of all of our Associates. When associates bring their best authentic selves our organization clients and communities thrive. The Company is an equal opportunity employer and makes all employment decisions on the basis of merit and business needs.


Required Experience:

IC

Job Description SummaryThe financial services industry is continuously targeted by sophisticated cyber adversaries ranging from criminal organizations to nation-state actors. Raymond James relies on the Cyber Threat Center (CTC) to identify assess and reduce technology risk across the enterprise. Th...

About Company

A full-service financial firm where progress is driven by connection, delivering extensive wealth management, banking and capital markets capabilities to help clients, institutions and communities reach their goals.

View Profile View Profile