Lead Application Security Engineer
Washington, District of Columbia, 20022, USA
Listed on 2026-10-03
-
IT/Tech
Cybersecurity, Systems Engineer
Work from Home;
Charlotte, NC (North Carolina);
Fort Wayne, IN (Indiana);
Greensboro, NC (North Carolina);
Radnor, PA (Pennsylvania)
Remote :
Work at home employee residing outside of a commutable distance to an office location.
is not available for this opportunity.
Requisition #: 76525
The Role at a GlanceThe Lead Application Security Engineer is responsible for working with application development and infrastructure teams to ensure applications are designed, coded, and implemented securely. You will be responsible for Integrating security best practices and controls into all phases of the Software Development Lifecycle (SDLC), including requirements, design, development, testing, deployment, and maintenance.
You will drive the improvement of policies, standards, and other supporting documentation. This is a hands-on technical position that you will find yourself collaborating with multiple groups across the organization. Strong communication skills are needed to explain complex security to a wide variety of technical levels. Experience as a developer is helpful, but not required.
What you'll be doing- Responsibility for the security of Lincoln Financial applications and services
- Conduct design review, code review, and dynamic analysis
- Evaluate the security posture of AI/ML systems, including LLM-integrated applications, RAG pipelines, and agentic workflows
- Identify, communicate, and drive the resolution of vulnerabilities
- Serve as a subject matter expert for application development and infrastructure teams
- Communicate effectively with a wide variety of technical levels
- Perform security assessments of web and mobile applications
- Research and advocate for new security solutions and technologies
- Stay current on security trends, vulnerabilities, and testing methods
- Contribute to related policies, standards, and supporting documentation
- Undergraduate degree or 4+ years of comparable work experience
- 5-7+ years of experience in Information Technology that directly aligns with the specific responsibilities for this position
- Extensive experience in web application security
- Strong knowledge of application security throughout the SDLC
- Experience with agile delivery practices
- Experience integrating security into Dev Ops practices.
- Experience conducting source code review preferred
- Experience using static application security testing tools such as Fortify, Checkmarx, Veracode, etc.
- Experience dynamic analysis with tools such as App Scan, Web inspect, Burp Suite, and OWASP ZAP, etc.
- Familiarity with related network infrastructure, such as firewalls, WAFs, and IPS
- Familiarity with common DMZ architectures
- Prior financial services experience preferred
- Agile Mindset; awareness/understanding of Agile methodologies
- OSCP, OSWE, ISC2 CISSP, CSSLP, GIAC GWAPT, GIAC GSSP-Java, GIAC GSSP-NET Preferred
Applications will be accepted through October 31, 2026, and the posting may be taken down early due to applicant volume.
What's it like to work here?At Lincoln Financial, we love what we do. We make meaningful contributions each and every day to empower our customers to take charge of their lives. Working alongside dedicated and talented colleagues, we build fulfilling careers and stronger communities through a company that values our unique perspectives, insights and contributions and invests in programs that empower each of us to take charge of our own future.
What'sin it for you
- Clearly defined career tracks and job levels, along with associated behaviors for each of Lincoln's core values and leadership attributes
- Leadership development and virtual training opportunities
- PTO/parental leave
- Competitive 401K…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).