Lead Application Security Engineer, IT Security
Job in
Saint Petersburg, Pinellas County, Florida, 33747, USA
Listed on 2026-08-02
Listing for:
Raymond James Financial, Inc.
Part Time
position Listed on 2026-08-02
Job specializations:
-
IT/Tech
Cybersecurity, Information Security & Data Protection
Job Description & How to Apply Below
* ** _
Please note:
This role is not eligible for Work Visa sponsorship, either currently or in the future._*
* ** Responsibilities*
* + Lead application security engineering activities across web applications, APIs, mobile applications, cloud-native services, containers, and supporting platforms.
+ Embed security controls throughout the software development lifecycle (SDLC), including requirements, architecture, design, development, build, test, release, and post-production monitoring.
+ Design, implement, tune, and govern automated security testing in CI/CD pipelines, including static application security testing (SAST), dynamic application security testing (DAST), interactive application security testing (IAST), software composition analysis (SCA), secrets detection, infrastructure-as-code scanning, container image scanning, API security testing, and mobile application testing.
+ Develop reusable automation, integrations, and security-as-code using Python, Power Shell, JavaScript, shell scripting, APIs, webhooks, and pipeline platforms to reduce manual effort and improve control coverage.
+ Build automated workflows that normalize, correlate, enrich, deduplicate, prioritize, ticket, route, retest, and close application vulnerability findings across security tools and engineering systems.
+ Leverage AI-assisted application vulnerability analysis to summarize evidence, identify code-to-vulnerability relationships, propose test cases, prioritize likely exploit paths, explain findings to developers, and draft remediation guidance.
+ Evaluate and govern AI-assisted security capabilities for accuracy, privacy, data handling, prompt-injection resistance, model and supply-chain risk, reproducibility, auditability, and human oversight; measure false-positive, false-negative, and remediation-quality outcomes.
+ Perform manual and tool-assisted application and API security assessments, validate exploitability, eliminate false positives, create proof-of-concept evidence when appropriate, and provide clear, actionable remediation guidance.
+ Lead application threat modeling and architecture risk reviews using practical methods such as abuse cases, data-flow analysis, trust-boundary analysis, and attack-path modeling.
+ Partner with software engineers, architects, product owners, Dev Ops/platform teams, cloud teams, and risk stakeholders to translate security requirements into pragmatic engineering solutions.
+ Develop and maintain secure coding standards, reusable security patterns, guardrails, reference implementations, and developer enablement materials aligned with OWASP guidance and recognized industry practices.
+ Create risk-based service-level objectives and prioritization models that account for exploitability, reachability, business criticality, data sensitivity, compensating controls, threat intelligence, and exposure.
+ Define and report meaningful program metrics, including coverage, control adoption, vulnerability aging, recurrence, escape rate, mean time to remediate, automation effectiveness, and risk reduction.
+ Conduct root-cause analysis for recurring vulnerability classes and drive systemic prevention through framework changes, paved-road patterns, automated controls, and targeted education.
+ Serve as a technical escalation point for complex application vulnerabilities and major cybersecurity incidents; participate in an on-call rotation as required.
+ Mentor application security engineers and developers, contribute to technical strategy and roadmaps, and remain current with emerging attack techniques, defensive technologies, and AI-enabled software development risks.
** Qualifications*
* ** Knowledge, Skills, and Abilities:*
* + Demonstrated expertise identifying, validating, explaining, and remediating application and API vulnerabilities, including vulnerability classes represented in the OWASP Top 10 and OWASP API Security Top 10.
+ Advanced understanding of authentication, authorization, session management, cryptography, input handling, deserialization, server-side request forgery, business-logic abuse, and modern client/server attack surfaces.
+ Hands-on experience with SAST, DAST, IAST, SCA, API testing, secrets detection, container scanning, infrastructure-as-code scanning, and penetration-testing tools; ability to tune controls and validate tool output rather than rely solely on scanner severity.
+ Strong automation and software engineering capability in Python and at least one of Power Shell, JavaScript/Type Script, Go, Java, C#, or shell; experience consuming REST/GraphQL APIs, processing structured data, writing tests, and maintaining production-quality code.
+ Experience integrating security tools with CI/CD and engineering platforms such as Git Hub, Git Lab, Azure Dev Ops, Jenkins, Jira, or comparable technologies.
+ Demonstrated experience applying…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×