×
Register Here to Apply for Jobs or Post Jobs. X

Lead Application Security Engineer, IT Security

Job in Saint Petersburg, Pinellas County, Florida, 33747, USA
Listing for: Raymond James Financial, Inc.
Part Time position
Listed on 2026-08-02
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security & Data Protection
Job Description & How to Apply Below
** This position follows a hybrid work model, with an expectation to be in the office 3 days per week at the St. Petersburg, FL Corporate Office location.*
* ** _

Please note:

This role is not eligible for Work Visa sponsorship, either currently or in the future._*
* ** Responsibilities*
* + Lead application security engineering activities across web applications, APIs, mobile applications, cloud-native services, containers, and supporting platforms.

+ Embed security controls throughout the software development lifecycle (SDLC), including requirements, architecture, design, development, build, test, release, and post-production monitoring.

+ Design, implement, tune, and govern automated security testing in CI/CD pipelines, including static application security testing (SAST), dynamic application security testing (DAST), interactive application security testing (IAST), software composition analysis (SCA), secrets detection, infrastructure-as-code scanning, container image scanning, API security testing, and mobile application testing.

+ Develop reusable automation, integrations, and security-as-code using Python, Power Shell, JavaScript, shell scripting, APIs, webhooks, and pipeline platforms to reduce manual effort and improve control coverage.

+ Build automated workflows that normalize, correlate, enrich, deduplicate, prioritize, ticket, route, retest, and close application vulnerability findings across security tools and engineering systems.

+ Leverage AI-assisted application vulnerability analysis to summarize evidence, identify code-to-vulnerability relationships, propose test cases, prioritize likely exploit paths, explain findings to developers, and draft remediation guidance.

+ Evaluate and govern AI-assisted security capabilities for accuracy, privacy, data handling, prompt-injection resistance, model and supply-chain risk, reproducibility, auditability, and human oversight; measure false-positive, false-negative, and remediation-quality outcomes.

+ Perform manual and tool-assisted application and API security assessments, validate exploitability, eliminate false positives, create proof-of-concept evidence when appropriate, and provide clear, actionable remediation guidance.

+ Lead application threat modeling and architecture risk reviews using practical methods such as abuse cases, data-flow analysis, trust-boundary analysis, and attack-path modeling.

+ Partner with software engineers, architects, product owners, Dev Ops/platform teams, cloud teams, and risk stakeholders to translate security requirements into pragmatic engineering solutions.

+ Develop and maintain secure coding standards, reusable security patterns, guardrails, reference implementations, and developer enablement materials aligned with OWASP guidance and recognized industry practices.

+ Create risk-based service-level objectives and prioritization models that account for exploitability, reachability, business criticality, data sensitivity, compensating controls, threat intelligence, and exposure.

+ Define and report meaningful program metrics, including coverage, control adoption, vulnerability aging, recurrence, escape rate, mean time to remediate, automation effectiveness, and risk reduction.

+ Conduct root-cause analysis for recurring vulnerability classes and drive systemic prevention through framework changes, paved-road patterns, automated controls, and targeted education.

+ Serve as a technical escalation point for complex application vulnerabilities and major cybersecurity incidents; participate in an on-call rotation as required.

+ Mentor application security engineers and developers, contribute to technical strategy and roadmaps, and remain current with emerging attack techniques, defensive technologies, and AI-enabled software development risks.

** Qualifications*
* ** Knowledge, Skills, and Abilities:*
* + Demonstrated expertise identifying, validating, explaining, and remediating application and API vulnerabilities, including vulnerability classes represented in the OWASP Top 10 and OWASP API Security Top 10.

+ Advanced understanding of authentication, authorization, session management, cryptography, input handling, deserialization, server-side request forgery, business-logic abuse, and modern client/server attack surfaces.

+ Hands-on experience with SAST, DAST, IAST, SCA, API testing, secrets detection, container scanning, infrastructure-as-code scanning, and penetration-testing tools; ability to tune controls and validate tool output rather than rely solely on scanner severity.

+ Strong automation and software engineering capability in Python and at least one of Power Shell, JavaScript/Type Script, Go, Java, C#, or shell; experience consuming REST/GraphQL APIs, processing structured data, writing tests, and maintaining production-quality code.

+ Experience integrating security tools with CI/CD and engineering platforms such as Git Hub, Git Lab, Azure Dev Ops, Jenkins, Jira, or comparable technologies.

+ Demonstrated experience applying…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary