Lead Application Security Engineer, IT Security
Listed on 2026-08-14
-
IT/Tech
Cybersecurity, Information Security & Data Protection
Job Description Summary
The financial services industry is continuously targeted by sophisticated cyber adversaries ranging from criminal organizations to nation-state actors. Raymond James relies on the Cyber Threat Center (CTC) to identify, assess, and reduce technology risk across the enterprise. The Lead Application Security Engineer will be a hands-on technical leader responsible for integrating security into the software development lifecycle, assessing application and API risk, and enabling development teams to deliver resilient software s role combines application security engineering, software security assessment, vulnerability analysis, secure software development practices, and cybersecurity architecture.
The engineer will build and automate security controls across CI/CD pipelines; perform risk-based testing and threat modeling; and responsibly apply AI-assisted techniques to accelerate vulnerability discovery, triage, validation, and remediation.
Job Description
This position follows a hybrid work model, with an expectation to be in the office 3 days per week at the St. Petersburg, FL Corporate Office location.
Please note:
This role is not eligible for Work Visa sponsorship, either currently or in the future.
Responsibilities
- Lead application security engineering activities across web applications, APIs, mobile applications, cloud-native services, containers, and supporting platforms.
- Embed security controls throughout the software development lifecycle (SDLC), including requirements, architecture, design, development, build, test, release, and post-production monitoring.
- Design, implement, tune, and govern automated security testing in CI/CD pipelines, including static application security testing (SAST), dynamic application security testing (DAST), interactive application security testing (IAST), software composition analysis (SCA), secrets detection, infrastructure-as-code scanning, container image scanning, API security testing, and mobile application testing.
- Develop reusable automation, integrations, and security-as-code using Python, Power Shell, JavaScript, shell scripting, APIs, webhooks, and pipeline platforms to reduce manual effort and improve control coverage.
- Build automated workflows that normalize, correlate, enrich, deduplicate, prioritize, ticket, route, retest, and close application vulnerability findings across security tools and engineering systems.
- Leverage AI-assisted application vulnerability analysis to summarize evidence,identifycode-to-vulnerability relationships, propose test cases, prioritizelikely exploitpaths, explain findings to developers, and draft remediation guidance.
- Evaluate and govern AI-assisted security capabilities for accuracy, privacy, data handling, prompt-injection resistance, model and supply-chain risk, reproducibility, auditability, and human oversight; measure false-positive, false-negative, and remediation-quality outcomes.
- Perform manual and tool-assisted application and API security assessments,validateexploitability,eliminatefalse positives, create proof-of-concept evidence when appropriate, and provide clear, actionable remediation guidance.
- Lead application threat modeling and architecture risk reviews using practical methods such as abuse cases, data-flow analysis, trust-boundary analysis, and attack-path modeling.
- Partner with software engineers, architects, product owners, Dev Ops/platform teams, cloud teams, and risk stakeholders to translate security requirements into pragmatic engineering solutions.
- Develop andmaintainsecure coding standards, reusable security patterns, guardrails, reference implementations, and developer enablement materials aligned with OWASP guidance and recognized industry practices.
- Create risk-based service-levelobjectivesand prioritization models that account for exploitability, reachability, business criticality, data sensitivity, compensating controls, threat intelligence, and exposure.
- Define and report meaningful program metrics, including coverage, control adoption, vulnerability aging, recurrence, escape rate, mean time to remediate, automation effectiveness, and risk reduction.
- Conduct root-cause analysis for recurring vulnerability classes and drive systemic prevention through framework changes, paved-road patterns, automated controls, and targeted education.
- Serve as a technical escalation point for complex application vulnerabilities and major cybersecurity incidents;participate in an on-call rotation as required.
- Mentor application security engineers and developers, contribute to technical strategy and roadmaps, and remain current with emerging attack techniques, defensive technologies, and AI-enabled software development risks.
Qualifications
Knowledge, Skills, and Abilities:
- Demonstratedexpertiseidentifying,validating, explaining, and remediating application and API vulnerabilities, including vulnerability classes represented in the OWASP Top 10 and OWASP API Security Top 10.
- Advanced understanding of authentication,…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).