Lead Application Security Engineer, IT Security
Listed on 2026-09-12
-
IT/Tech
Cybersecurity
Job Description Summary
The financial services industry is continuously targeted by sophisticated cyber adversaries ranging from criminal organizations to nation-state actors. Raymond James relies on the Cyber Threat Center (CTC) to identify, assess, and reduce technology risk across the enterprise. The Lead Application Security Engineer will be a hands-on technical leader responsible for integrating security into the software development lifecycle, assessing application and API risk, and enabling development teams to deliver resilient software s role combines application security engineering, software security assessment, vulnerability analysis, secure software development practices, and cybersecurity architecture.
The engineer will build and automate security controls across CI/CD pipelines; perform risk-based testing and threat modeling; and responsibly apply AI-assisted techniques to accelerate vulnerability discovery, triage, validation, and remediation.
Job Description
This position follows a hybrid work model, with an expectation to be in the office 3 days per week at the St. Petersburg, FL Corporate Office location.
Please note:
This role is not eligible for Work Visa sponsorship, either currently or in the future.
Responsibilities
- Lead application security engineering activities across web applications, APIs, mobile applications, cloud-native services, containers, and supporting platforms.
- Embed security controls throughout the software development lifecycle (SDLC), including requirements, architecture, design, development, build, test, release, and post-production monitoring.
- Design, implement, tune, and govern automated security testing in CI/CD pipelines, including static application security testing (SAST), dynamic application security testing (DAST), interactive application security testing (IAST), software composition analysis (SCA), secrets detection, infrastructure-as-code scanning, container image scanning, API security testing, and mobile application testing.
- Develop reusable automation, integrations, and security-as-code using Python, Power Shell, JavaScript, shell scripting, APIs, webhooks, and pipeline platforms to reduce manual effort and improve control coverage.
- Build automated workflows that normalize, correlate, enrich, deduplicate, prioritize, ticket, route, retest, and close application vulnerability findings across security tools and engineering systems.
- Leverage AI-assisted application vulnerability analysis to summarize evidence,identify code-to-vulnerability relationships, propose test cases, prioritize likely exploit paths, explain findings to developers, and draft remediation guidance.
- Evaluate and govern AI-assisted security capabilities for accuracy, privacy, data handling, prompt-injection resistance, model and supply-chain risk, reproducibility, auditability, and human oversight; measure false-positive, false-negative, and remediation-quality outcomes.
- Perform manual and tool-assisted application and API security assessments,validate exploitability,eliminate false positives, create proof-of-concept evidence when appropriate, and provide clear, actionable remediation guidance.
- Lead application threat modeling and architecture risk reviews using practical methods such as abuse cases, data-flow analysis, trust-boundary analysis, and attack-path modeling.
- Partner with software engineers, architects, product owners, Dev Ops/platform teams, cloud teams, and risk stakeholders to translate security requirements into pragmatic engineering solutions.
- Develop andmaintainsecure coding standards, reusable security patterns, guardrails, reference implementations, and developer enablement materials aligned with OWASP guidance and recognized industry practices.
- Create risk-based…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).