Lead Application Security Engineer, IT Security
Raymond James Financial
- Location
- Remote
- Work model
- Hybrid
- Level
- Senior
- Posted
- 5h ago
Skills
About this role
Job Description
Summary The financial services industry is continuously targeted by sophisticated cyber adversaries ranging from criminal organizations to nation-state actors. Raymond James relies on the Cyber Threat Center (CTC) to identify, assess, and reduce technology risk across the enterprise. The Lead Application Security Engineer will be a hands-on technical leader responsible for integrating security into the software development lifecycle, assessing application and API risk, and enabling development teams to deliver resilient software at scale. This role combines application security engineering, software security assessment, vulnerability analysis, secure software development practices, and cybersecurity architecture. The engineer will build and automate security controls across CI/CD pipelines; perform risk-based testing and threat modeling; and responsibly apply AI-assisted techniques to accelerate vulnerability discovery, triage, validation, and remediation Job Description This position follows a hybrid work model, with an expectation to be in the office 3 days per week at the St. Petersburg, FL Corporate Office location. Please note: This role is not eligible for Work Visa sponsorship, either currently or in the future.
Responsibilities
Lead application security engineering activities across web applications, APIs, mobile applications, cloud-native services, containers, and supporting platforms. Embed security controls throughout the software development lifecycle (SDLC), including requirements, architecture, design, development, build, test, release, and post-production monitoring. Design, implement, tune, and govern automated security testing in CI/CD pipelines, including static application security testing (SAST), dynamic application security testing (DAST), interactive application security testing (IAST), software composition analysis (SCA), secrets detection, infrastructure-as-code scanning, container image scanning, API security testing, and mobile application testing. Develop reusable automation, integrations, and security-as-code using Python, PowerShell, JavaScript, shell scripting, APIs, webhooks, and pipeline platforms to reduce manual effort and improve control coverage. Build automated workflows that normalize, correlate, enrich, deduplicate, prioritize, ticket, route, retest, and close application vulnerability findings across security tools and engineering systems. Leverage AI-assisted application vulnerability analysis to summarize evidence, identify code-to-vulnerability relationships, propose test cases, prioritize likely exploit paths, explain findings to developers, and draft remediation guidance. Evaluate and govern AI-assisted security capabilities for accuracy, privacy, data handling, prompt-injection resistance, model and supply-chain risk, reproducibility, auditability, and human oversight; measure false-positive, false-negative, and remediation-quality outcomes. Perform manual and tool-assisted application and API security assessments, validate exploitability, eliminate false positives, create proof-of-concept evidence when appropriate, and provide clear, actionable remediation guidance. Lead application threat modeling and architecture risk reviews using practical methods such as abuse cases, data-flow analysis, trust-boundary analysis, and attack-path modeling. Partner with software engineers, architects, product owners, DevOps/platform teams, cloud teams, and risk stakeholders to translate security requirements into pragmatic engineering solutions. Develop and maintain secure coding standards, reusable security patterns, guardrails, reference implementations, and developer enablement materials aligned with OWASP guidance and recognized industry practices. Create risk-based service-level objectives and prioritization models that account for exploitability, reachability, business criticality, data sensitivity, compensating controls, threat