Raymond James logo
Raymond JamesPosted 3 weeks ago

Lead Application Security Engineer, IT Security

HybridSt. Petersburg, Florida, United States

Full TimeSenior LevelLargeFinancial Services

Job Summary

Lead application security engineering activities across web, API, mobile, and cloud-native services by embedding security controls throughout the software development lifecycle. Design, implement, and govern automated security testing in CI/CD pipelines, including SAST, DAST, IAST, and secrets detection, while leveraging AI-assisted techniques to accelerate vulnerability discovery and remediation. Build reusable automation and security-as-code to normalize, correlate, and close vulnerability findings, and perform manual assessments to validate exploitability and provide actionable guidance. Lead application threat modeling and architecture risk reviews, partner with engineering teams to translate security requirements into pragmatic solutions, and mentor developers on secure coding standards. Serve as a technical escalation point for complex vulnerabilities and major incidents, participating in an on-call rotation as required.

Required Qualifications

  • Bachelor's degree in computer science, software engineering, cybersecurity, information systems, or a related field
  • 5 or more years of relevant experience
  • 3 or more years of hands-on application security, product security, penetration testing, secure software development, or software security assessment experience
  • Demonstrated expertise identifying, validating, explaining, and remediating application and API vulnerabilities, including vulnerability classes represented in the OWASP Top 10 and OWASP API Security Top 10
  • Advanced understanding of authentication, authorization, session management, cryptography, input handling, deserialization, server-side request forgery, business-logic abuse, and modern client/server attack surfaces
  • Hands-on experience with SAST, DAST, IAST, SCA, API testing, secrets detection, container scanning, infrastructure-as-code scanning, and penetration-testing tools
  • Strong automation and software engineering capability in Python and at least one of PowerShell, JavaScript/TypeScript, Go, Java, C#, or shell
  • Experience integrating security tools with CI/CD and engineering platforms such as GitHub, GitLab, Azure DevOps, Jenkins, Jira, or comparable technologies
  • Demonstrated experience applying AI-assisted or machine-learning-enabled security tooling to source-code review, vulnerability triage, exploit-path analysis, test generation, remediation support, or finding correlation
  • Ability to critically evaluate AI output, recognize hallucinations and insecure recommendations, protect sensitive source code and data, design human-in-the-loop validation, and establish measurable quality and governance controls
  • Knowledge of secure AI-assisted development risks, including prompt injection, insecure output handling, excessive agency, sensitive information disclosure, model or dependency supply-chain concerns, and misuse of generated code
  • Experience securing cloud-native applications on Microsoft Azure, Amazon Web Services, and/or Google Cloud Platform, including identity, secrets, workloads, APIs, containers, serverless services, and Kubernetes
  • Working knowledge of threat modeling, secure architecture principles, software supply-chain security, SBOM/VEX concepts, artifact integrity, dependency governance, and provenance or attestation practices
  • Ability to communicate technical risk clearly to developers, architects, executives, auditors, and non-technical stakeholders
  • Ability to lead through influence, exercise sound judgment under uncertainty, mentor others, and balance security outcomes with client and business needs
  • Typically requires 3 or more years of hands-on application security, product security, penetration testing, secure software development, or software security assessment experience
  • Demonstrated experience developing security automation and integrating application security controls into CI/CD workflows
  • Practical experience using AI-assisted capabilities for application vulnerability analysis, with evidence of validation, governance, and measurable improvement in security outcomes
  • One or more of the following certifications, or the ability to obtain a relevant certification within one year, is preferred: GIAC Web Application Penetration Tester (GWAPT), GIAC Certified Web Application Defender (GWEB), or comparable application security certification
  • Offensive Security Web Expert (OSWE) or comparable advanced assessment certification
  • AWS, Microsoft Azure, Google Cloud, Kubernetes, or DevSecOps certification relevant to the assigned environment

Desired Qualifications

  • An equivalent combination of education, training, and experience may be considered
  • Certifications: One or more of the following certifications, or the ability to obtain a relevant certification within one year, is preferred: GIAC Web Application Penetration Tester (GWAPT), GIAC Certified Web Application Defender (GWEB), or comparable application security certification
  • Offensive Security Web Expert (OSWE) or comparable advanced assessment certification
  • AWS, Microsoft Azure, Google Cloud, Kubernetes, or DevSecOps certification relevant to the assigned environment

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Apply on Sorce