Sr. Application Security Engineer
Core
Develop, mature, and sustain the Application Security program by performing security testing, risk evaluation, and secure development support for critical Advisor and Investor applications.
Role type
Senior IC application security engineer (vulnerability management & DevSecOps)
Builds
Secure Advisor and Investor LPL applications
Domain
Financial services / Application Security
Deliverable
production ML models | product features | dashboards & analysis | client delivery | infrastructure
Required skills
Application security SME expertise, manual testing of APIs and web applications, enterprise security library development, application security risk evaluation, CI/CD pipeline security integration, automated scanning tool configuration, vulnerability scan result analysis
Preferred skills
Application development experience, Security Architecture experience, C#, Java, HTML, CSS, JS, React, Angular, REST technologies, DevSecOps methodologies, Application Security Code Scanning Tools (Synopsys, BlackDuck, J-Frog, PrismaCloud, Burpsuite, Postman)
Responsibilities
Perform application security SME duties across Web, Mobile, Databases, APIs, and Containers; Support and maintain application security testing platforms; Review false-positive scan results and evaluate mitigating factors; Produce and track application security metrics; Mentor engineers on secure development best practices; Monitor CVEs and industry developments; Collaborate with Internal Audit, IT Governance, and Compliance
Seniority
Senior, hands-on IC