Raymond James Financial, Inc

Lead Application Security Engineer, IT Security

Raymond James Financial, Inc$110K — $135K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 5-7 years of experience in application and API security with a focus on OWASP vulnerabilities.
  • Expertise in secure coding practices and common attack vectors.
  • Proficiency in automation using Python and familiarity with CI/CD tools.
  • Demonstrated ability to leverage AI for security tasks and validate tool outputs.
  • Experience with cloud security for platforms such as AWS and Azure required.

Responsibilities

  • Lead application security engineering for web and mobile platforms.
  • Embed security controls in the software development lifecycle (SDLC).
  • Design and govern automated security testing in CI/CD pipelines.
  • Develop automation solutions for security testing and vulnerability management.
  • Conduct risk assessments and threat modeling for application architectures.
  • Mentor engineers and promote security best practices across teams.

Benefits

  • Hybrid work model requiring 3 days in the office each week.
  • Comprehensive medical, dental, and vision insurance package.
  • Retirement savings options including 401(k) plans.
  • Paid time off that covers vacation, sick leave, and parental leave.
  • Life, disability, and critical illness insurance options available.
Full Job Description
Job Description Summary
The financial services industry is continuously targeted by sophisticated cyber adversaries ranging from criminal organizations to nation-state actors. Raymond James relies on the Cyber Threat Center (CTC) to identify, assess, and reduce technology risk across the enterprise. The Lead Application Security Engineer will be a hands-on technical leader responsible for integrating security into the software development lifecycle, assessing application and API risk, and enabling development teams to deliver resilient software at scale.
This role combines application security engineering, software security assessment, vulnerability analysis, secure software development practices, and cybersecurity architecture. The engineer will build and automate security controls across CI/CD pipelines; perform risk-based testing and threat modeling; and responsibly apply AI-assisted techniques to accelerate vulnerability discovery, triage, validation, and remediation

Job Description

This position follows a hybrid work model, with an expectation to be in the office 3 days per week at the St. Petersburg, FL Corporate Office location.

Please note: This role is not eligible for Work Visa sponsorship, either currently or in the future.

Responsibilities

  • Lead application security engineering activities across web applications, APIs, mobile applications, cloud-native services, containers, and supporting platforms.
  • Embed security controls throughout the software development lifecycle (SDLC), including requirements, architecture, design, development, build, test, release, and post-production monitoring.
  • Design, implement, tune, and govern automated security testing in CI/CD pipelines, including static application security testing (SAST), dynamic application security testing (DAST), interactive application security testing (IAST), software composition analysis (SCA), secrets detection, infrastructure-as-code scanning, container image scanning, API security testing, and mobile application testing.
  • Develop reusable automation, integrations, and security-as-code using Python, PowerShell, JavaScript, shell scripting, APIs, webhooks, and pipeline platforms to reduce manual effort and improve control coverage.
  • Build automated workflows that normalize, correlate, enrich, deduplicate, prioritize, ticket, route, retest, and close application vulnerability findings across security tools and engineering systems.
  • Leverage AI-assisted application vulnerability analysis to summarize evidence, identify code-to-vulnerability relationships, propose test cases, prioritize likely exploit paths, explain findings to developers, and draft remediation guidance.
  • Evaluate and govern AI-assisted security capabilities for accuracy, privacy, data handling, prompt-injection resistance, model and supply-chain risk, reproducibility, auditability, and human oversight; measure false-positive, false-negative, and remediation-quality outcomes.
  • Perform manual and tool-assisted application and API security assessments, validate exploitability, eliminate false positives, create proof-of-concept evidence when appropriate, and provide clear, actionable remediation guidance.
  • Lead application threat modeling and architecture risk reviews using practical methods such as abuse cases, data-flow analysis, trust-boundary analysis, and attack-path modeling.
  • Partner with software engineers, architects, product owners, DevOps/platform teams, cloud teams, and risk stakeholders to translate security requirements into pragmatic engineering solutions.
  • Develop and maintain secure coding standards, reusable security patterns, guardrails, reference implementations, and developer enablement materials aligned with OWASP guidance and recognized industry practices.
  • Create risk-based service-level objectives and prioritization models that account for exploitability, reachability, business criticality, data sensitivity, compensating controls, threat intelligence, and exposure.
  • Define and report meaningful program metrics, including coverage, control adoption, vulnerability aging, recurrence, escape rate, mean time to remediate, automation effectiveness, and risk reduction.
  • Conduct root-cause analysis for recurring vulnerability classes and drive systemic prevention through framework changes, paved-road patterns, automated controls, and targeted education.
  • Serve as a technical escalation point for complex application vulnerabilities and major cybersecurity incidents; participate in an on-call rotation as required.
  • Mentor application security engineers and developers, contribute to technical strategy and roadmaps, and remain current with emerging attack techniques, defensive technologies, and AI-enabled software development risks.


Qualifications

Knowledge, Skills, and Abilities:
  • Demonstrated expertise identifying, validating, explaining, and remediating application and API vulnerabilities, including vulnerability classes represented in the OWASP Top 10 and OWASP API Security Top 10.
  • Advanced understanding of authentication, authorization, session management, cryptography, input handling, deserialization, server-side request forgery, business-logic abuse, and modern client/server attack surfaces.
  • Hands-on experience with SAST, DAST, IAST, SCA, API testing, secrets detection, container scanning, infrastructure-as-code scanning, and penetration-testing tools; ability to tune controls and validate tool output rather than rely solely on scanner severity.
  • Strong automation and software engineering capability in Python and at least one of PowerShell, JavaScript/TypeScript, Go, Java, C#, or shell; experience consuming REST/GraphQL APIs, processing structured data, writing tests, and maintaining production-quality code.
  • Experience integrating security tools with CI/CD and engineering platforms such as GitHub, GitLab, Azure DevOps, Jenkins, Jira, or comparable technologies.
  • Demonstrated experience applying AI-assisted or machine-learning-enabled security tooling to source-code review, vulnerability triage, exploit-path analysis, test generation, remediation support, or finding correlation.
  • Ability to critically evaluate AI output, recognize hallucinations and insecure recommendations, protect sensitive source code and data, design human-in-the-loop validation, and establish measurable quality and governance controls.
  • Knowledge of secure AI-assisted development risks, including prompt injection, insecure output handling, excessive agency, sensitive information disclosure, model or dependency supply-chain concerns, and misuse of generated code.
  • Experience securing cloud-native applications on Microsoft Azure, Amazon Web Services, and/or Google Cloud Platform, including identity, secrets, workloads, APIs, containers, serverless services, and Kubernetes.
  • Working knowledge of threat modeling, secure architecture principles, software supply-chain security, SBOM/VEX concepts, artifact integrity, dependency governance, and provenance or attestation practices.
  • Ability to communicate technical risk clearly to developers, architects, executives, auditors, and non-technical stakeholders, and to translate findings into prioritized engineering actions.
  • Ability to lead through influence, exercise sound judgment under uncertainty, mentor others, and balance security outcomes with client and business needs.


Education/Previous Experience:
  • Typically requires a Bachelor's degree in computer science, software engineering, cybersecurity, information systems, or a related field and 5 or more years of relevant experience; an equivalent combination of education, training, and experience may be considered.
  • Typically requires 3 or more years of hands-on application security, product security, penetration testing, secure software development, or software security assessment experience.
  • Demonstrated experience developing security automation and integrating application security controls into CI/CD workflows.
  • Practical experience using AI-assisted capabilities for application vulnerability analysis, with evidence of validation, governance, and measurable improvement in security outcomes.
  • One or more of the following certifications, or the ability to obtain a relevant certification within one year, is preferred:
  • GIAC Web Application Penetration Tester (GWAPT), GIAC Certified Web Application Defender (GWEB), or comparable application security certification.
  • Offensive Security Web Expert (OSWE) or comparable advanced assessment certification.
  • AWS, Microsoft Azure, Google Cloud, Kubernetes, or DevSecOps certification relevant to the assigned environment.


Education
Bachelor's: Information Technology, Bachelor's (Required)

Work Experience
General Experience - 6 to 10 years

Certifications

Travel

Workstyle
Hybrid

The total compensation for this position includes base salary or wages, and may include components such as additional compensation (cash or equity), discretionary bonuses, or commissions. This position is eligible for a benefits package that may include medical, dental, and vision; life insurance; critical illness insurance and accident insurance; disability benefits; retirement savings; paid time off (including vacation, holidays, and sick leave); and parental leave. Eligibility for benefits and specific offerings may vary based on position and employment status. To view more details of the benefits offered, visit Myrjbenefits.com.

About Raymond James Financial, Inc

The Raymond James Technology and Communications Investment Banking Group is a committed and thoughtful partner that provides a full range of investment banking services and best practices. The group is comprised of experienced professionals that have extensive investment banking expertise. They leverage the industry expertise of Raymond James' award-winning research department. The group focuses on key sectors within technology and communications including: communications software, communication towers, defense electronics, enterprise software, internet infrastructure services, homeland security, IT services, mobile technology, semiconductors, software-as-a-service, telecommunications equipment, telecommunications infrastructure and support services, and wireless & wireline telecommunications services. They take pride in a client-centric approach to M&A, with focus on delivering independent solutions that creates value for the long term. The outcome of this unique approach may be seen in the successful transactions of their clients, including over 80 public offerings totaling $17 billion and over 85 strategic advisory transactions totaling over $5 billion in value since 1998.

Raymond James Financial, Inc Careers

Join the vibrant team at Raymond James Financial, Inc, a leading financial services company where innovation, leadership, and professional growth are at the forefront of our operations. As a hub of diversity and expertise, Raymond James offers unparalleled job opportunities that propel your career to new heights. Work You’ll Do At Raymond James Financial, Inc, you’ll collaborate with some of the most talented professionals in the financial industry. Our team is dedicated to providing strategic financial solutions and advice to our clients, helping them achieve their financial goals while fostering economic growth. With a culture rooted in leadership and diversity training, Raymond James is the perfect place to enhance your skills and thrive professionally. Join our market-leading team to assist a diverse range of clients, from individuals to large corporations, in navigating their financial planning with precision and innovative strategies. Lead in a role where your expertise directly influences the success and stability of our clients' financial futures. Work with a dynamic team of advisors and experts who are committed to pushing the boundaries of the financial sector through continuous innovation and exceptional client service. Raymond James Financial, Inc Job Opportunities Introducing the Raymond James Career Development Program We are committed to nurturing talent through our comprehensive career development program designed to provide every employee—from interns to senior leaders—with the tools and training necessary for success. Whether you’re just starting out with an internship or you’re a seasoned professional, Raymond James offers career paths that align with your ambitions and skills. Do Innovative Work Join a company where innovation is part of the daily routine. At Raymond James Financial, Inc, you’ll engage with cutting-edge financial tools and resources that keep you ahead in the industry. Our commitment to technology and innovation ensures that we stay at the forefront of financial services. Be Part of a Great Team Experience a collaborative environment where teamwork and networking are encouraged. Our inclusive culture supports diversity and offers benefits that ensure the well-being of all team members. At Raymond James, you’re not just an employee; you’re part of a family that values your unique contributions and supports your professional journey. Future-Proof Your Career Advance your career with Raymond James, where opportunities for growth are abundant. Benefit from our industry-leading training programs and gain certifications that will elevate your professional standing. With a focus on career longevity and satisfaction, Raymond James ensures that your professional journey is as rewarding as it is successful. Explore Discover the various positions available at Raymond James Financial, Inc that match your skills and interests. We are continuously hiring across multiple disciplines, eager to welcome passionate, curious, and solution-driven team players. Stay Connected Join Our Team Search open positions at Raymond James Financial, Inc and find the perfect match for your career aspirations. Explore a range of opportunities from financial advising to corporate roles that align with your professional skills and goals. Keep Up to Date Stay informed with the latest career tips, insider perspectives, and industry-leading insights—all from the professionals who thrive at Raymond James. Job Alert Emails Customize your subscription to receive job alerts, latest news, and insider tips tailored to your preferences. Discover the exciting and rewarding career opportunities waiting for you at Raymond James Financial, Inc. Join Raymond James Financial, Inc today and be part of a company that values innovation, leadership, and professional growth. Your future in the financial industry starts here.
Learn more about Raymond James Financial, Inc
Size
15,000 employees
Market Cap
$22.6 billion
Industry
Net Income
$862 million
5 Year Trend
+11.6%
Revenue
$8.3 billion
NASDAQ

Similar Jobs

More Jobs at Raymond James Financial, Inc

More Information Technology Jobs

Find similar Lead Application Security Engineer, IT Security jobs: