Application Security Engineer IV

Edward Jones

St. Louis (MO)

Hybrid

USD 140,000 - 190,000

Full time

6 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

401(k) plan
Medical + prescription
Dental & vision
Short- & long-term disability
Life insurance
Employee Assistance Program
Paid holidays and vacation
Bonus potential & profit sharing

Job summary

Edward Jones is seeking an experienced Application Security Engineer to operate an AI-enabled harness that evaluates source code for security vulnerabilities throughout the Secure SDLC. You will partner with AppSec, DevSecOps, and platform teams to ensure reliable findings, actionable recommendations, and governance that meets financial-services controls.

Responsibilities include maintaining harness health, building observability dashboards, automating workflows, and ensuring evidence-quality

Qualifications

  • Bachelor’s degree in Computer Science, Cybersecurity, Software Engineering, Information Technology, Engineering, or related field (or equivalent practical experience).
  • 6+ years of experience in application security, secure software engineering, DevSecOps, or related cybersecurity engineering roles.
  • Hands-on experience supporting security capabilities across CI/CD, source control, ticketing, artifact management, logging, and AppSec reporting workflows.
  • Knowledge of secure code review, vulnerability triage, remediation validation, threat modeling, and secure SDLC practices.

Responsibilities

  • Operate and maintain the AI secure-code evaluation harness for source code repositories and SDLC changes.
  • Monitor harness health across ingestion, orchestration, model routing, and scanner integration.
  • Build observability dashboards and alerts for run success, latency, and cost management.
  • Troubleshoot CI/CD tooling, including Jenkins, GitHub, Jira/Azure DevOps, and AppSec scanners.
  • Automate operational workflows with Python, shell scripts, APIs, and IaC patterns.
  • Maintain runbooks, SOPs, and escalation paths.
  • Support secure ingestion and handling of source code, artifacts, SBOMs, logs, and evidence packages.

Skills

Application security
DevSecOps
Python
Shell scripting
LLM governance
CI/CD
Jenkins
GitHub Actions
Observability
SBOMs

Education

Bachelor's degree

Tools

Jenkins
GitHub Actions
GitHub Enterprise
Jira/Azure DevOps

Job description

This job posting is anticipated to remain open for 30 days, from 17-Aug-2026. The posting may close early due to the volume of applicants.

Join a financial services firm where your contributions are valued. Edward Jones is a Fortune 500¡ company where people come first. With over 9 million clients and 20,000 financial advisors across the U.S. and Canada, we’re proud to be privately-owned, placing the focus on our clients rather than shareholder returns.

Behind everything we do is our purpose: We partner for positive impact to improve the lives of our clients and colleagues, and together, better our communities and society. We are an innovative, flexible, and inclusive organization that attracts, develops, and inspires performance excellence and a sense of belonging.

People are at the center of our partnership. Edward Jones associates are seen, heard, respected, and supported. This is what we believe makes us the best place to start or build your career.

View our Purpose, Inclusion and Citizenship Report.

¡Fortune 500, published June 2024, data as of December 2023. Compensation provided for using, not obtaining, the rating.

Team Overview:

The Application Security Engineer, Agentic Secure Code Harness Engineer is a hands-on role responsible for operating, monitoring, and improving an AI-enabled AppSec harness used to evaluate application and infrastructure source code for security vulnerabilities and insecure-design practices throughout the Secure SDLC lifecycle. The role focuses on harness health, observability, reliability, troubleshooting, evidence capture, and day-to-day operability of the AppSec process.

The engineer partners with AppSec, DevSecOps, platform engineering, AI governance, and application teams to ensure reliability, accuracy of findings, and recommendations are actionable, evidence is repeatable, developer workflows remain aligned to the secure SDLC, AI model governance, and financial-services control expectations.

What You’ll Do:
  • Operate and maintain the AI secure-code evaluation harness for source code repositories, SDLC and lifecycle changes, and agentic security workflows.
  • Monitor harness health across ingestion, orchestration, model routing, scanner integration, executions, evidence generation, remediations, and reporting.
  • Build and tune observability dashboards and alerts for run success, queue depth, latency, cost management, model/API availability, regression failures, missing evidence, and integration outages.
  • Troubleshoot issues across development tooling such as: Jenkins, GitHub Actions, GitHub Enterprise, Atlassian, AppSec scanners, context tools, logging platforms, artifact repositories, and harness components.
  • Execute recurring operational routines, including run validation, readiness checks, benchmark refreshes, regression reviews, evidence-quality checks, and post-run reconciliation.
  • Maintain runbooks, SOPs, support playbooks, recovery steps, known-error documentation, and escalation paths.
  • Support secure ingestion and handling of source code, artifacts, scanner output, SBOMs, metadata, golden datasets, logs, and evidence packages.
  • Maintain benchmark suites, golden test cases, prompt/model configuration records, retrieval settings, scoring rubrics, and operational test data.
  • Validate that findings flow into developer workflows with context, severity, confidence, remediation guidance, traceability, and rejection rationale where applicable.
  • Collect audit-ready evidence aligned to NIST SSDF, NIST CSF 2.0, NYDFS, FINRA, SOX ITGC, FFIEC, GLBA, internal AI governance, and technology risk controls.
  • Report operational KPIs including run availability, failed-run rate, MTTR, validation cycle time, evidence completeness, cost per validated finding, false-positive trends, and developer remediation adoption.
  • Drive automation that reduces manual triage, improves repeatability, lowers operational toil, and increases developer trust in AI-assisted AppSec outcomes.
What Experience You’ll Need:
  • Bachelor’s degree in Computer Science, Cybersecurity, Software Engineering, Information Technology, Engineering, or related field, or equivalent practical experience.
  • 6+ years of experience in application security, secure software engineering, DevSecOps, platform engineering, security operations, or related cybersecurity engineering roles.
  • Hands-on experience supporting security capabilities across CI/CD, source control, ticketing, artifact management, logging, and AppSec reporting workflows.
  • Working knowledge of secure code review, vulnerability triage, exploitability analysis, remediation validation, threat modeling concepts, and secure SDLC practices.
  • Practical experience with SAST, SCA, DAST, secrets scanning, API security testing, container security, IaC scanning, SBOMs, SARIF, and findings management.
  • Experience with Jenkins, GitHub Actions, GitHub Enterprise, Jira/Azure DevOps, developer portals, observability platforms, and AppSec dashboards.
  • Strong understanding of logs, metrics, traces, health checks, alert thresholds, run manifests, error budgets, and incident response routines.
  • Ability to automate operational workflows using Python, shell scripting, APIs, configuration files, and infrastructure or policy-as-code patterns.
  • Familiarity with LLM or AI-assisted engineering concepts such as prompts, model versions, retrieval configurations, guardrails, token usage, latency, cost tracking, and drift monitoring.
  • Understanding of secure handling requirements for proprietary source code, credentials, logs, telemetry, evidence packages, and regulated financial-services data.
  • Working knowledge of OWASP Top 10, CWE, CVSS, NIST SSDF, NIST CSF 2.0, AI security risks, auditability, and regulated source-code handling.
What Could Set You Apart:
  • Certifications such as CISSP, CSSLP, CCSP, AWS/Azure security, Kubernetes security, GIAC application security, or AI governance.
  • Experience operating AI-assisted AppSec, software assurance, or vulnerability-validation platforms in a Fortune 500 or regulated financial-services environment.
  • Hands-on experience with observability platforms, SIEM integrations, telemetry pipelines, operational dashboards, SLIs, and alert tuning.
  • Experience supporting LLM-enabled workflows, including prompt evaluation, regression testing, guardrail monitoring, model routing, cost governance, and human-in-the-loop review.
  • Experience maintaining benchmark datasets, golden test cases, validation pipelines, custom static-analysis rules, or exploitability-validation workflows.
  • Track record reducing AppSec operational toil, improving evidence completeness, lowering false positives, improving run reliability, and accelerating developer remediation
Candidates that live within a commutable distance from our Tempe, AZ and St. Louis, MO home office locations are expected to work in the office four days per week effective June 1, 2026. Before June 1, 2026, candidates that live within a commutable distance from our Tempe, AZ and St. Louis, MO home office locations are expected to work in the office three days per week, with preference for Tuesday through Thursday.

At Edward Jones, we are building a place where everyone feels like they belong. We're proud of our associates' contributions to the firm and the recognitions we have received.

Check out our U.S. awards and accolades: Insights & Information Blog Postings about Edward Jones

Check out our Canadian awards and accolades: Insights & Information Blog Postings about Edward Jones

Edward Jones does not discriminate on the basis of race, color, gender, religion, national origin, age, disability, sexual orientation, pregnancy, veteran status, genetic information or any other basis prohibited by applicable law.

Edward Jones' compensation and benefits package includes medical and prescription drug, dental, vision, voluntary benefits (such as accident, hospital indemnity, and critical illness), short- and long-term disability, basic life, and basic AD&D coverage. Short- and long-term disability, basic life, and basic AD&D coverage are provided at no cost to associates. Edward Jones offers a 401k retirement plan, and tax-advantaged accounts: health savings account, and flexible spending account. Edward Jones observes ten paid holidays and provides 15 days of vacation for new associates beginning on January 1 of each year, as well as sick time, personal days, and a paid day for volunteerism. Associates may be eligible for bonuses and profit sharing. All associates are eligible for the firm's Employee Assistance Program. For more information on the Benefits available to Edward Jones associates, please visit our benefits page.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Application Security Engineer IV - AI Harness
Application Security Engineer IV - AI Harness

Edward Jones • St. Louis (MO)

Hybrid
USD 120,000 - 170,000
Medical benefits
Dental benefits
Vision benefits
+2
Application Security Architect
Application Security Architect

Edward Jones • St. Louis (MO)

Hybrid
USD 150,000 - 230,000
Medical and prescription drug coverage
Dental coverage
Vision coverage
+2
Security Engineer IV
Security Engineer IV

Edward Jones • St. Louis (MO)

Hybrid
USD 120,000 - 150,000
Senior Security Engineer
Senior Security Engineer

Edward Jones • St. Louis (MO)

On-site
USD 130,000 - 180,000
Medical insurance
Dental & Vision
401k with matching
+5
Data Security Engineer IV
Data Security Engineer IV

Edward Jones • St. Louis (MO)

Hybrid
USD 120,000 - 180,000
Medical & Prescription
401k & Benefits
Paid holidays
+2
Security Engineer IV
Security Engineer IV

Edward Jones • Tempe (AZ)

Hybrid
USD 120,000 - 150,000
Lead Theme Strategist
Lead Theme Strategist

Edward Jones • St. Louis (MO)

Hybrid
USD 110,000 - 170,000
Medical and prescription drug coverage
Dental and vision coverage
401(k) retirement plan
+1
Senior Technical Product Owner (DevOps)
Senior Technical Product Owner (DevOps)

Edward Jones • St. Louis (MO)

Hybrid
USD 130,000 - 170,000
Senior Risk & Controls Associate - Digital Risk Management
Senior Risk & Controls Associate - Digital Risk Management

Edward Jones • St. Louis (MO)

Hybrid
USD 120,000 - 150,000
Medical benefits
Dental & Vision
401(k) plan
+1
Senior Data Advisor
Senior Data Advisor

Edward Jones • Tempe (AZ), Northern (KY)

Hybrid
USD 120,000 - 160,000
Medical benefits
401k plan
Paid holidays
+1