Sr. Application Security Engineer

LPL Financial LLC

Town of Charlotte, Fort Mill (NY, SC)

On-site

USD 101,000 - 168,000

Full time

14 days+
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

LPL Financial is seeking a Sr. Application Security Engineer to help develop, mature, and sustain the Application Security program.

You will collaborate with Development teams to review vulnerabilities, mentor engineers, and monitor CVEs while driving secure development practices across Advisor and Investor applications. The role emphasizes expertise in web, mobile, databases, APIs, and containers, with a strong focus on metrics, automation, and continuous improvement within a fast-paced

Qualifications

  • 5+ years of application security experience.
  • 5+ years of API and web application security testing experience.
  • 5+ years building and maintaining enterprise security libraries, components, and checklists.
  • 5+ years evaluating application security risk and improving CI/CD security posture.
  • 5+ years creating and maintaining scan profiles for static, dynamic, and SCA analysis.
  • 5+ years reviewing vulnerability scan results and tracking closure.

Responsibilities

  • Perform as an application security SME in Web Applications, Mobile Applications, Databases, APIs, Containers and other domains.
  • Support and maintain application security testing platforms and develop integrations with automation platforms.
  • Work with Development teams to review potential false-positive results and mitigating factors.
  • Produce and track application security metrics.
  • Support the secure development and testing of Advisor and Investor LPL applications.
  • Mentor and educate product development and quality engineers on secure development practices.
  • Monitor CVEs and industry developments for continuous improvement.
  • Collaborate with Internal Audit, IT Governance, IT Compliance on projects.

Skills

Application security
API security testing
Web/mobile/app security
CI/CD security
Vulnerability management

Education

Bachelor’s Degree or equivalent in Information Security, Engineering or Computer Science

Tools

Synopsys
BlackDuck
J-Frog
PrismaCloud
API scanners
Burpsuite
Postman

Job description

Where Ambition Meets Innovation Build a career that matches all your initiative with an impressive dose of innovation. From cutting-edge resources and a collaborative environment to the freedom to make an impact and more, you'll find the ingredients you need at LPL Financial to shape your success while helping clients pursue their financial goals.

Job Overview

Job Overview: As a member of the Information Security team, the Sr. Application Security Engineer will be responsible for helping to develop, mature, and sustain the Application Security program for the company. Application Security is a top area of focus at LPL. We have incorporated key industry security best practices, technologies and integrated processes to further strengthen our defense posture. This is an exciting time to join the Information Security Vulnerability Management team as we are continuing to expand the Application Security program.

Responsibilities
  • Perform as an application security SME in the following areas: Web Applications, Mobile Applications, Databases, APIs, Containers and other domains.
  • Support and maintain application security testing platforms and develop integrations with automation platforms
  • Work with Application Development teams to review potential false-positive scan results and evaluate proposed mitigating factors
  • Produce and track application security metrics
  • Support the secure development and testing of critical Advisor and Investor LPL applications
  • Mentor and educate product development and quality engineers on secure development and security best practices
  • Monitor and review CVEs, industry developments, and provide inputs for continuous improvement
  • Work with Internal Audit, IT Governance, IT Compliance and other key stakeholder groups on specific projects
What are we looking for

We're looking for strong collaborators who deliver exceptional client experiences and thrive in fast-paced, team-oriented environments. Our ideal candidates pursue greatness, act with integrity, and are driven to help our clients succeed. We value those who embrace creativity, continuous improvement, and contribute to a culture where we win together and create and share joy in our work.

Requirements
  • 5+ years of application security experience
  • 5+ years of experience performing manual testing of APIs and web applications to identify/validate vulnerabilities.
  • 5+ years of experience developing and maintaining enterprise security libraries, components, best practices checklists.
  • 5+ years of experience performing application security risk evaluation, partnering with key stakeholders to further enhance application security CI/CD pipeline and continually assess security posture for improvement.
  • 5+ years of experience creating and maintaining scan profiles for performing static, authenticated dynamic, IAST, and 3rd party library automated analysis with application scanning tools
  • 5+ years of experience with reviewing and analyzing vulnerability scan results and tracking closure of vulnerabilities
Core Competencies
  • Understanding of OWASP Top 10 Critical Web Application Security Risks, their identification, and architecture, design, coding patterns to mitigate them
  • Knowledge of secure coding best practices, secure SDLC, secure architecture, and DevSecOps methodologies
  • Strong analytical, interpersonal and communication skills
Preferences
  • Bachelor’s Degree or equivalent in Information Security, Engineering or Computer Science.
  • Application development and Security Engineering or Security Architecture experience
  • Experience using Application Security Code Scanning Tools such as Synopsys, BlackDuck, J-Frog, PrismaCloud, API scanners as well as manual tools such as Burpsuite and Postman
  • Experience working with security of applications developed in C#, Java, and web (HTML, CSS, JS, React, Angular, REST) technologies
  • Experience working with DevSecOps and CI/CD pipelines
Eligibility

This position does not offer work authorization sponsorship now or in the future. Applicants must have valid U.S. work authorization that does not require employer sponsorship.

Pay Range

$100,631.00 - $167,787.00 Actual base salary varies based on factors, including but not limited to, relevant skill, prior experience, education, base salary of internal peers, demonstrated performance, and geographic location. Additionally, LPL Total Rewards package is highly competitive, designed to support your success at work, at home, and at play - such as 401K matching, health benefits, employee stock options, paid time off, volunteer time off, and more.

Benefits
  • 401K matching
  • health benefits
  • employee stock options
  • paid time off
  • volunteer time off
Company Overview

LPL Financial Holdings Inc. (Nasdaq: LPLA) is among the fastest growing wealth management firms in the U.S. As a leader in the financial advisor-mediated marketplace(6) , LPL supports over 32,000 financial advisors and the wealth management practices of approximately 1,100 financial institutions, servicing and custodying approximately $2.3 trillion in brokerage and advisory assets on behalf of approximately 8 million Americans. The firm provides a wide range of advisor affiliation models, investment solutions, fintech tools and practice management services, ensuring that advisors and institutions have the flexibility to choose the business model, services, and technology resources they need to run thriving businesses. For further information about LPL, please visit www.lpl.com. At LPL, independence means that advisors and institution leaders have the freedom they deserve to choose the business model, services, and technology resources they need to run a thriving business. They have the flexibility to do business their way. And they have the freedom to manage their client relationships, because they know their clients best. Simply put, we take care of our advisors and institutions, so they can take care of their clients. For further information about LPL, please visit www.lpl.com. Join the LPL team and help us make a difference by turning life's aspirations into financial realities. LPL Financial is the nation's largest independent broker-dealer. Our company is widely known for its financial strength, exceptional service, and favorable industry reputation among financial professionals. To understand who we are, it's important to know our core belief: financial guidance is a fundamental need for everyone. LPL Financial creates the space to let you do what you do best – create personal, long-term client relationships that turn financial aspirations into realities. Each year, thousands of financial professionals successfully manage billions of dollars in assets. Because our company is not too big and not too small, you can seize the opportunity to make a real impact. To learn more about our organization visit our About LPL page.

Information on Interviews

LPL will only communicate with a job applicant directly from an @lplfinancial.com email address and will never conduct an interview online or in a chatroom forum. During an interview, LPL will not request any form of payment from the applicant, or information regarding an applicant’s bank or credit card. Should you have any questions regarding the application process, please contact LPL’s Human Resources Solutions Center at (855) 575-6947.

EOE.

EAC 5.19.26

We Are LPL Benefits Culture Social Responsibility

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Sr. Application Security Engineer
Sr. Application Security Engineer

LPL Financial • Tempe (AZ)

On-site
USD 101,000 - 168,000
401K matching
Health benefits
Employee stock options
+2
Sr. Application Security Engineer
Sr. Application Security Engineer

LPL Financial • New York (NY)

On-site
USD 101,000 - 168,000
Sr. Application Security Engineer
Sr. Application Security Engineer

LPL Financial • San Diego (CA)

On-site
USD 101,000 - 168,000
Sr. Application Security Engineer
Sr. Application Security Engineer

LPL Financial • Fort Mill (SC)

On-site
USD 101,000 - 168,000
401K matching
Health benefits
Employee stock options
+2
Sr. Application Security Engineer
Sr. Application Security Engineer

LPL Financial • Austin (TX)

On-site
USD 101,000 - 168,000
Senior Vulnerability Management Engineer
Senior Vulnerability Management Engineer

LPL Financial LLC • Fort Mill (SC), Charlotte (NC)

On-site
USD 101,000 - 168,000
401K matching
Health benefits
Employee stock options
+1
AVP, Engineering Security Operations Manager
AVP, Engineering Security Operations Manager

LPL Financial LLC • Austin (TX)

On-site
USD 129,986 - 216,609
401K matching
Health benefits
Employee stock options
+2
Sr. Software Engineer
Sr. Software Engineer

LPL Financial LLC • Town of Charlotte (NY), Fort Mill (SC)

On-site
USD 106,000 - 177,000
Sr Eng, Software Dev Test QE
Sr Eng, Software Dev Test QE

LPL Financial LLC • Fort Mill (SC), Charlotte (NC)

On-site
USD 91,000 - 152,000
AVP, Engineering Security Operations Manager
AVP, Engineering Security Operations Manager

LPL Financial • Austin (TX)

On-site
USD 129,000 - 217,000
401K matching
Health benefits
Employee stock options
+2