> Markdown version of [/jobs/ext/2021100-sr-application-security-engineer](https://www.wearedevelopers.com/jobs/ext/2021100-sr-application-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Sr. Application Security Engineer - **Company:** LPL Financial - **Location:** Fort Mill, SC, United States (Remote available) - **Experience:** Expert - **Salary:** $100,631.0 - $167,787.0 - **Contract:** Permanent contract - **Skills:** HTML, Java (Programming Language), Application Programming Interfaces (APIs), C Sharp (Programming Language), Cascading Style Sheets (CSS), Code Review, Cyber Security, Databases, Continuous Integration, IT Management, Mobile Application Software, Information Systems Security Architecture Professional, Automation of Marketing, Open Web Application Security, Systems Development Life Cycle, Secure Coding, Web Application Security, Software Engineering, Systems Integration, Software Vulnerability Management, Web Applications, Postman, ReactJS, Software Security, AngularJS, Information Technology, Tenable Nessus, Synopsys Black Duck, Restful APIs, Burpsuite, Devsecops, Vulnerability Analysis - **Published:** August 11, 2026 - **Apply:** https://lplfinancial.wd1.myworkdayjobs.com/External/job/Fort-MillCharlotte/Sr-Application-Security-Engineer_R-052354-1 ## About the Role * 5+ years of application security experience * 5+ years of experience performing manual testing of APIs and web applications to identify/validate vulnerabilities. * 5+ years of experience developing and maintaining enterprise security libraries, components, best practices checklists. * 5+ years of experience performing application security risk evaluation, partnering with key stakeholders to further enhance application security CI/CD pipeline and continually assess security posture for improvement. * 5+ years of experience creating and maintaining scan profiles for performing static, authenticated dynamic, IAST, and 3rd party library automated analysis with application scanning tools * 5+ years of experience with reviewing and analyzing vulnerability scan results and tracking closure of vulnerabilities Core Competencies: * Understanding of OWASP Top 10 Critical Web Application Security Risks, their identification, and architecture, design, coding patterns to mitigate them * Knowledge of secure coding best practices, secure SDLC, secure architecture, and DevSecOps methodologies * Strong analytical, interpersonal and communication skills Preferences: * Bachelor's Degree or equivalent in Information Security, Engineering or Computer Science. * Application development and Security Engineering or Security Architecture experience * Experience using Application Security Code Scanning Tools such as Synopsys, BlackDuck, J-Frog, PrismaCloud, API scanners as well as manual tools such as Burpsuite and Postman * Experience working with security of applications developed in C#, Java, and web (HTML, CSS, JS, React, Angular, REST) technologies * Experience working with DevSecOps and CI/CD pipelines Please note: This position does not offer work authorization sponsorship now or in the future. Applicants must have valid U.S. work authorization that does not require employer sponsorship. ## Description As a member of the Information Security team, the Sr. Application Security Engineer will be responsible for helping to develop, mature, and sustain the Application Security program for the company. Application Security is a top area of focus at LPL. We have incorporated key industry security best practices, technologies and integrated processes to further strengthen our defense posture. This is an exciting time to join the Information Security Vulnerability Management team as we are continuing to expand the Application Security program., * Perform as an application security SME in the following areas: Web Applications, Mobile Applications, Databases, APIs, Containers and other domains. * Support and maintain application security testing platforms and develop integrations with automation platforms * Work with Application Development teams to review potential false-positive scan results and evaluate proposed mitigating factors * Produce and track application security metrics * Support the secure development and testing of critical Advisor and Investor LPL applications * Mentor and educate product development and quality engineers on secure development and security best practices * Monitor and review CVEs, industry developments, and provide inputs for continuous improvement * Work with Internal Audit, IT Governance, IT Compliance and other key stakeholder groups on specific projects What are we looking for? We're looking for strong collaborators who deliver exceptional client experiences and thrive in fast-paced, team-oriented environments. Our ideal candidates pursue greatness, act with integrity, and are driven to help our clients succeed. We value those who embrace creativity, continuous improvement, and contribute to a culture where we win together and create and share joy in our work. ## Related Videos - [Watch Tests Go Brrrr! : Getting Started with Cypress in ReactJS](https://www.wearedevelopers.com/videos/282-watch-tests-go-brrrr-getting-started-with-cypress-in-reactjs) - [Are Your APIs Ready for AI Agents](https://www.wearedevelopers.com/videos/2004-are-your-apis-ready-for-ai-agents) - [The Resilience of the World Wide Web](https://www.wearedevelopers.com/videos/1281-the-resilience-of-the-world-wide-web) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Real-World Security for Busy Developers](https://www.wearedevelopers.com/videos/1545-real-world-security-for-busy-developers) - [NoLoJS - Avoiding JavaScript Cruft with HTML and CSS - Aaron T. Grogg](https://www.wearedevelopers.com/videos/1806-nolojs-avoiding-javascript-cruft-with-html-and-css-aaron-t-grogg) ## Related Articles - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [The 8 Best Code Testing Tools](https://www.wearedevelopers.com/magazine/402-the-8-best-code-testing-tools) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers)