> Markdown version of [/jobs/ext/2246721-lead-application-security-engineer](https://www.wearedevelopers.com/jobs/ext/2246721-lead-application-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Lead Application Security Engineer - **Company:** CareerCircle - **Location:** Charlotte, NC, United States (Remote available) - **Experience:** Expert - **Salary:** $120,375.0 - $192,600.0 - **Contract:** Permanent contract - **Skills:** Java (Programming Language), .NET Framework, Agile Methodology, Artificial Intelligence, Amazon Web Services, Microsoft Azure, Burp Suite, Mobile Application Development, Cloud Computing Security, Cloud Engineering, Code Review, DevOps, Dynamic Program Analysis, Mobile Application Software, Information Systems Security Architecture Professional, Lightweight Directory Access Protocols (LDAP), Machine Learning, Network Architecture, Open Web Application Security, Systems Development Life Cycle, Role-Based Access Control, Cloud Services, Fortify (Software), Web Application Security, Software Engineering, Systems Integration, Web Applications, Webinspect, Large Language Models, Software Security, Veracode, Firewalls (Computer Science), GWAPT, Information Technology, Machine Learning Operations, Checkmarx, Appscan, Burpsuite, Static Application Security Testing - **Published:** August 26, 2026 - **Apply:** https://www.careercircle.com/jobs/all/all/usa/pa/radnor/b209cbab-afb6-4845-9032-1e237b243da7 ## About the Role Must Haves: * Undergraduate degree or 4+ years of comparable work experience * 5-7+ years of experience in Information Technology that directly aligns with the specific responsibilities for this position * Extensive experience in web application security * Strong knowledge of application security throughout the SDLC * Experience with agile delivery practices * Experience integrating security into DevOps practices. * Experience conducting source code review preferred * Experience using static application security testing tools such as Fortify, Checkmarx, Veracode, etc. * Experience dynamic analysis with tools such as AppScan, Webinspect, BurpSuite, and OWASP ZAP, etc. * Familiarity with related network infrastructure, such as firewalls, WAFs, and IPS * Familiarity with common DMZ architectures * Prior financial services experience preferred * Agile Mindset; awareness/understanding of Agile methodologies Nice to Haves * OSCP, OSWE, ISC2 CISSP, CSSLP, GIAC GWAPT, GIAC GSSP-Java, GIAC GSSP-NET Preferred ## Description DevOps Research Advocacy Firewall VeraCode Marketing Annuities Checkmarx Pipelines Leadership Burp Suite Code Review Wholesaling Fundraising Communication Design Reviews Tax Accounting Social Security Machine Learning Virtual Training Agile Methodology Financial Services Security Solutions Workflow Management Development Testing GIAC Certifications Application Security Information Technology Network Infrastructure Artificial Intelligence Application Development Employment Applications Web Application Security Dynamic Program Analysis Demilitarized Zones (DMZ) Employee Assistance Programs Health And Wellness Coaching Mobile Application Development Systems Development Life Cycle Software Development Life Cycle GIAC Web Application Penetration Tester Static Application Security Testing (SAST) Open Web Application Security Project (OWASP) Certified Secure Software Lifecycle Professional GIAC Secure Software Programmer .NET (GSSP-.NET) GIAC Secure Software Programmer Java (GSSP-JAVA) Certified Information Systems Security Professional, The Lead Application Security Engineer is responsible for working with application development and infrastructure teams to ensure applications are designed, coded, and implemented securely. You will be responsible for Integrating security best practices and controls into all phases of the Software Development Lifecycle (SDLC), including requirements, design, development, testing, deployment, and maintenance. You will drive the improvement of policies, standards, and other supporting documentation. This is a hands-on technical position that you will find yourself collaborating with multiple groups across the organization. Strong communication skills are needed to explain complex security to a wide variety of technical levels. Experience as a developer is helpful, but not required. What you'll be doing * Responsibility for the security of Lincoln Financial applications and services * Conduct design review, code review, and dynamic analysis * Evaluate the security posture of AI/ML systems, including LLM-integrated applications, RAG pipelines, and agentic workflows * Identify, communicate, and drive the resolution of vulnerabilities * Serve as a subject matter expert for application development and infrastructure teams * Communicate effectively with a wide variety of technical levels * Perform security assessments of web and mobile applications * Research and advocate for new security solutions and technologies * Stay current on security trends, vulnerabilities, and testing methods * Contribute to related policies, standards, and supporting documentation, This position may be subject to Lincoln's Political Contribution Policy. An offer of employment may be contingent upon disclosing to Lincoln the details of certain political contributions. Lincoln may decline to extend an offer or terminate employment for this role if it determines political contributions made could have an adverse impact on Lincoln's current or future business interests, misrepresentations were made, or for failure to fully disclose applicable political contributions and or fundraising activities. Any unsolicited resumes or candidate profiles submitted through our web site or to personal e-mail accounts of employees of Lincoln Financial are considered property of Lincoln Financial and are not subject to payment of agency fees. Lincoln Financial ("Lincoln" or "the Company") is an Equal Opportunity employer and, as such, is committed in policy and practice to recruit, hire, compensate, train and promote, in all job classifications, without regard to race, color, religion, sex, age, national origin or disability. Opportunities throughout Lincoln are available to employees and applicants are evaluated on the basis of job qualifications. If you are a person with a disability that impedes your ability to express your interest for a position through our online application process, or require TTY/TDD assistance, contact us by calling (866) 922-6543. This Employer Participates in E-Verify. See the E-Verify notices. Este Empleador Participa en E-Verify. Ver el E-Verify avisos. Related Jobs Lead Cloud Security Engineer Lincoln Financial Radnor, PA*Remote Sales Gmail Marketing Annuities Leadership Management Automation Wholesaling Fundraising Cloud Services Cloud Security Tax Accounting Microsoft Azure Decision Making Social Security Virtual Training Change Management Incident Response Security Solutions Root Cause Analysis Amazon Web Services Enterprise Security Application Security Information Technology Employment Applications Cloud Security Architecture Employee Assistance Programs Cloud Computing Architecture Health And Wellness Coaching Security Requirements Analysis +0 Lead Application Security Engineer Lincoln Financial Radnor, PA*Remote Sales Gmail DevOps Research Advocacy Firewall VeraCode Marketing Annuities Checkmarx Pipelines Leadership Burp Suite Code Review Wholesaling Fundraising Communication Design Reviews Tax Accounting Social Security Machine Learning Virtual Training Agile Methodology Financial Services Security Solutions Workflow Management Development Testing GIAC Certifications Application Security Information Technology Network Infrastructure Artificial Intelligence Application Development Employment Applications Web Application Security Dynamic Program Analysis Demilitarized Zones (DMZ) Employee Assistance Programs Health And Wellness Coaching Mobile Application Development Systems Development Life Cycle Software Development Life Cycle GIAC Web Application Penetration Tester Static Application Security Testing (SAST) Open Web Application Security Project (OWASP) Certified Secure Software Lifecycle Professional GIAC Secure Software Programmer .NET (GSSP-.NET) GIAC Secure Software Programmer Java (GSSP-JAVA) Certified Information Systems Security Professional +0 Identity And Access Security Engineer TEKsystems King of Prussia, PA*Remote Operations Management Automation Governance IdentityIQ Business Valuation Workflow Management Security Governance Full Stack Development Artificial Intelligence Business Transformation Privileged Access Management Role-Based Access Control (RBAC) Lightweight Directory Access Protocols +0 Login | JoinContact ## Related Videos - [From DevOps to Scaled DevOps: How We’re Rebuilding Continuous Delivery as a Platform](https://www.wearedevelopers.com/videos/100018-from-devops-to-scaled-devops-how-we-re-rebuilding-continuous-delivery-as-a-platform) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [DevOps Maturity Check – a way to balance autonomy and alignment](https://www.wearedevelopers.com/videos/58-devops-maturity-check-a-way-to-balance-autonomy-and-alignment) - [Securing Your Web Application Pipeline From Intruders](https://www.wearedevelopers.com/videos/53-securing-your-web-application-pipeline-from-intruders) - [Software Security 101: Secure Coding Basics](https://www.wearedevelopers.com/videos/220-software-security-101-secure-coding-basics) - [#90DaysOfDevOps - The DevOps Learning Journey](https://www.wearedevelopers.com/videos/548-90daysofdevops-the-devops-learning-journey) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Where to Find Entry-Level Software Engineering Jobs](https://www.wearedevelopers.com/magazine/397-where-to-find-entry-level-software-engineering-jobs) - [7 Important Tips That Every Software Developer Should Know](https://www.wearedevelopers.com/magazine/101-7-important-tips-that-every-software-developer-should-know)