> Markdown version of [/jobs/ext/2643070-lead-application-security-engineer](https://www.wearedevelopers.com/jobs/ext/2643070-lead-application-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Lead Application Security Engineer - **Company:** Lincoln National Corporation - **Location:** Radnor, PA, United States (Remote available) - **Experience:** Expert - **Salary:** $120,375.0 - $192,600.0 - **Contract:** Permanent contract - **Skills:** Agile Methodology, Artificial Intelligence, Burp Suite, Code Review, DevOps, Dynamic Program Analysis, Mobile Application Software, Network Architecture, Systems Development Life Cycle, Fortify (Software), Web Application Security, Software Engineering, Systems Integration, Webinspect, Large Language Models, Software Security, Veracode, Firewalls (Computer Science), Information Technology, Machine Learning Operations, Checkmarx, Appscan, Burpsuite, Static Application Security Testing - **Published:** August 25, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=053512a37b5dab2b ## About the Role Undergraduate degree or 4+ years of comparable work experience 5-7+ years of experience in Information Technology that directly aligns with the specific responsibilities for this position Extensive experience in web application security Strong knowledge of application security throughout the SDLC Experience with agile delivery practices Experience integrating security into DevOps practices. Experience conducting source code review preferred Experience using static application security testing tools such as Fortify, Checkmarx, Veracode, etc. Experience dynamic analysis with tools such as AppScan, Webinspect, BurpSuite, and OWASP ZAP, etc. Familiarity with related network infrastructure, such as firewalls, WAFs, and IPS Familiarity with common DMZ architectures Prior financial services experience preferred Agile Mindset; awareness/understanding of Agile methodologies ## Description The Lead Application Security Engineer is responsible for working with application development and infrastructure teams to ensure applications are designed, coded, and implemented securely. You will be responsible for Integrating security best practices and controls into all phases of the Software Development Lifecycle (SDLC), including requirements, design, development, testing, deployment, and maintenance. You will drive the improvement of policies, standards, and other supporting documentation. This is a hands-on technical position that you will find yourself collaborating with multiple groups across the organization. Strong communication skills are needed to explain complex security to a wide variety of technical levels. Experience as a developer is helpful, but not required. What you'll be doing Responsibility for the security of Lincoln Financial applications and services Conduct design review, code review, and dynamic analysis Evaluate the security posture of AI/ML systems, including LLM-integrated applications, RAG pipelines, and agentic workflows Identify, communicate, and drive the resolution of vulnerabilities Serve as a subject matter expert for application development and infrastructure teams Communicate effectively with a wide variety of technical levels Perform security assessments of web and mobile applications Research and advocate for new security solutions and technologies Stay current on security trends, vulnerabilities, and testing methods Contribute to related policies, standards, and supporting documentation, This position may be subject to Lincoln's Political Contribution Policy. An offer of employment may be contingent upon disclosing to Lincoln the details of certain political contributions. Lincoln may decline to extend an offer or terminate employment for this role if it determines political contributions made could have an adverse impact on Lincoln's current or future business interests, misrepresentations were made, or for failure to fully disclose applicable political contributions and or fundraising activities. Any unsolicited resumes or candidate profiles submitted through our web site or to personal e-mail accounts of employees of Lincoln Financial are considered property of Lincoln Financial and are not subject to payment of agency fees. Lincoln Financial ("Lincoln" or "the Company") is an Equal Opportunity employer and, as such, is committed in policy and practice to recruit, hire, compensate, train and promote, in all job classifications, without regard to race, color, religion, sex, age, national origin or disability. Opportunities throughout Lincoln are available to employees and applicants are evaluated on the basis of job qualifications. If you are a person with a disability that impedes your ability to express your interest for a position through our online application process, or require TTY/TDD assistance, contact us by calling (866) 922-6543. ## Related Videos - [Securing Your Web Application Pipeline From Intruders](https://www.wearedevelopers.com/videos/53-securing-your-web-application-pipeline-from-intruders) - [From DevOps to Scaled DevOps: How We’re Rebuilding Continuous Delivery as a Platform](https://www.wearedevelopers.com/videos/100018-from-devops-to-scaled-devops-how-we-re-rebuilding-continuous-delivery-as-a-platform) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Real-World Security for Busy Developers](https://www.wearedevelopers.com/videos/1545-real-world-security-for-busy-developers) - [DevOps Maturity Check – a way to balance autonomy and alignment](https://www.wearedevelopers.com/videos/58-devops-maturity-check-a-way-to-balance-autonomy-and-alignment) - [#90DaysOfDevOps - The DevOps Learning Journey](https://www.wearedevelopers.com/videos/548-90daysofdevops-the-devops-learning-journey) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Now is the time for industrialized software development](https://www.wearedevelopers.com/magazine/601-now-is-the-time-for-industrialized-software-development) - [The 8 Best Code Testing Tools](https://www.wearedevelopers.com/magazine/402-the-8-best-code-testing-tools) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs)