> Markdown version of [/jobs/ext/2966676-application-security-engineer-iv](https://www.wearedevelopers.com/jobs/ext/2966676-application-security-engineer-iv). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Application Security Engineer IV - **Company:** Edward D. Jones & Co., L.P. - **Location:** St. Louis, MO, United States - **Salary:** $150,000.0 - $180,000.0 - **Contract:** Permanent contract - **Skills:** Java (Programming Language), C Sharp (Programming Language), Software as a Service, Computer Programming, Continuous Integration, Open Web Application Security, Systems Development Life Cycle, Secure Coding, Software Vulnerability Management, Software Security, Static Application Security Testing, Dynamic Application Security Testing - **Published:** September 17, 2026 - **Apply:** https://find.jobs/jobs-near-me/apply/ats-redirect/?id=2975765721-2 ## About the Role * Application security engineering * Secure SDLC implementation * Threat modeling * Secure code review * SAST/DAST/SCA tooling * Vulnerability management * CI/CD pipeline security * Web and API security (OWASP Top 10) * Cloud application security * Programming (Java, C#, or similar) ## Description Edward Jones is seeking an experienced Application Security Engineer IV to strengthen security across our financial platforms. In this senior role, you will lead secure SDLC practices, perform threat modeling and code review, and integrate security tooling into CI/CD pipelines. You will partner closely with development, architecture, and infrastructure teams to design secure solutions, remediate vulnerabilities, and guide risk-based decisions. You will mentor engineers, contribute to security standards, and help safeguard client data and critical financial systems in a collaborative, growth-oriented culture. Responsibilities * Lead application security design, reviews, and standards for financial platforms * Perform threat modeling, secure code reviews, and security testing across applications * Integrate and tune security tools (SAST, DAST, SCA, IAST) within CI/CD pipelines * Collaborate with engineering and architecture teams to design secure solutions * Identify, prioritize, and drive remediation of application vulnerabilities and risks * Develop and champion secure SDLC practices and security guidelines * Mentor developers and junior security engineers on application security best practices * Partner with risk, compliance, and infrastructure teams on security requirements * Contribute to incident response and root cause analysis for application issues * Continuously evaluate emerging application security threats and technologies ## Related Videos - [Software Security 101: Secure Coding Basics](https://www.wearedevelopers.com/videos/220-software-security-101-secure-coding-basics) - [Photonic Computing: Programming a New Class of AI Accelerators (incl. Live Coding)](https://www.wearedevelopers.com/videos/100196-photonic-computing-programming-a-new-class-of-ai-accelerators-incl-live-coding) - [How to Cause (or Prevent) a Massive Data Breach- Secure Coding and IDOR](https://www.wearedevelopers.com/videos/39-how-to-cause-or-prevent-a-massive-data-breach-secure-coding-and-idor) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Unleashing the Power of Developers: Why Cybersecurity is the Missing Piece?!?](https://www.wearedevelopers.com/videos/712-unleashing-the-power-of-developers-why-cybersecurity-is-the-missing-piece) - [How GitHub secures open source](https://www.wearedevelopers.com/videos/1450-how-github-secures-open-source) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [The 8 Best Code Testing Tools](https://www.wearedevelopers.com/magazine/402-the-8-best-code-testing-tools) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing)