Job Overview :
LPL is hiring an Application Security Engineer role for our Information Security team. As a member of the Information Security team, the Application Security Engineer will be responsible for helping to develop, mature, and sustain the Application Security program for the company. Application security is a top area of focus at LPL. We have incorporated key industry security best practices, technologies and integrated processes to further strengthen our defense posture. This is an exciting time to join the Information Security Vulnerability Management team as we are continuing to expand the Application Security program.
Responsibilities :
Learn to perform as an application security SME in the following areas : Web Applications, Mobile Applications, Databases, APIs, Containers and other domains.
Support and maintain application security testing platforms and develop integrations with automation platforms
Create and maintain scan profiles for performing static, authenticated dynamic, IAST, and 3rd party library automated analysis with application scanning tools
Review and analyze vulnerability scan results and track closure of vulnerabilities
Work with Application Development teams to review potential false-positive scan results and evaluate proposed mitigating factors
Perform manual testing of APIs and web applications to identify / validate vulnerabilities
Produce and track application security metrics
Support the secure development and testing of critical Advisor and Investor LPL applications
Mentor and educate product development and quality engineers on secure development and security best practices
Monitor and review CVEs, industry developments, and provide inputs for continuous improvement
Work with Internal Audit, IT Governance, IT Compliance and other key stakeholder groups on specific projects
Develop and maintain enterprise security libraries, components, best practices checklists.
Perform application security risk evaluation, partner with key stakeholders to further enhance application security CI / CD pipeline and continually assess security posture for improvement.
What are we looking for?
We want strong collaborators who can deliver a world-class client experience. We are looking for people who thrive in a fast-paced environment, are client-focused, team oriented, and are able to execute in a way that encourages creativity and continuous improvement.
Requirements :
Bachelor’s Degree in Computer Science, Engineering, or Cyber Security, or 1+ year of professional experience in application security
Core Competencies :
Understanding of OWASP Top 10 Critical Web Application Security Risks, their identification, and architecture, design, coding patterns to mitigate them
Knowledge of secure coding best practices, secure SDLC, secure architecture, and DevSecOps methodologies
Strong analytical, interpersonal and communication skills
Preferred Experience :
Application Development and Security Engineering or Security Architecture experience
Experience using Application Security Code Scanning Tools such as Veracode, Black Duck, Prisma Cloud and J-Frog as well as manual tools such as Burpsuite and Postman
Experience working with security of applications developed in C#, Java, and web (HTML, CSS, JS, React, REST) technologies
Experience working with DevSecOps and CI / CD pipelines
LI-Hybrid
Pay Range :
30.96-$51.59 / hourActual base salary varies based on factors, including but not limited to, relevant skill, prior experience, education, base salary of internal peers, demonstrated performance, and geographic location. Additionally, LPL Total Rewards package is highly competitive, designed to support your success at work, at home, and at play – such as 401K matching, health benefits, employee stock options, paid time off, volunteer time off, and more. Your recruiter will be happy to discuss all that LPL has to offer!
Company Overview :
LPL Financial Holdings Inc. (Nasdaq : LPLA) was founded on the principle that the firm should work for advisors and institutions, and not the other way around. Today, LPL is a leader in the markets we serve, serving more than 23,000 financial advisors, including advisors at approximately 1,000 institutions and at approximately 580 registered investment advisor ("RIA") firms nationwide. We are steadfast in our commitment to the advisor-mediated model and the belief that Americans deserve access to personalized guidance from a financial professional.
At LPL, independence means that advisors and institution leaders have the freedom they deserve to choose the business model, services, and technology resources that allow them to run a thriving business. They have the flexibility to do business their way. And they have the freedom to manage their client relationships, because they know their clients best. Simply put, we take care of our advisors and institutions, so they can take care of their clients.
Join LPL Financial : Where Your Potential Meets Opportunity
At LPL Financial, we believe that everyone deserves objective financial guidance. As the nation’s leading independent broker-dealer, we offer an integrated platform of cutting-edge technology, brokerage, and investment advisor services.
Application Security Engineer • Tempe