Application Security Engineer I
LPL FinancialAbout the role
What if you could build a career where ambition meets innovation? At LPL Financial, we empower professionals to shape their success while helping clients pursue their financial goals with confidence.
What if you could have access to cutting-edge resources, a collaborative environment, and the freedom to make an impact? If you're ready to take the next step, discover what’s possible with LPL Financial.
Job Overview:
LPL is hiring an Application Security Engineer role for our Information Security team. As a member of the Information Security team, the Application Security Engineer will be responsible for helping to develop, mature, and sustain the Application Security program for the company. Application security is a top area of focus at LPL. We have incorporated key industry security best practices, technologies and integrated processes to further strengthen our defense posture. This is an exciting time to join the Information Security Vulnerability Management team as we are continuing to expand the Application Security program.
Responsibilities:
Learn to perform as an application security SME in the following areas: Web Applications, Mobile Applications, Databases, APIs, Containers and other domains.
Support and maintain application security testing platforms and develop integrations with automation platforms
Create and maintain scan profiles for performing static, authenticated dynamic, IAST, and 3rd party library automated analysis with application scanning tools
Review and analyze vulnerability scan results and track closure of vulnerabilities
Work with Application Development teams to review potential false-positive scan results and evaluate proposed mitigating factors
Perform manual testing of APIs and web applications to identify/validate vulnerabilities
Produce and track application security metrics
Support the secure development and testing of critical Advisor and Investor LPL applications
Mentor and educate product development and quality engineers on secure development and security best practices
Monitor and review CVEs, industry developments, and provide inputs for continuous improvement
Work with Internal Audit, IT Governance, IT Compliance and other key stakeholder groups on specific projects
Develop and maintain enterprise security libraries, components, best practices checklists.
Perform application security risk evaluation, partner with key stakeholders to further enhance application security CI/CD pipeline and continually assess security posture for improvement.
What are we looking for?
We want strong collaborators who can deliver a world-class client experience. We are looking for people who thrive in a fast-paced environment, are client-focused, team oriented, and are able to execute in a way that encourages creativity and continuous improvement.
Requirements:
Bachelor’s Degree in Computer Science, Engineering, or Cyber Security, or 1+ year of professional experience in application security
Core Competencies:
Understanding of OWASP Top 10 Critical Web Application Security Risks, their identification, and architecture, design, coding patterns to mitigate them
Knowledge of secure coding best practices, secure SDLC, secure architecture, and DevSecOps methodologies
Strong analytical, interpersonal and communication skills
Preferred Experience:
Application Development and Security Engineering or Security Architecture experience
Experience using Application Security Code Scanning Tools such as Veracode, Black Duck, Prisma Cloud and J-Frog as well as manual tools such as Burpsuite and Postman
Experience working with security of applications developed in C#, Java, and web (HTML, CSS, JS, React, REST) technologies
Experience working with DevSecOps and CI/CD pipelines
#LI-Hybrid
Pay Range:
$30.96-$51.59/hourCompany Overview:
LPL Financial Holdings Inc. (Nasdaq: LPLA) was founded on the principle
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s