Haystack
← Back to Jobs
Full time
Technology
EJ

Application Security Engineer

Edward JonesSaint Louis, Missouri🇺🇸United StatesPosted Sep 10, 2026

Why This Role Stands Out

This hybrid Application Security Engineer role at Edward Jones offers a fantastic opportunity to shape security for critical financial platforms, leveraging your expertise in secure SDLC and threat modeling to mentor teams and drive innovation. You'll thrive here if you're a mid-senior engineer passionate about building secure solutions and contributing to a collaborative, growth-oriented culture. Apply now to make a significant impact while enjoying valuable flexibility.

Quick Overview

Seniority
Mid Senior
Employment type
Full Time
Work mode
Hybrid
Location
Saint Louis, Missouri, United States
OWASPC#Java

Job Description

Edward Jones is seeking an experienced Application Security Engineer IV to strengthen security across our financial platforms. In this senior role, you will lead secure SDLC practices, perform threat modeling and code review, and integrate security tooling into CI/CD pipelines. You will partner closely with development, architecture, and infrastructure teams to design secure solutions, remediate vulnerabilities, and guide risk-based decisions. You will mentor engineers, contribute to security standards, and help safeguard client data and critical financial systems in a collaborative, growth-oriented culture.

Responsibilities

  • Lead application security design, reviews, and standards for financial platforms
  • Perform threat modeling, secure code reviews, and security testing across applications
  • Integrate and tune security tools (SAST, DAST, SCA, IAST) within CI/CD pipelines
  • Collaborate with engineering and architecture teams to design secure solutions
  • Identify, prioritize, and drive remediation of application vulnerabilities and risks
  • Develop and champion secure SDLC practices and security guidelines
  • Mentor developers and junior security engineers on application security best practices
  • Partner with risk, compliance, and infrastructure teams on security requirements
  • Contribute to incident response and root cause analysis for application issues
  • Continuously evaluate emerging application security threats and technologies

Required Skills

  • Application security engineering
  • Secure SDLC implementation
  • Threat modeling
  • Secure code review
  • SAST/DAST/SCA tooling
  • Vulnerability management
  • CI/CD pipeline security
  • Web and API security (OWASP Top 10)
  • Cloud application security
  • Programming (Java, C#, or similar)

Similar jobs