Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy
Jobs / Job page
Sr Application Security Engineer image - Rise Careers
Job details

Sr Application Security Engineer

Why Stifel

Stifel strives for a culture that puts its clients and associates first: a culture where everyone belongs, everyone is welcome, and everyone contributes to the success of our clients, their careers, and the firm as a whole.

 

Let’s talk about how you can find your place here at Stifel, where success meets success.

What You'll Be Doing

The Sr. Application Security Engineer is responsible for the secure design and testing of internally developed software and deeply understands security principles, technologies, and methodologies. The Sr Application Security Engineer works with software development teams from design to code implementation, ensuring security is included in the complete software development life cycle. The ideal candidate has a strong technical background and proven leadership experience, with expertise in cybersecurity, software development, automation tools, and scripting languages.

What We're Looking For

  • Perform application security testing using automated tools such as SAST, SCA, and DAST.
  • Evaluate automation testing results for accuracy and assign priority based on risk.
  • Communicate the nature and severity of security concerns to development teams.
  • Provide technical guidance and direction to remediation security weaknesses.
  • Continuously evaluate emerging threats, identify current control gaps, lead the search for software solutions, conduct vendor evaluations, manage proof of concepts, oversee vendor selection, ultimately deploy and manage the selected tool.
  • Identify gaps and propose solutions to increase security efficiency and effectiveness.
  • Assist in documenting secure code guidelines, best practices, and procedures.
  • Assist in the development of processes and solutions to automate repeatable tasks.
  • Stays current on cyber security threats and prevention methods.
  • Mentor junior engineers by providing technical guidance, offering constructive feedback, and fostering a collaborative and supportive environment.

What You'll Bring

  • Working knowledge of cloud computing and associated security risks.
  • Experience with threat modeling and application security risk assessments.
  • Strong analytical and problem-solving skills with the ability to identify and mitigate security risks.
  • Ability to effectively communicate technical topics to technical and non-technical audiences.
  • Understanding of application security principles, methods, and technologies.
  • Ability to prioritize workload and consistently meet deadlines.
  • Security architecture, threat modeling, secure design.
  • Experience conducting security assessments and developing remediation strategies.

Education & Experience

  • Minimum Required: Bachelor's degree in Computer Science, Information Systems, Cybersecurity, or related field; or a related combination of education and experience.
  • Minimum Required: 6+ years combined information security and software development experience.

Licenses & Credentials

  • Minimum Required: None.

Systems & Technology

  • Experience with application security testing, such as SAST, DAST, and SCA.
  • Preferred: C#, Angular, and Python programming experience.
  • Preferred: Experience in cloud platforms, AWS or Microsoft Azure.
  • Preferred: Security certification CISSP, CSSLP, GIAC, or similar.

About Stifel

Stifel is more than 130 years old and still thinking like a start-up.  We are a global wealth management and investment banking firm serious about innovation and fresh ideas.  Built on a simple premise of safeguarding our clients’ money as if it were our own, coined by our namesake, Herman Stifel, our success is intimately tied to our commitment to helping families, companies, and municipalities find their own success.

 

While our headquarters is in St. Louis, we have offices in New York, San Francisco, Baltimore, London, Frankfurt, Toronto, and more than 400 other locations.  Stifel is home to approximately 9,000 individuals who are currently building their careers as financial advisors, research analysts, project managers, marketing specialists, developers, bankers, operations associates, among hundreds more.  Let’s talk about how you can find your place here at Stifel, where success meets success.

 

At Stifel we offer an entrepreneurial environment, comprehensive benefits package to include health, dental and vision care, 401k, wellness initiatives, life insurance, and paid time off.

 

Stifel is an Equal Opportunity Employer.

Average salary estimate

$135000 / YEARLY (est.)
min
max
$120000K
$150000K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

What You Should Know About Sr Application Security Engineer, Stifel

Are you ready to take your skills to the next level? At Stifel, we're looking for a dynamic Sr Application Security Engineer to join our innovative team in Saint Louis. Here, we cultivate a culture that prioritizes our clients and associates, ensuring that everyone feels welcome, valued, and empowered to contribute to our success. In this vital role, you will be responsible for securing the design and testing of our internally developed software, working closely with our talented development teams throughout the entire software development life cycle. You'll leverage your strong technical background, expertise in cybersecurity, and leadership skills to implement robust security measures and guide the remediation of security weaknesses. From performing application security testing using cutting-edge automated tools to mentoring junior engineers and evaluating emerging threats, you'll make a significant impact on our security posture. Your responsibilities will also include developing secure code guidelines and proposing innovative solutions to enhance security efficiency. If you are a problem-solver with a passion for technology and a commitment to security principles, we’d love to have you on board at Stifel, where your success is intertwined with our commitment to safeguarding our clients’ assets and facilitating their growth. Let’s explore how you can thrive in this unique environment and be part of our success story.

Frequently Asked Questions (FAQs) for Sr Application Security Engineer Role at Stifel
What are the responsibilities of a Sr Application Security Engineer at Stifel?

As a Sr Application Security Engineer at Stifel, you will be engaged in secure software design and testing processes. Your primary responsibilities will involve conducting application security testing using automated tools, evaluating risk levels, and guiding development teams in remediating security vulnerabilities. You will also document best practices, mentor junior engineers, and stay updated on emerging cybersecurity threats. This role is pivotal in integrating security throughout the software development life cycle.

Join Rise to see the full answer
What qualifications are required for the Sr Application Security Engineer position at Stifel?

To qualify for the Sr Application Security Engineer role at Stifel, candidates should have a minimum of a Bachelor's degree in Computer Science, Cybersecurity, or a related field, alongside 6+ years of combined experience in information security and software development. Familiarity with application security principles, threat modeling, cloud computing security risks, and experience with languages like C#, Angular, and Python will be advantageous.

Join Rise to see the full answer
How does Stifel support the professional development of a Sr Application Security Engineer?

At Stifel, we understand the importance of continuous professional development. As a Sr Application Security Engineer, you'll have the opportunity to mentor junior engineers, providing guidance and constructive feedback. Stifel also encourages you to stay current with evolving cybersecurity threats and methodologies, ensuring you have the resources and support needed for your growth in the industry.

Join Rise to see the full answer
What tools and technologies does a Sr Application Security Engineer use at Stifel?

In the role of Sr Application Security Engineer at Stifel, you will utilize various application security testing tools like SAST, DAST, and SCA. Additionally, experience with automation tools, cloud platforms like AWS or Microsoft Azure, and programming languages, such as C# and Python will be beneficial in driving your projects forward and enhancing security measures.

Join Rise to see the full answer
What is the company culture like for a Sr Application Security Engineer at Stifel?

The company culture at Stifel is built on inclusivity, innovation, and a commitment to success. As a Sr Application Security Engineer, you will thrive in an entrepreneurial environment that values collaboration and encourages creative problem-solving. At Stifel, we are invested in our associates' careers and offer a supportive atmosphere where everyone's contributions are appreciated.

Join Rise to see the full answer
Common Interview Questions for Sr Application Security Engineer
How do you approach application security testing?

In approaching application security testing, I begin by understanding the full scope of the application being tested, followed by selecting appropriate automated tools like SAST and DAST. It's crucial to analyze the results to identify vulnerabilities and communicate these effectively to the development team, ensuring that fixes are prioritized based on risk.

Join Rise to see the full answer
Can you explain your experience with threat modeling?

Certainly! My experience with threat modeling involves identifying potential threats to an application during the design phase. I conduct risk assessments to prioritize these threats and work collaboratively with development teams to devise effective mitigation strategies that enhance the overall security of the application.

Join Rise to see the full answer
What’s your process for remediating security vulnerabilities?

My process for remediating security vulnerabilities typically starts with conducting a thorough analysis of the identified issue. I then prioritize vulnerabilities based on their risk levels and collaborate with the development team to implement effective fixes. After remediation, I perform retesting to ensure that vulnerabilities are effectively closed.

Join Rise to see the full answer
Describe a challenging security issue you’ve faced and how you resolved it.

In a previous role, I encountered a critical vulnerability that could lead to data exposure. I immediately collaborated with my team to perform a root cause analysis and identified the flaw within the code. By guiding the team toward implementing a secure coding practice and conducting thorough testing, we successfully mitigated the risk and improved our security framework.

Join Rise to see the full answer
How do you keep yourself updated with the latest cybersecurity trends?

To stay updated on the latest cybersecurity trends, I regularly read industry blogs, participate in webinars, and attend conferences. Engaging with professional networks and forums also helps me exchange knowledge and insights with other security professionals, allowing me to adapt to the ever-evolving security landscape.

Join Rise to see the full answer
What programming languages are you proficient in and how do they help in security engineering?

I am proficient in programming languages such as C#, Angular, and Python. These languages are beneficial in security engineering as they allow me to understand application behaviors deeply and create scripts for automated security testing. This proficiency enables me to identify vulnerabilities effectively and contribute to the development of secure systems.

Join Rise to see the full answer
How do you communicate security issues to non-technical stakeholders?

When communicating security issues to non-technical stakeholders, I prioritize clarity and simplicity. I avoid jargon and focus on explaining the impact of the vulnerability in business terms. Using visuals and analogies can also help convey the significance of these issues, ensuring stakeholders understand the risks and the importance of mitigation strategies.

Join Rise to see the full answer
What role does automation play in your security practice?

Automation plays a vital role in my security practice, particularly in application security testing. By employing automated tools for SAST, DAST, and SCA, I can efficiently conduct repetitive security assessments. This allows me to focus on critical issues that require manual intervention while enhancing the overall accuracy and speed of security processes.

Join Rise to see the full answer
How do you evaluate new security tools?

When evaluating new security tools, I consider several factors such as the tool’s capabilities, compatibility with our existing systems, user-friendliness, and support from the vendor. Conducting proof-of-concept tests helps determine the tool’s effectiveness in addressing our specific security challenges and fits within our overall security strategy.

Join Rise to see the full answer
What best practices do you recommend for secure coding?

Best practices for secure coding include conducting regular code reviews, implementing input validation, avoiding hard-coded secrets, and applying the principle of least privilege. Ensuring comprehensive testing and keeping security documentation updated can significantly enhance code security, reduce vulnerabilities, and foster a security-conscious development culture.

Join Rise to see the full answer
Similar Jobs
Posted 7 days ago

Join Stifel as a Bank Systems Analyst where you'll support the integration of banking and payment systems in a growing financial firm.

Join Stifel as a Summer Analyst in Phoenix, where you will gain invaluable experience in public finance and investment banking.

Photo of the Rise User

Join Compass as a Senior Manager in Incident Response & Forensics, leading vital security practices in a groundbreaking real estate firm.

Photo of the Rise User
Visa Remote Bogota, Colombia
Posted 10 days ago

Join Visa as a DevOps Consultant and play a crucial role in managing code deployments and enhancing our digital payment solutions.

Photo of the Rise User
Posted 6 days ago

As a key leader in a Fortune 500 company, you'll spearhead DevOps initiatives to enhance IT capabilities and drive a culture of innovation and agile delivery.

Photo of the Rise User

Join Scientific Research Corporation as a Joint Interface Control Officer (JICO) and support the Air Force with critical Tactical Datalink operations.

Photo of the Rise User
Experis Hybrid Rancho Cordova, CA
Posted 6 days ago

We are looking for a Senior Computer Operator to provide mentorship and process improvements within a renowned technology organization.

Photo of the Rise User
Peraton Hybrid Herndon
Posted 12 days ago

Join Peraton as an Oracle Database Administrator, where you will play a crucial role in managing and optimizing critical production databases.

NCS Australia is on the hunt for a Senior Infrastructure Engineer to lead the implementation of Microsoft 365 services in a transformative tech environment.

Posted 13 days ago

GDT seeks a Service Provider Solutions Architect to drive technical design and foster client relationships in a remote role.

MATCH
VIEW MATCH
FUNDING
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
No info
HQ LOCATION
No info
EMPLOYMENT TYPE
Full-time, on-site
DATE POSTED
April 18, 2025

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!
LATEST ACTIVITY
Photo of the Rise User
Someone from OH, Perrysburg just viewed Sourcing Leader, Minerals & Cullet at Owens Corning
Photo of the Rise User
Someone from OH, North Royalton just viewed Remote AI Voice Trainer (High-Quality Microphone Required) at Datadog
C
Someone from OH, Akron just viewed Phlebotomy Technician - Outpatient at CCF
Photo of the Rise User
Someone from OH, Solon just viewed Graphic Designer at Applause
Photo of the Rise User
Someone from OH, North Canton just viewed NodeJs developer at BlackStone eIT
Photo of the Rise User
Someone from OH, North Canton just viewed Software Development Engineer - Recent Grads Welcome at Sonos
Photo of the Rise User
16 people applied to SOC Analyst I at CBIZ
Photo of the Rise User
Someone from OH, Dayton just viewed Data Entry and Word Processing at MoxieIT
Photo of the Rise User
Someone from OH, Dayton just viewed Content Developer - Intern at Big Ideas Learning
Photo of the Rise User
Someone from OH, Pickerington just viewed Salesforce Lead at Bounteous
Photo of the Rise User
Someone from OH, Pickerington just viewed Industry Lead - High Tech (Salesforce) at Thunder
D
Someone from OH, Akron just viewed Junior Motion Designer at DEPT®
R
Someone from OH, Akron just viewed 2D Graphic and Motion Designer at Ruby Labs