Application Security Engineer

Lead with Purpose. Partner with Impact.
Kestra Holdings offers industry-leading wealth management platforms for independent wealth management professionals nationwide. With an innovative culture that celebrates independence, the company seeks to redefine the future of the advisory industry through superior service, cutting-edge technology, and preeminent resources that every financial professional needs to succeed in the market now and in the years to come.
Kestra Holdings companies collectively oversee $123 billion in assets under administration (AUA) and support more than 2,400+ independent financial professionals across the country in delivering comprehensive securities, trust, and investment advisory services to their clients. Located in the “Silicon Hills” of Austin, Texas, Kestra Holdings offers an experience as unique as the city in which it operates.
The Application Security Engineer will be pivotal in integrating security into our development and operations processes. As an expert in development and security, the ideal candidate will foster a culture of shared security responsibility across the entire organization. This position requires a balance of application security know-how and some DevOps experience.

What you’ll Do:

Secure Software Development: Ensure security measures are embedded throughout the development lifecycle.
Tool Management: Manage security tools and solutions.
Security Assessments: Perform regular security assessments, code reviews, and penetration tests.
Automation: Integrate security tools, standards, and processes into the CI/CD pipeline and KPI reporting.
Collaboration: Partner closely with IT and development teams to ensure secure architectural designs and to address application security concerns.
Training & Culture: Advocate for a strong security culture and provide development teams with secure coding training and resources to help them build secure applications from the start.
Documentation: Maintain DevSecOps and secure software development documentation to ensure accuracy.
Continuous Learning: Stay up-to-updated with security trends, vulnerabilities, and best practices.

What You Bring:

Bachelor’s degree in computer science, IT, or related field.
2+ years of proven experience in a similar role.
A strong understanding of the OWASP Top 10 vulnerabilities.
Proficiency in Python and basic Javascript, Bash, Powershell, and C# knowledge.
Hands-on experience with CI/CD tools and integrating security into DevOps processes.

See also

Security jobs by country — openings, pay and top skills →

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available