Lead Security Engineer
Raymond James Financial Services
Lead Vulnerability Research EngineerThe financial services industry is continuously targeted by sophisticated cyber adversaries ranging from criminal organizations to nation-state actors. Raymond James relies on the Cyber Threat Center (CTC) to identify, assess, and reduce technology risk across the enterprise. The Lead Vulnerability Research Engineer will be a hands-on technical leader within Vulnerability Management, responsible for discovering, validating, and operationalizing knowledge of vulnerabilities that present credible risk to the firm. The role combines threat-informed vulnerability research, offensive security, software engineering, data analysis, and security automation. The engineer will investigate emerging vulnerabilities and attack techniques; determine exploitability, reachability, and enterprise relevance; and convert research into repeatable detection, prioritization, validation, and remediation capabilities at scale. The engineer will responsibly apply AI-assisted techniques to accelerate hypothesis generation, code and patch analysis, test development, finding correlation, exploit-path reasoning, and remediation guidance. AI output must remain subject to rigorous human validation, security and privacy controls, reproducibility standards, and measurable quality outcomes. The role will partner across threat intelligence, security operations, application security, infrastructure, cloud, engineering, architecture, and technology risk teams to reduce exposure before adversaries can act.This position follows a hybrid work model, with an expectation to be in the office 3 days per week at the St. Petersburg, FL Corporate Office location.ResponsibilitiesLead threat-focused vulnerability research across enterprise applications, APIs, operating systems, network devices, cloud services, containers, open-source components, commercial products, and emerging AI-enabled technologies.Continuously analyze threat intelligence, vendor advisories, public exploit research, malware and campaign reporting, security-research disclosures, and internal telemetry to identify vulnerabilities with credible relevance to the enterprise.Perform authorized, controlled technical research to validate vulnerability conditions, affected versions, attack prerequisites, exploitability, reachability, likely impact, and available mitigations without creating unnecessary operational risk.Reproduce vulnerabilities in isolated lab environments; analyze patches, source code, binaries, configurations, protocols, and proof-of-concept artifacts; and create defensible evidence that distinguishes theoretical exposure from actionable risk.Develop safe detection and validation content such as authenticated checks, queries, signatures, scripts, test harnesses, configuration assessments, and exposure analytics. Ensure research artifacts are reviewed, version-controlled, documented, and designed to avoid disruption.Build production-quality automation and integrations that ingest, normalize, enrich, correlate, deduplicate, prioritize, ticket, route, retest, and close vulnerability findings across scanners, asset inventories, threat-intelligence sources, software inventories, cloud platforms, endpoint tools, and engineering systems.Create threat-informed prioritization models that incorporate active exploitation, adversary behavior, exploit maturity, internet exposure, asset criticality, application context, business service dependency, reachability, compensating controls, data sensitivity, and remediation feasibility.Use AI-assisted research capabilities to summarize technical evidence, identify likely vulnerable code paths, compare patches, generate and refine test hypotheses, correlate findings, propose validation steps, and draft remediation guidance.Evaluate and govern AI-assisted security workflows for accuracy, hallucination, prompt injection, insecure output, sensitive-data exposure, excessive agency, model and dependency supply-chain risk, reproducibility, auditability, and appropriate human oversight.Design human-in-the-loop controls and benchmark AI-assisted workflows using measurable outcomes, including precision, recall, false-positive and false-negative rates, analyst time saved, validation quality, remediation quality, and reduction in time to protective action.Provide rapid technical analysis for high-risk and actively exploited vulnerabilities, including concise impact assessments, affected-asset logic, interim mitigations, detection opportunities, validation procedures, and executive-ready risk communication.Conduct root-cause and recurring-pattern analysis to identify systemic weaknesses in technology selection, configuration, software dependencies, asset visibility, patch processes, or control coverage; recommend durable preventive improvements.Partner with remediation owners to explain technical risk, validate fixes and compensating controls, resolve disputed findings, and support risk-based decisions while maintaining clear evidence and accountability.Define and report program metrics such as research-to-detection time, time to enterprise impact assessment, vulnerable-asset identification coverage, validation accuracy, remediation aging, recurrence, automation effectiveness, and measurable risk reduction.Mentor engineers and analysts, establish research standards and playbooks, contribute to technical strategy and roadmaps, and serve as an escalation point for complex vulnerability questions and significant cybersecurity incidents.QualificationsKnowledge, Skills, and Abilities:Demonstrated expertise identifying, validating, explaining, and remediating application and API vulnerabilities, including vulnerability classes represented in the OWASP Top 10 and OWASP API Security Top 10.Advanced understanding of authentication, authorization, session management, cryptography, input handling, deserialization, server-side request forgery, business-logic abuse, and modern client/server attack surfaces.Hands-on experience with SAST, DAST, IAST, SCA, API testing, secrets detection, container scanning, infrastructure-as-code scanning, and penetration-testing tools; ability to tune controls and validate tool output rather than rely solely on scanner severity.Strong automation and software engineering capability in Python and at least one of PowerShell, JavaScript/TypeScript, Go, Java, C#, or shell; experience consuming REST/GraphQL APIs, processing structured data, writing tests, and maintaining production-quality code.Experience integrating security tools with CI/CD and engineering platforms such as GitHub, GitLab, Azure DevOps, Jenkins, Jira, or comparable technologies.Demonstrated experience applying AI-assisted or machine-learning-enabled security tooling to source-code review, vulnerability triage, exploit-path analysis, test generation, remediation support, or finding correlation.Ability to critically evaluate AI output, recognize hallucinations and insecure recommendations, protect sensitive source code and data, design human-in-the-loop validation, and establish measurable quality and governance controls.Knowledge of secure AI-assisted development risks, including prompt injection, insecure output handling, excessive agency, sensitive information disclosure, model or dependency supply-chain concerns, and misuse of generated code.Experience securing cloud-native applications on Microsoft Azure, Amazon Web Services, and/or Google Cloud Platform, including identity, secrets, workloads, APIs, containers, serverless services, and Kubernetes.Working knowledge of threat modeling, secure architecture principles, software supply-chain security, SBOM/VEX concepts, artifact integrity, dependency governance, and provenance or attestation practices.Ability to communicate technical risk clearly to developers, architects, executives, auditors, and non-technical stakeholders, and to translate findings into prioritized engineering actions.Ability to lead through influence, exercise sound judgment under uncertainty, mentor others, and balance security outcomes with client and business needs.Education/Previous Experience:Typically requires a Bachelor's degree in computer science, software engineering, cybersecurity, information systems, artificial intelligence, data science, engineering, or a related field and five or more years of relevant experience. An equivalent combination of education, training, industry research, and demonstrated technical experience may be considered.Typically requires three or more years of hands-on experience in vulnerability research, vulnerability management engineering, offensive security, penetration testing, exploit validation, security tooling development, detection engineering, product security, application security, or a closely related discipline.Demonstrated hands-on experience using leading large language model platforms, including OpenAI GPT models and Anthropic Claude models, for security research, code and patch analysis, hypothesis generation, finding correlation, exploit-path reasoning, test development, technical writing, and remediation support.Experience designing, building, and maintaining reusable AI capabilities such as custom GPTs, Agent Skills, agents, subagents, prompt and context libraries, tool-enabled workflows, and multi-step analysis pipelines that encode repeatable vulnerability-research methods and produce consistent, auditable outputs.Experience developing automated or agentic workflows using model APIs and orchestration frameworks, including OpenAI's Responses API and Agents SDK, Anthropic's API and agent tooling, function or tool calling, structured outputs, retrieval-augmented generation, Model Context Protocol integrations, and secure connections to enterprise data and systems.Demonstrated ability to translate analyst procedures into repeatable AI-assisted workflows for vulnerability intake, advisory and patch analysis, exposure assessment, proof-of-concept review, affected-asset identification, threat-informed prioritization, remediation guidance, retesting, reporting, and knowledge capture.Practical experience evaluating multiple models and selecting fit-for-purpose approaches based on reasoning quality, coding performance, context requirements, latency, cost, privacy, data residency, and security constraints rather than relying on a single model or provider.Demonstrated experience developing security automation and integrating vulnerability data, AI-assisted analysis, and security controls with CI
- ...Lead Engineer For ServiceNow Solutions Team Raymond James is seeking a Lead Engineer for our ServiceNow Solutions team. The ServiceNow... ...on factors such as reporting formats required, costs, and security needs to determine hardware configuration. Participates in...SuggestedWork experience placementWork at office3 days per week
- ...Wealth management firm seeks a Lead Salesforce Engineer to own the delivery and evolution of its RIA CRM platform. Hands-on leadership role: architecting, configuring, and extending customized Salesforce environments while overseeing implementation, QA, data migrations...SuggestedWork at officeLocal area
- ...Acron Aviation (Avionics – Recorders): Acron Aviation designs, engineers, and manufactures certified avionics systems that support... ...Position Summary We are seeking a highly skilled and experienced Lead Systems Project Engineer to lead the design, development,...SuggestedFor subcontractor
$121.2k - $218.2k
...Join to apply for the Application Security Architect role at Jabil 1 day ago Be among the... ...impact IT solutions and their use involving leading edge technologies and methods... ...architects, domain specialists and application engineers to advance and deliver solutions Consult...SuggestedTemporary workPart timeWork at officeLocal area$145.64k
...DUTIES: Leads and participates in assigned projects using Azure DevOps tools. Writes and/or supplements work item instructions... ...expectations, and supported frameworks, ensuring compliance with security and quality standards. Maintains technical specification...SuggestedInterim roleShift work- ...Traffic in Arms Regulations (ITAR) and other U.S. government security regulations. Candidates for these positions should be a "U.... ...hear from you! Learn More About PPS Job Purpose The Lead Mechanical Engineer serves as the technical leader for the design, development,...Permanent employmentTemporary workLocal areaFlexible hours
- ...Job Description Job Description Description: Overview Dynasty Financial Partners is hiring a Lead Salesforce Engineer to lead the delivery and ongoing evolution of Dynasty’s CRM Platform for RIAs across the Dynasty network. This is a hands-on leadership role...
$139k - $176.7k
...Manager, Software Engineering The Manager, Software Engineering leads the engineering team behind the Cost Engine. A core API and backend service that standardizes... ...run-vs-change, keeping the platform healthy (security, reliability, and maintenance work) while still...Full timeWork at officeLocal areaVisa sponsorshipFlexible hours- ...Software Engineering Manager Raymond James is seeking an experienced Software Engineering Manager to spearhead delivery of a critical... ...ensure end-to-end process and data integration are achieved. Leads projects to successful completion as defined by predetermined project...Work experience placementNight shift
- ...Process Engineering ManagerIn this role, you will be responsible for managing Process Engineering activities within the Technical Management group.General Managerial DutiesPerforms all normal supervisory functions, to include hiring, training, appraisal, counseling, and...Work at office
- ...Job Description Position Title : Senior Security Researcher Location : St. Petersburg... ...looking for a committed Software Test Engineer to join our Cyber Security team. You will... ...MS-DOS, PowerShell, etc. Experience leading customer-witnessed, CNO program acceptance...Full timeTemporary workWork at officeLocal areaRemote workFlexible hours
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Lead Security Engineer. Be the first to apply!


