Application Security Engineer
Kestra Financial is a wealth management platform dedicated to empowering independent financial professionals—including traditional and hybrid RIAs—to grow their businesses and deliver exceptional client service. We combine advanced business management technology with personalized consulting to provide unmatched scale, efficiency, and support. Our advisor-focused culture is built on innovation and advocacy, enabling advisors to offer comprehensive securities and investment advisory solutions to their clients.
About the role
The Application Security Engineer will be pivotal in integrating security into our development and operations processes. As an expert in development and security, the ideal candidate will foster a culture of shared security responsibility across the entire organization. This position requires a balance of application security know-how and some DevOps experience.
Responsibilities
- Secure Software Development: Ensure security measures are embedded throughout the development lifecycle.
- Tool Management: Manage security tools and solutions.
- Security Assessments: Perform regular security assessments, code reviews, and penetration tests.
- Automation: Integrate security tools, standards, and processes into the CI/CD pipeline and KPI reporting.
- Collaboration: Partner closely with IT and development teams to ensure secure architectural designs and to address application security concerns.
- Training & Culture: Advocate for a strong security culture and provide development teams with secure coding training and resources to help them build secure applications from the start.
- Documentation: Maintain DevSecOps and secure software development documentation to ensure accuracy.
- Continuous Learning: Stay up-to-date with security trends, vulnerabilities, and best practices.
Requirements
- Bachelor’s degree in computer science, IT, or related field.
- 2+ years of proven experience in a similar role.
- A strong understanding of the OWASP Top 10 vulnerabilities.
- Proficiency in Python and basic Javascript, Bash, Powershell, and C# knowledge.
- Hands-on experience with CI/CD tools and integrating security into DevOps processes.
Internal applicants must be in good standing and have a minimum of 1 year of service with Kestra. Internal applicants must also have a minimum of 1 year service in current role unless approved by EVP.
Benefits
- Competitive pay and benefits with a large employer (over 1600 employees nationwide)
- 401(k), health insurance, and a competitive benefits package
- Work in a supportive, collaborative environment committed to professional excellence
- Opportunities for training, development, and long-term growth within the firm
- Tuition reimbursement for qualified expenses
About Kestra
Kestra Holdings offers industry-leading wealth management platforms for independent wealth management professionals nationwide. With an innovative culture that celebrates independence, the company seeks to redefine the future of the advisory industry through superior service, cutting-edge technology, and preeminent resources that every financial professional needs to succeed in the market now and in the years to come. Kestra Holdings companies collectively oversee $123 billion in assets under administration (AUA) and support more than 2,400+ independent financial professionals across the country in delivering comprehensive securities, trust, and investment advisory services to their clients.
Located in the “Silicon Hills” of Austin, Texas, Kestra Holdings offers an experience as unique as the city in which it operates.
Our Mission is Powering Financial Independence, enabling the growth and success of investing clients and the advisors who serve them. We do that by living our values: Serve, Make it Happen, and One team.