Prepin
Log in
Edward Jones

engineering opportunity

Application Security Engineer IV - AI Harness

The engineer will operate and maintain an AI-enabled application security harness to evaluate source code for vulnerabilities throughout the SDLC. They will also monitor harness health, troubleshoot integration issues, and ensure findings are actionable for development teams.

United StateshybridFULL_TIME

Posted

About the role

What will you do at Edward Jones?

OPPORTUNITY OVERVIEW

Team Overview:

The Application Security Engineer, Agentic Secure Code Harness Engineer is a

hands-on role responsible for operating, monitoring, and improving an AI-enabled

AppSec harness used to evaluate application and infrastructure source code for

security vulnerabilities and insecure-design practices throughout the Secure

SDLC lifecycle. The role focuses on harness health, observability, reliability,

troubleshooting, evidence capture, and day-to-day operability of the AppSec

process.

The engineer partners with AppSec, DevSecOps, platform engineering, AI

governance, and application teams to ensure reliability, accuracy of findings,

and recommendations are actionable, evidence is repeatable, developer workflows

remain aligned to the secure SDLC, AI model governance, and financial-services

control expectations.

What You'll Do

  • * Operate and maintain the AI secure-code evaluation harness for source code
  • repositories, SDLC and lifecycle changes, and agentic security workflows.
  • * Monitor harness health across ingestion, orchestration, model routing,
  • scanner integration, executions, evidence generation, remediations, and
  • reporting.
  • * Build and tune observability dashboards and alerts for run success, queue
  • depth, latency, cost management, model/API availability, regression failures,
  • missing evidence, and integration outages.
  • * Troubleshoot issues across development tooling such as: Jenkins, GitHub
  • Actions, GitHub Enterprise, Atlassian, AppSec scanners, context tools,
  • logging platforms, artifact repositories, and harness components.
  • * Execute recurring operational routines, including run validation, readiness
  • checks, benchmark refreshes, regression reviews, evidence-quality checks, and
  • post-run reconciliation.
  • * Maintain runbooks, SOPs, support playbooks, recovery steps, known-error
  • documentation, and escalation paths.
  • * Support secure ingestion and handling of source code, artifacts, scanner
  • output, SBOMs, metadata, golden datasets, logs, and evidence packages.
  • * Maintain benchmark suites, golden test cases, prompt/model configuration
  • records, retrieval settings, scoring rubrics, and operational test data.
  • * Validate that findings flow into developer workflows with context, severity,
  • confidence, remediation guidance, traceability, and rejection rationale where
  • applicable.
  • * Collect audit-ready evidence aligned to NIST SSDF, NIST CSF 2.0, NYDFS,
  • FINRA, SOX ITGC, FFIEC, GLBA, internal AI governance, and technology risk
  • controls.
  • * Report operational KPIs including run availability, failed-run rate, MTTR,
  • validation cycle time, evidence completeness, cost per validated finding,
  • false-positive trends, and developer remediation adoption.
  • * Drive automation that reduces manual triage, improves repeatability, lowers
  • operational toil, and increases developer trust in AI-assisted AppSec
  • outcomes.
  • POSITION REQUIREMENTS
  • What Experience You'll Need:
  • * Bachelor’s degree in Computer Science, Cybersecurity, Software Engineering,
  • Information Technology, Engineering, or related field, or equivalent
  • practical experience.
  • * 6+ years of experience in application security, secure software engineering,
  • DevSecOps, platform engineering, security operations, or related
  • cybersecurity engineering roles.
  • * Hands-on experience supporting security capabilities across CI/CD, source
  • control, ticketing, artifact management, logging, and AppSec reporting
  • workflows.
  • * Working knowledge of secure code review, vulnerability triage, exploitability
  • analysis, remediation validation, threat modeling concepts, and secure SDLC
  • practices.
  • * Practical experience with SAST, SCA, DAST, secrets scanning, API security
  • testing, container security, IaC scanning, SBOMs, SARIF, and findings
  • management.
  • * Experience with Jenkins, GitHub Actions, GitHub Enterprise, Jira/Azure
  • DevOps, developer portals, observability platforms, and AppSec dashboards.
  • * Strong understanding of logs, metrics, traces, health checks, alert
  • thresholds, run manifests, error budgets, and incident response routines.
  • * Ability to automate operational workflows using Python, shell scripting,
  • APIs, configuration files, and infrastructure or policy-as-code patterns.
  • * Familiarity with LLM or AI-assisted engineering concepts such as prompts,
  • model versions, retrieval configurations, guardrails, token usage, latency,
  • cost tracking, and drift monitoring.
  • * Understanding of secure handling requirements for proprietary source code,
  • credentials, logs, telemetry, evidence packages, and regulated
  • financial-services data.
  • * Working knowledge of OWASP Top 10, CWE, CVSS, NIST SSDF, NIST CSF 2.0, AI
  • security risks, auditability, and regulated source-code handling.
  • What Could Set You Apart:
  • * Certifications such as CISSP, CSSLP, CCSP, AWS/Azure security, Kubernetes
  • security, GIAC application security, or AI governance.
  • * Experience operating AI-assisted AppSec, software assurance, or
  • vulnerability-validation platforms in a Fortune 500 or regulated
  • financial-services environment.
  • * Hands-on experience with observability platforms, SIEM integrations,
  • telemetry pipelines, operational dashboards, SLIs, and alert tuning.
  • * Experience supporting LLM-enabled workflows, including prompt evaluation,
  • regression testing, guardrail monitoring, model routing, cost governance, and
  • human-in-the-loop review.
  • * Experience maintaining benchmark datasets, golden test cases, validation
  • pipelines, custom static-analysis rules, or exploitability-validation
  • workflows.
  • * Track record reducing AppSec operational toil, improving evidence
  • completeness, lowering false positives, improving run reliability, and
  • accelerating developer remediation
  • **Candidates that live within a commutable distance from our Tempe, AZ and St.
  • Louis, MO home office locations are expected to work in the office four days per
  • week effective June 1, 2026. Before June 1, 2026, candidates that live within a
  • commutable distance from our Tempe, AZ and St. Louis, MO home office locations
  • are expected to work in the office three days per week, with preference for
  • Tuesday through Thursday.**
  • COMPANY DESCRIPTION
  • Join a financial services firm where your contributions are valued. Edward
  • Jones is a Fortune 500¹ company where people come first. With over 9 million
  • clients and 20,000 financial advisors across the U.S. and Canada, we’re proud to
  • be privately-owned, placing the focus on our clients rather than shareholder
  • returns.
  • Behind everything we do is our purpose: We partner for positive impact to
  • improve the lives of our clients and colleagues, and together, better our
  • communities and society. We are an innovative, flexible, and inclusive
  • organization that attracts, develops, and inspires performance excellence and a
  • sense of belonging.
  • People are at the center of our partnership. Edward Jones associates are seen,
  • heard, respected, and supported. This is what we believe makes us the best place
  • to start or build your career.
  • View our Purpose, Inclusion and Citizenship Report
  • [https://careers.edwardjones.com/blog/edward-jones-releases-annual-purpose-inclusion-and-citizenship-report/?codes=DIRECT&utm_source=DIRECT].
  • ¹Fortune 500, published June 2024, data as of December 2023.

Compensation

provided for using, not obtaining, the rating.

AWARDS AND ACCOLADES

At Edward Jones, we are building a place where everyone feels like they belong.

We're proud of our associates' contributions to the firm and the recognitions we

have received.

Check out our U.S. awards and accolades: Insights & Information Blog Postings

about Edward Jones

[https://careers.edwardjones.com/blog/? _sft_category=awards-accolades]

Check out our Canadian awards and accolades: Insights & Information Blog

Postings about Edward Jones

[https://careers.edwardjones.com/en-CA/blogs/? _sft_category=awards-accolades-en-ca]

EEO STATEMENT

Edward Jones does not discriminate on the basis of race, color, gender,

religion, national origin, age, disability, sexual orientation, pregnancy,

veteran status, genetic information or any other basis prohibited by applicable

law.

SALARY INFORMATION

Edward Jones' compensation and benefits package includes medical and

prescription drug, dental, vision, voluntary benefits (such as accident,

hospital indemnity, and critical illness), short- and long-term disability,

basic life, and basic AD&D coverage. Short- and long-term disability, basic

life, and basic AD&D coverage are provided at no cost to associates. Edward

Jones offers a 401k retirement plan, and tax-advantaged accounts: health savings

account, and flexible spending account. Edward Jones observes ten paid holidays

and provides 15 days of vacation for new associates beginning on January 1 of

each year, as well as sick time, personal days, and a paid day for

volunteerism. Associates may be eligible for bonuses and profit sharing. All

associates are eligible for the firm's Employee Assistance Program. For more

information on the Benefits available to Edward Jones associates, please visit

our benefits page

[https://secure.edwardjonesbenefits.com/fleet/public/index/f914262d-0362-4682-bd1e-0ccd25f1dfb1].

Which skills does this role require?

Application securityDevSecOpsPythonShell scriptingJenkinsGitHub ActionsSASTSCADASTAPI securityContainer securityIaC scanningLLMVulnerability triageThreat modelingObservabilityApplication SecurityAI-enabledSecure SDLCGitHub EnterpriseSBOMSARIFNIST SSDFNIST CSF 2.0OWASP Top 10CWECVSSInfrastructure-as-CodeAPI SecurityVulnerability ManagementAutomationFinancial ServicesComplianceAuditTelemetryPrompt EngineeringCloud SecurityKubernetesAWSAzureLLMsJira

Make your next move

Build a shortlist and prepare

Identify the requirements you can demonstrate, then choose examples from your work to discuss with the hiring team.

Review the responsibilities and requirements before adding an opening to your shortlist.

Role information can change. Confirm current details on the original application page.

Product

AI Candidate AgentCompaniesBrowse JobsDeep ProfileSkill AssessmentOpportunity Matching
Prepin.ai

© 2026 Prepin | All rights reserved.