ForgeApply · Job listing
AVP, AWS Security Engineer
LPL Financial
See all 311 open roles at LPL Financial →
Tailor your resume for this LPL Financial job in about a minute.
ForgeApply tailors your resume and cover letter to this exact posting, then hands you a ready-to-submit application for LPL Financial's site. Free trial, no card required.
About this role
Where Ambition Meets Innovation
Build a career that matches all your initiative with an impressive dose of innovation. From cutting-edge resources and a collaborative environment to the freedom to make an impact and more, you’ll find the ingredients you need at LPL Financial to shape your success while helping clients pursue their financial goals.
At LPL, security is everyone's responsibility — and the Security & Governance pod within our Cloud Center of Excellence is where that responsibility becomes a property of our AWS landing zone. As AVP, Security & Governance, you raise LPL's cloud security posture to meet the standards of our enterprise Information Security organization and the application and infrastructure teams shipping into the landing zone. Security & Governance is involved in every aspect of CCOE, so you partner closely with the Network Engineering pod within Foundations and collaborate with every other CCOE team and pod. You codify controls in Security Hub CSPM and AWS Config (including custom conformance packs), partner with Security Engineering on Wiz signal, and support our enterprise vulnerability management team — all while staying hands-on in AWS and Terraform. If you'd rather codify a control once than chase it ten times, and want to operate as the security partner to every engineering team in our cloud, this is your seat.
Job Overview: As the AVP, AWS Security Engineer, you are a hands-on senior cloud security engineer in the Security & Governance pod within the Foundations team in LPL's Cloud Center of Excellence (CCOE). At LPL, security is everyone's responsibility, and Security & Governance is involved in every aspect of CCOE — so you partner closely with the Network Engineering pod within Foundations and collaborate with every other team and pod across CCOE (Foundations, Platforms, Containers, Support, Delivery) to raise our cloud security posture to meet the standards of LPL's enterprise Information Security organization and the application and infrastructure teams delivering into our AWS landing zone. You codify controls today in Security Hub CSPM and AWS Config — including custom conformance packs — and you help adopt additional control-management systems as the landscape evolves. You partner with the Security Engineering team within LPL's Information Security organization (a peer of Security Architecture), which manages Wiz, to jointly monitor Wiz signal and drive resolution of Wiz findings; you separately drive resolution of Security Hub findings within CCOE (the two often diverge). You support LPL's enterprise vulnerability management department on cloud-workload findings rather than owning vulnerability management end-to-end, and you contribute directly to the Account Factory for Terraform (AFT) foundational base layer so security baselines are codified into the platform. LPL is an AWS-first CCOE: a multi-account landing zone with 100+ private reusable Terraform modules that enable 60+ AWS services, all delivered through Terraform Cloud and GitHub Actions. You spend the majority of your time hands-on in Terraform, security-findings triage, control authoring, and incident response across LPL's US offices and India Global Capability Center (GCC).
Responsibilities: • Codify and continuously improve LPL's cloud control library — Security Hub CSPM as today's AWS-native control system, AWS Config with custom conformance packs to express controls as code, and additional control-management systems as the landscape evolves — and triage, investigate, and drive resolution of Security Hub findings within CCOE
• Partner with the Security Engineering team within LPL's enterprise Information Security organization (a peer of Security Architecture), which manages Wiz, to jointly monitor Wiz signal and drive resolution of Wiz findings, recognizing that Wiz and Security Hub findings frequently diverge
• Contribute directly to the Account Factory for Terraform (AFT) foundational base layer — security-control modules, Service Control Policies, AWS Config conformance packs, and reference patterns — so the secure-by-default posture is a property of the platform every account inherits
• Support LPL's enterprise vulnerability management department on cloud-workload findings: assist with triage, prioritization, and remediation guidance for findings that originate in or affect AWS, without owning vulnerability management end-to-end
• Operate as the security & governance partner across every CCOE team and pod — Foundations (FinOps, Functional Design Engineering & Strategy, Network Engineering, Monitoring), Platforms, Containers, Support, and Delivery — since Security & Governance is involved in every aspect of CCOE; embed security and governance review into design, code, and delivery touchpoints
• Partner closely and day-to-day with the Network Engineering pod within Foundations (VP, AVP, and engineers) on shared network-security controls: segmentation and micro-segmentation, ingress/egress inspection, encryption in transit, WAF, Shield, and certificate lifecycle
• Collaborate cross-organization with Security Architecture and Security Engineering — peer teams within LPL's Information Security organization — to evaluate, pilot, and operationalize additional security solutions (CNAPP, CSPM, CWPP, runtime defense, DSPM, secrets scanning) and to ensure CCOE's posture meets InfoSec and application-team requirements
• Translate regulatory requirements (FINRA, SEC, PCI, SOX) into automated, code-reviewed controls; lead cloud-security incident response within CCOE's scope as a senior responder; partner with Internal Audit and Information Security on evidence collection, attestation, and audit response; drive blameless post-incident reviews to durable control improvements
• Embed agentic AI capabilities into the team's engineering practice (e.g., Cursor, Claude Code, Bedrock, MCP servers, agentic IaC and review workflows) and into the platform's self-service experience for inter
Salary insight
The midpoint of this range ($167k) is right around the median disclosed salary for Austin roles listed on ForgeApply ($171k across 827 jobs).
See full Security Engineer salary data for Austin →
Based on live postings with disclosed pay on ForgeApply; refreshed daily. Not an estimate of this employer's offer.
Tailor your resume for this LPL Financial role before you apply.
Tailor my resume for this jobSimilar jobs
- Senior AWS DevSecOps Engineer — Accenturefederalservices · Tampa, FL
- Senior AWS Cloud Engineer — "Stride · Remote
- Sr AWS Sales Engineer — Ingram Micro · Remote
- AI DevOps Engineer (AWS) — Capco · US - Orlando
- Senior AWS DevOps / Platform Engineer — Guidehouse · Remote
- AWS Cloud Engineer — Accenturefederalservices · Tampa, FL
- Senior AI Security Engineer — Scopely · IN - Bangalore, India
- Senior AWS Enterprise Architect — Ameriprise · Minneapolis, Minnesota
More like this: Security & Cybersecurity Jobs · Security & Cybersecurity Jobs in Austin · Browse all jobs
Free ATS checker · How to Tailor Your Resume to a Job Description (Step by Step)