What are the responsibilities and job description for the VP, Offensive Security position at LPL Financial?
Are you curious to learn? Are you interested in working on meaningful projects? Do you want to work with cutting-edge technology? Are you interested in being part of a team that is working to transform and do things differently? If so, LPL Financial is the place for you!
Job Overview:
As a member of the Information Security team, the VP of Offensive Security will be responsible for overseeing and maturing the penetration testing function at LPL. This position will be focused on the development and execution of an internal penetration testing program to supplement our existing 3rd party program, with a strong focus on web application testing.
This role will lead a highly technical team charged with performing penetration testing engagements to validate the security of resources across the company. Candidates are expected to perform hands-on testing as well as serve as the team lead of all the penetration testing activities and lead the overall function. The ideal candidate must possess a highly technical skillset and the ability to collaborate with stakeholders across the company to integrate penetration testing within company processes.
Offensive Security is a top area of focus at LPL. This is an exciting time to join the Information Security team as we look to build and greatly expand the current program.
Responsibilities:
We want strong collaborators who can deliver a world-class client experience. We are looking for people who thrive in a fast-paced environment, are client-focused, team oriented, and are able to execute in a way that encourages creativity and continuous improvement.
Requirements:
$143,100-$238,500/year
Actual base salary varies based on factors, including but not limited to, relevant skill, prior experience, education, base salary of internal peers, demonstrated performance, and geographic location. Additionally, LPL Total Rewards package is highly competitive, designed to support your success at work, at home, and at play – such as 401K matching, health benefits, employee stock options, paid time off, volunteer time off, and more. Your recruiter will be happy to discuss all that LPL has to offer!
Company Overview:
LPL Financial Holdings Inc. (Nasdaq: LPLA) was founded on the principle that the firm should work for advisors and institutions, and not the other way around. Today, LPL is a leader in the markets we serve, serving more than 23,000 financial advisors, including advisors at approximately 1,000 institutions and at approximately 580 registered investment advisor ("RIA") firms nationwide. We are steadfast in our commitment to the advisor-mediated model and the belief that Americans deserve access to personalized guidance from a financial professional.
At LPL, independence means that advisors and institution leaders have the freedom they deserve to choose the business model, services, and technology resources that allow them to run a thriving business. They have the flexibility to do business their way. And they have the freedom to manage their client relationships, because they know their clients best. Simply put, we take care of our advisors and institutions, so they can take care of their clients.
Join LPL Financial: Where Your Potential Meets Opportunity
At LPL Financial, we believe that everyone deserves objective financial guidance. As the nation’s leading independent broker-dealer, we offer an integrated platform of cutting-edge technology, brokerage, and investment advisor services.
Why LPL?
Information on Interviews:
LPL will only communicate with a job applicant directly from an @lplfinancial.com email address and will never conduct an interview online or in a chatroom forum. During an interview, LPL will not request any form of payment from the applicant, or information regarding an applicant’s bank or credit card. Should you have any questions regarding the application process, please contact LPL’s Human Resources Solutions Center at (855) 575-6947.
EAC1.22.25
Job Overview:
As a member of the Information Security team, the VP of Offensive Security will be responsible for overseeing and maturing the penetration testing function at LPL. This position will be focused on the development and execution of an internal penetration testing program to supplement our existing 3rd party program, with a strong focus on web application testing.
This role will lead a highly technical team charged with performing penetration testing engagements to validate the security of resources across the company. Candidates are expected to perform hands-on testing as well as serve as the team lead of all the penetration testing activities and lead the overall function. The ideal candidate must possess a highly technical skillset and the ability to collaborate with stakeholders across the company to integrate penetration testing within company processes.
Offensive Security is a top area of focus at LPL. This is an exciting time to join the Information Security team as we look to build and greatly expand the current program.
Responsibilities:
- Partner with other Technology stakeholders to develop the scope and activities of the penetration testing program, including integrating penetration testing within existing company SDLC processes to enhance our ability to identify security weaknesses in applications prior to production deployment
- Build and lead the internal penetration testing team, execute testing, and oversee the execution of all related activities
- Conduct tactical security penetration test assessments to validate the security of company applications (web,mobile, and apis) against OWASP Top 10 threats and work with the Application Security team to provide feedback and recommendations to increase automated capabilities
- Perform assessments of internal/external networks, infrastructure, cloud environments, social engineering and a wide array of internally developed and commercial products.
- Think creatively and strategically to circumvent security controls, identify vulnerabilities and develop effective solutions. Stay informed on ever-emerging and fast-changing TTPs, zero-days and remediation strategies. Develop/modify custom tooling to solve new needs.
- Document and formally report testing initiatives, test findings, justified risk ratings, remediation recommendations and validation results in a clear and concise manner.
- Partner with technology teams to present security testing results, highlight the threat presented by the results, and consult on remediation guidance in a way that is easy for understand for IT stakeholders.
- Partner with the Security Operations Center to perform purple team exercises designed to validate and improve security detections
- Develop and maintain process documentation as well as tools and scripts used in penetration testing and red team processes.
- Ensure penetration testing activities are meeting security and business objectives and outcomes by establishing metrics & key performance indicators (KPIs)
- Establish penetration testing function roadmap, lead the scoping and execution of program improvement initiatives and communicate status to senior leadership
- Manage the 3rd party penetration testing program by identifying vendors, overseeing vendor testing activities and working with Sourcing to develop statement of work documentation and procure such services
- Oversee the communication, reporting, and tracking of findings identified during testing activities, following up with remediation teams to determine status, escalating findings as needed to senior leadership, and performing retesting to validate successful closure of previously identified findings
- Assist with the validation of issues submitted to the company’s Vulnerability Disclosure Program and Bug Bounty programs
We want strong collaborators who can deliver a world-class client experience. We are looking for people who thrive in a fast-paced environment, are client-focused, team oriented, and are able to execute in a way that encourages creativity and continuous improvement.
Requirements:
- 10 years’ experience conducting application/API and network-based penetration-testing/red team engagements.
- 5 years experience leading technical red team/offensive security function
- Advanced level of knowledge with security assessment tools and frameworks, including Burp Suite, Kali Linux, Nessus, Accunetix, Metasploit, AutoSploit, Cobalt Strike, etc.
- At least one industry certification such as OSCP, OSCE, OSWE, GPEN, GCIH, GWAPT, or GXPN.
- Bachelor’s Degree or equivalent in Information Security, Engineering, or Computer Science.
- Experience managing information security teams
- Advanced understanding of OWASP, the MITRE ATT&CK framework and the software development lifecycle (SDLC).
- Advanced knowledge in programming languages (.NET, Javascript, Python, Java, PowerShell, Perl, Ruby, Bash, etc.)
- Advanced level knowledge of Linux/Mac/Windows operating systems, AWS/Azure cloud environments and cloud-native resources (ex. Containers, Kubernetes, microservices, serverless functions)
- Experience with conducting reverse engineering on mobile applications, including applications with anti-emulator and obfuscation protections.
- Breadth and depth of knowledge in security of operating systems, networking and protocols, firewalls, databases and middleware applications, forensics, scripting and programing.
- Good communication skills and ability to working with all stakeholders, internal and external, finding, advising and implementing the best solutions.
- Strong organization skills and people management skills
- Insatiable curiosity for tinkering with and circumventing security features and controls.
$143,100-$238,500/year
Actual base salary varies based on factors, including but not limited to, relevant skill, prior experience, education, base salary of internal peers, demonstrated performance, and geographic location. Additionally, LPL Total Rewards package is highly competitive, designed to support your success at work, at home, and at play – such as 401K matching, health benefits, employee stock options, paid time off, volunteer time off, and more. Your recruiter will be happy to discuss all that LPL has to offer!
Company Overview:
LPL Financial Holdings Inc. (Nasdaq: LPLA) was founded on the principle that the firm should work for advisors and institutions, and not the other way around. Today, LPL is a leader in the markets we serve, serving more than 23,000 financial advisors, including advisors at approximately 1,000 institutions and at approximately 580 registered investment advisor ("RIA") firms nationwide. We are steadfast in our commitment to the advisor-mediated model and the belief that Americans deserve access to personalized guidance from a financial professional.
At LPL, independence means that advisors and institution leaders have the freedom they deserve to choose the business model, services, and technology resources that allow them to run a thriving business. They have the flexibility to do business their way. And they have the freedom to manage their client relationships, because they know their clients best. Simply put, we take care of our advisors and institutions, so they can take care of their clients.
Join LPL Financial: Where Your Potential Meets Opportunity
At LPL Financial, we believe that everyone deserves objective financial guidance. As the nation’s leading independent broker-dealer, we offer an integrated platform of cutting-edge technology, brokerage, and investment advisor services.
Why LPL?
- Innovative Environment: We foster creativity and growth, providing a supportive and responsive leadership team. Learn more about our leadership team here!
- Limitless Career Potential: Your career at LPL has no limits, only amazing potential. Learn more about our careers here!
- Unified Mission: We are one team on one mission—taking care of our advisors so they can take care of their clients. Learn more about our mission and values here!
- Impactful Work: Our size is just right for you to make a real impact. Learn more here!
- Commitment to Equality: We support workplace equality and embrace diverse perspectives and backgrounds. Learn more here!
- Community Focus: We care for our communities and encourage our employees to do the same. Learn more here!
- Benefits and Total Rewards: Our Total Rewards package goes beyond just compensation and insurance. It includes a mix of traditional and unique benefits, perks, and resources designed to enhance your life both at work and at home. Learn more here!
Information on Interviews:
LPL will only communicate with a job applicant directly from an @lplfinancial.com email address and will never conduct an interview online or in a chatroom forum. During an interview, LPL will not request any form of payment from the applicant, or information regarding an applicant’s bank or credit card. Should you have any questions regarding the application process, please contact LPL’s Human Resources Solutions Center at (855) 575-6947.
EAC1.22.25
Salary : $143,100 - $238,500