Innovate here. And see your ideas come to life.
It's an exciting time to work in tech at Edward Jones. We are making massive investments in emerging technologies to improve how we work with our clients and with each other. Relationships are the focus of our business model. And working in Technology here means using your skills to build, deliver and maintain the technologies that enable us to deepen and support those relationships. The best part? We develop and create our own industry-leading solutions internally. And you can be a part of it. Working with emerging new technologies. Creating platforms, programs and experiences that change how we work together - and support our client-first focus. Changing the future of our firm, the industry and the advisor-client relationship.
Job OverviewPosition Schedule: Full-Time
This job posting is anticipated to remain open for 30 days, from 19-Mar-2026. The posting may close early due to the volume of applicants.
Team Overview
The Application Security Penetration Test team is responsible for conducting internal offensive testing and third-party facilitation for firm developed web applications deemed critical or high risk to support early identification of vulnerabilities and validation of existing controls. This reduces the likelihood of exploitation by threat actors and strengthens the organization's overall security posture.
What You'll Do:
As a Penetration Test Engineer IV, you will independently manage and/or facilitate third-party test engagements from scoping through reporting while contributing to the continuous improvement of secure development, DevSecOps, and cybersecurity practices. To support this, you will be responsible for:
Evaluating the security of enterprise applications by conducting hands‑on penetration testing across web, API, and mobile platforms
-
Perform in‑depth assessments of application architectures
-
Identify complex vulnerabilities, and simulate realistic attack scenarios to measure the resiliency of critical systems
-
Execute both manual and tool‑assisted testing
-
Collaborate with development and engineering teams to validate findings
-
Provide clear remediation guidance aligned with industry's best practices
-
Assists with capabilities and ensuring tools remain up to date
-
Develop and mentors' junior engineers
-
Contributes to building team knowledge base, creation, and annual validation of SOPs
-
QA/Peer review of test scenarios and postmortem reports/evidence collection
Edward Jones' compensation and benefits package includes medical and prescription drug, dental, vision, voluntary benefits (such as accident, hospital indemnity, and critical illness), short- and long-term disability, basic life, and basic AD&D coverage. Short- and long-term disability, basic life, and basic AD&D coverage are provided at no cost to associates. Edward Jones offers a 401k retirement plan, and tax-advantaged accounts: health savings account, and flexible spending account. Edward Jones observes ten paid holidays and provides 15 days of vacation for new associates beginning on January 1 of each year, as well as sick time, personal days, and a paid day for volunteerism. Associates may be eligible for bonuses and profit sharing. All associates are eligible for the firm's Employee Assistance Program. For more information on the Benefits available to Edward Jones associates, please visit our benefits page.
Hiring Minimum: $101700
Hiring Maximum: $173200
Read More About Job Overview
Skills/RequirementsWhat Experience You'll Need:-
5+ years of hands‑on penetration testing experience across web, API, and/or mobile applications.
-
Strong subject matter expertise with mobile application development & testing
-
Strong ability to identify, exploit, and document vulnerabilities such as:
-
Authentication and authorization flaws
-
Injection attacks
-
Business logic issues
-
API security weaknesses
-
Client-side security issues
-
Web Application Security
-
Proficiency with web technologies (HTTP/S, REST/GraphQL, cookies, sessions, CORS, JWT)
Hands‑on experience with:-
Web proxies (e.g., Kali Linux, Burp Suite Pro)
-
Browser exploitation tools
-
Mobile Application Security (iOS & Android)
-
Experience testing mobile applications, including:
-
Static and dynamic analysis
-
Reverse engineering basics
-
Mobile OS security models (sandboxing, keychain/keystore, app permissions)
-
Common web attack techniques, OWASP Testing Methodology
Familiarity with:-
Burp Suite Pro, Frida, MobSF
-
Mobile runtime manipulation and SSL pinning bypass techniques
-
Mobile API interaction and backend validation
-
Comfort using Linux and command‑line tooling.
-
Scripting experience (Python, Bash, or PowerShell).
-
Ability to read and interpret code in languages such as Java, Kotlin, Swift, JavaScript, or C#.
Current INTERNAL home-based associates: While this role is posted as hybrid,
if selected and accepted, you may retain your home-based status. Edward Jones intends in good faith to continue offering the role as home-based, though future business or regulatory needs may require on-site work.
**Candidates that live within a commutable distance from our Tempe, AZ and St. Louis, MO home office locations are expected to work in the office four days per week effective June 1, 2026. Before June 1, 2026, candidates that live within a commutable distance from our Tempe, AZ and St. Louis, MO home office locations are expected to work in the office three days per week, with preference for Tuesday through Thursday.**
Read More About Skills/Requirements
Awards & Accolades
At Edward Jones, we are building a place where everyone feels like they belong. We're proud of our associates' contributions to the firm and the recognitions we have received.
Check out our U.S. awards and accolades: Insights & Information Blog Postings about Edward Jones
Check out our Canadian awards and accolades: Insights & Information Blog Postings about Edward Jones
Read More About Awards & Accolades
About Us
Join a financial services firm where your contributions are valued. Edward Jones is a Fortune 500¹ company where people come first. With over 9 million clients and 20,000 financial advisors across the U.S. and Canada, we're proud to be privately-owned, placing the focus on our clients rather than shareholder returns.
Behind everything we do is our purpose: We partner for positive impact to improve the lives of our clients and colleagues, and together, better our communities and society. We are an innovative, flexible, and inclusive organization that attracts, develops, and inspires performance excellence and a sense of belonging.
People are at the center of our partnership. Edward Jones associates are seen, heard, respected, and supported. This is what we believe makes us the best place to start or build your career.
View our Purpose, Inclusion and Citizenship Report.
¹Fortune 500, published June 2024, data as of December 2023. Compensation provided for using, not obtaining, the rating.
Edward Jones does not discriminate on the basis of race, color, gender, religion, national origin, age, disability, sexual orientation, pregnancy, veteran status, genetic information or any other basis prohibited by applicable law.
#LI-HO