Stifel Financial Corp.
Cloud Security Engineer
Full details on LinkedIn
The complete job description, requirements, and application details are available on the original posting.
About Stifel Financial Corp.
Stifel Financial Corp. is a leading independent investment bank and financial services company based in St. Louis, Missouri. Founded in 1890, it has grown into a full-service firm, ranking as the 7th largest in the U.S. by the number of advisors. Stifel went public in 1983 and is listed on the New York Stock Exchange under the ticker symbol "SF." The company offers a variety of services, including wealth management, investment banking, equity research, and sales and trading. Stifel provides personalized investment advisory and financial planning through a large network of financial advisors. Its investment banking division specializes in debt and equity offerings, private placements, and strategic advisory services. Stifel also operates one of the largest equity research platforms in the U.S., covering over 1,100 companies, and engages in market making for more than 3,000 domestic equities. The firm serves a diverse clientele, including individual investors, institutional clients, businesses, and municipalities, providing tailored financial solutions to meet their needs.
Security at Stifel Financial Corp.
Compiled from public job postings, careers pages, and company materials. Data may not reflect current state — verify during interviews.
Security Philosophy
- Stifel's AppSec philosophy centers on safeguarding clients' financial data and assets as a top priority in system architecture and operations.
- The firm frames security as a risk-mitigation and active-defense effort built on industry standards (NIST Cybersecurity Framework and CIS Critical Security Controls), integrates security priorities into corporate strategy, and emphasizes secure development practices and firm-wide training and governance.
Security Team
- AppSec-related teams and governance described in public materials: a robust data security team plus dedicated cloud enablement and cloud security teams.
- Board of Directors receives quarterly briefings on information security posture (including application security).
- Operational AppSec role example: IT Application Security Analyst II (tracks vulnerabilities, performs risk-based prioritization, coordinates remediation, produces remediation reports and trend analysis, documents risk acceptance, and communicates with stakeholders).
Key Initiatives
- Documented and stated initiatives: careful and deliberate cloud migration supported by cloud enablement/security teams.
- Infrastructure modernization and extension of SAFe to security initiatives (2023).
- Continuous enhancement of Cybersecurity and Resiliency listed as a 2024 priority.
- Integration of security into Agile/SAFe development processes.
- Risk-based vulnerability management and remediation coordination.
- Firm-wide training covering cybersecurity, information security, data privacy, ethics, and compliance.
Preparing for an AppSec interview?
Get the weekly briefing 2,000+ security pros trust.