AppSec Jobs
← Back to all jobs

Cetera Financial Group

Senior Security Engineer

Dallas, Texas, United StatesWebsite

Full details on LinkedIn

The complete job description, requirements, and application details are available on the original posting.


About Cetera Financial Group

Cetera Financial Group is a prominent network of independent retail broker-dealers and registered investment advisers. The company empowers financial advisors and institutions to provide objective financial advice to individuals, families, and company retirement plans throughout the United States. Founded in 2010 through the acquisition of three broker-dealers, Cetera has its headquarters in San Diego, California, and operates approximately 40 branches nationwide. Cetera consists of four main broker-dealers, each serving distinct communities: Cetera Advisors, Cetera Wealth Services, Cetera Financial Specialists, and Cetera Investment Services. The company supports over 9,000 independent financial professionals and serves more than 455 financial institutions, managing nearly $70.7 billion in assets. Cetera emphasizes unbiased advice, strong regulatory compliance, and tailored support for advisors and institutions, ensuring that their recommendations are based solely on merit.

Industry

financial services

Employees

1,900

133 engineers

Revenue

$1.9B

Website

Visit →

Security at Cetera Financial Group

Compiled from public job postings, careers pages, and company materials. Data may not reflect current state — verify during interviews.

3 Intel Signals

Security Philosophy

  • Stated AppSec Mission: 'Cetera's Information Security Program is comprehensive and is designed to allow our representatives to use the tools and software we provide with confidence.' Cetera maintains a comprehensive Information Security Program based on ISO 27001/27002 and NIST SP 800-53 standards.
  • Risk philosophy emphasizes continuous identification, assessment and management of enterprise and branch level risk.
  • Stated pain points include identifying and assessing risk from unsanctioned AI tool usage, proposing technical guardrails for AI security, and implementing controls aligned to OWASP Top 10 for LLMs and NIST AI RMF.

Security Team

  • Cetera Financial Group's security function is led by CISO Scott Hennon. AppSec-specific responsibilities are embedded across at least three active postings as of: (1) AI Security Engineer (Dallas, TX.
  • Posted 2026-06) covering cloud + application + AI security with DevSecOps/CI-CD and SAST/DAST duties.
  • (2) Senior Security Engineer focused on DSPM/DLP (Dallas, TX.
  • (3) Senior Security Operations Engineer (Dallas-Fort Worth / Rancho San Diego.
  • Posted ~) focused on NexGen SIEM and M365.
  • The AI Security Engineer role partners with IT Risk, Cloud Security, and Engineering teams. No centralized vs. embedded AppSec model is publicly stated.
  • No individual AppSec team lead below the CISO was identified.

Key Initiatives

Shift Left: Integration of security into CI/CD pipelines with DevSecOps practices. Vulnerability Management: Ongoing internal and external threat and vulnerability assessment and remediation with 24/7/365 monitoring of systems and networks. Verification of security controls conducted both internally and by independent third parties. Secure SDLC: Development of security standards, runbooks, and architecture documentation. Support for audits and regulatory compliance activities (NIST CSF, NIST 800-53, FINRA, SEC). Recent investment in AI-aware AppSec indicated by active AI Security Engineer role posting. No evidence of public bug-bounty program, named penetration-testing cadence, or Security Champions program.

Preparing for an AppSec interview?

Get the weekly briefing 2,000+ security pros trust.