
Cybersecurity Application Security Engineer
Nelnet, Inc.11 days ago
Remote, United States or Centennial, CO, USAMid Level / Senior
Base Salary
$90k - $125k/yr
Responsibilities
- Perform manual source-code reviews and SAST/DAST scanning.
- Conduct web, mobile, and application penetration testing and assess vulnerabilities.
- Develop automated source-code review processes and integrate security checks into CI/CD pipelines.
- Expand the Security Champions program and help product teams implement secure SDLC practices.
- Assess traditional and AI/LLM-integrated application security risks, including prompt injection, insecure output handling, model-data leakage, and RAG vulnerabilities.
- Prepare detailed vulnerability and technical risk reports for business, management, and engineering stakeholders.
- Build custom security tooling and automate manual processes using scripting.
- Mentor junior developers and engineers on secure design and coding practices when appropriate.
Requirements
- Requires 2–4 years of hands-on application security experience.
- Requires strong manual code-review experience in at least one major language, such as Java, JavaScript/TypeScript, C#, or PHP.
- Requires experience integrating security tooling and automated checks into CI/CD pipelines.
- Requires familiarity with the OWASP Top 10, web testing methodologies, SAST, SCA, DAST, penetration testing, container scanners, and secrets-detection tools.
- Requires solid threat-modeling expertise using STRIDE, attack trees, and misuse cases for traditional and AI/LLM-integrated systems.
- Requires scripting and automation skills with Python, Bash, or Node.
- Requires knowledge of web and API security concepts, including session management, secure storage, and transport security.
- Requires strong risk assessment, technical report writing, presentation, verbal communication, and written communication skills.
- Preferred qualifications include secure code review or internal developer-tooling experience, AI/LLM application or model-security experience, mobile security or reverse-engineering experience, and relevant security certifications such as OSWE, OSCP, GWAPT, GCSA, GCPN, or ML security certifications.
- Applicants must be U.S. citizens able to obtain the required United States Government security clearance.
Benefits
- Hybrid work option for associates living within 30 miles of an office, with three days per week in the office.
- Medical, dental, vision, HSA, and FSA benefits.
- Generous earned time off, 401K and student-loan repayment, life insurance, AD&D insurance, employee assistance, employee stock purchase, tuition reimbursement, disability coverage, and wellness programs.
- Performance-based incentive pay is available.
- Nelnet cannot provide current or future visa sponsorship for this position; applicants must already be authorized to work in the United States.