Hybrid Cybersecurity Application Security Engineer

Posted 3 weeks ago

Apply now

About the role

  • Application Security Engineer safeguarding applications and AI-driven components at Nelnet. Collaborating closely with engineering, cloud, and product teams to ensure security at speed.

Responsibilities

  • Manual Source Code Review
  • SAST/DAST scanning
  • Expand the Security Champions program
  • Develop automated source code review processes
  • Work with product teams to ensure secure SDLC processes are in place
  • Provide detail vulnerability reports to businesses

Requirements

  • 2–4 years of hands-on application security experience
  • Experience integrating security tooling and automated checks into CI/CD pipelines
  • Familiarity and experience with OWASP Top 10 and web testing methodologies
  • Experience with effectively assessing and communicating risks and appropriate levels of urgency to management and engineering staff
  • Experience with technical report writing and communication
  • Strong manual code review experience in at least one major language (Java, JavaScript/TypeScript, C#, PHP, etc.)
  • Solid threat-modeling expertise (STRIDE, attack trees, misuse cases) for both traditional systems and AI/LLM-integrated features
  • Proficiency with SAST, SCA, DAST, web and mobile pentesting, container scanners, secrets-detection tools, and ideally AI-security scanning platforms
  • Experience integrating security tooling and automated checks into CI/CD pipeline
  • Scripting/automation skills (Python, Bash, Node) for building custom tooling and automating manual processes
  • Good understanding of AI/LLM attack surfaces including prompt injection, insecure output handling, model-data leakage, and RAG vulnerabilities
  • Strong knowledge of web/API security concepts (session management, secure storage, transport security)
  • Excellent organizational, presentation, verbal, and written communication skills
  • Ability to effectively assess and communicate risks and appropriate levels of urgency to management and engineering staff
  • Ability to mentor junior developers/engineers in secure design and coding practices
  • Experience performing secure code reviews or building internal developer tooling.
  • Previous work with AI or LLM-integrated applications, model security, or prompt safety.
  • Certifications such as OSWE, OSCP, GWAPT, GCSA, GCPN, or ML security certs (not required but beneficial).

Benefits

  • medical
  • dental
  • vision
  • HSA and FSA
  • generous earned time off
  • 401K/student loan repayment
  • life insurance & AD&D insurance
  • employee assistance program
  • employee stock purchase program
  • tuition reimbursement
  • performance-based incentive pay
  • short- and long-term disability
  • robust wellness program

Job title

Cybersecurity Application Security Engineer

Job type

Experience level

JuniorMid level

Salary

$90,000 - $125,000 per year

Degree requirement

Bachelor's Degree

Location requirements

Report this job

See something inaccurate? Let us know and we'll update the listing.

Report job