Application Security Engineer safeguarding applications and AI-driven components at Nelnet. Collaborating closely with engineering, cloud, and product teams to ensure security at speed.
Responsibilities
Manual Source Code Review
SAST/DAST scanning
Expand the Security Champions program
Develop automated source code review processes
Work with product teams to ensure secure SDLC processes are in place
Provide detail vulnerability reports to businesses
Requirements
2–4 years of hands-on application security experience
Experience integrating security tooling and automated checks into CI/CD pipelines
Familiarity and experience with OWASP Top 10 and web testing methodologies
Experience with effectively assessing and communicating risks and appropriate levels of urgency to management and engineering staff
Experience with technical report writing and communication
Strong manual code review experience in at least one major language (Java, JavaScript/TypeScript, C#, PHP, etc.)
Solid threat-modeling expertise (STRIDE, attack trees, misuse cases) for both traditional systems and AI/LLM-integrated features
Proficiency with SAST, SCA, DAST, web and mobile pentesting, container scanners, secrets-detection tools, and ideally AI-security scanning platforms
Experience integrating security tooling and automated checks into CI/CD pipeline
Scripting/automation skills (Python, Bash, Node) for building custom tooling and automating manual processes
Good understanding of AI/LLM attack surfaces including prompt injection, insecure output handling, model-data leakage, and RAG vulnerabilities
Strong knowledge of web/API security concepts (session management, secure storage, transport security)
Excellent organizational, presentation, verbal, and written communication skills
Ability to effectively assess and communicate risks and appropriate levels of urgency to management and engineering staff
Ability to mentor junior developers/engineers in secure design and coding practices
Experience performing secure code reviews or building internal developer tooling.
Previous work with AI or LLM-integrated applications, model security, or prompt safety.
Certifications such as OSWE, OSCP, GWAPT, GCSA, GCPN, or ML security certs (not required but beneficial).
Senior Application Engineer at Bank Frick responsible for technical operation of core banking system Olympic. Collaborate with team on middleware, Kubernetes configuration, and application security.
Sales Application Engineer developing Fluid Handling Technology projects for key accounts with a technical eye and sales flair in a hybrid role serving the Netherlands.
Proposal Engineer responsible for reviewing applications and generating equipment quotes for integration projects. Collaborating with vendors and internal teams to ensure accurate proposals and timely submissions.
Application Engineer responsible for designing and developing Oracle ERP - PVM solutions at Navy Federal. Collaborating with teams to leverage the full software development lifecycle for effective integration.
Applications Engineer responsible for conceptualizing and implementing robotic systems for various projects. Involves providing technical support and training for international branches.
Application Security Engineering Manager leading a global team to enhance application security. Collaborating with development teams to integrate security tools into software development lifecycle.
Applications Engineer handling quotations and technical responses for KSB's centrifugal pumps and auxiliary equipment. Collaborating with sales personnel and supporting the General Industrial market.
Field Product Specialist supporting customer teams with product differentiation and technical expertise in semiconductor testing. Delivering presentations and overseeing project scopes for customer applications.
Control and Protection Application Engineer at GE Grid Solutions designing control systems for HVDC schemes. Collaborating within a dynamic engineering team to improve grid technology and efficiency.
Senior Development Application Engineer providing solutions and technical leadership at GE Grid Solutions. Collaborating to drive innovation in protection and control devices.