Hybrid Application Security Engineer

Posted 2 weeks ago

Apply now

About the role

  • Develop and maintain applications to support our application security concepts
  • Develop security reference implementations
  • Integrate security into our build and deploy pipelines
  • Maintain security controls and measure implementation across technology platforms, .NET, Java, Cloud, etc
  • Enable controls to monitor our development supply chain (i.e.third party dependencies)
  • Remediate and facilitate the resolution of vulnerabilities
  • Participate and facilitate Risk Assessment and Threat Modeling
  • Serve as an auditing, consulting, and training resource to all Nelnet product teams
  • Perform appropriate vulnerability scanning – static and dynamic analysis
  • Work with external entities that are performing vulnerability scans
  • Participate in tool and vendor selection process from a security perspective.
  • Create and update learning resources for application security
  • Develop and present on application security topics for a wide variety of audiences
  • Stay informed about application security best practices across Nelnet development platforms including web, mobile, and cloud

Requirements

  • BS / MS in Computer Science, Engineering, related discipline or equivalent experience
  • Minimum 2 years of experience in web application software development.
  • Minimum 1 years of experience focused on Application Security.
  • Understanding of a variety of application development architectures, platforms, methodologies, and supporting operating system
  • Experience identifying and protecting against web application and web-service security vulnerabilities including those found in the OWASP Top 10 and CWE Top 25
  • Knowledge of authentication and authorization, cryptography, and API security
  • Ability to identify, triage, manage, and remediate security vulnerabilities
  • Experience with build processes and CI/CD
  • Knowledge of cloud technologies
  • Experience with web and API development technologies such as .NET, Java, NPM, Angular, React

Benefits

  • medical
  • dental
  • vision
  • HSA and FSA
  • generous earned time off
  • 401K/student loan repayment
  • life insurance & AD&D insurance
  • employee assistance program
  • employee stock purchase program
  • tuition reimbursement
  • performance-based incentive pay
  • short- and long-term disability
  • robust wellness program

Job title

Application Security Engineer

Job type

Experience level

JuniorMid level

Salary

$80,000 - $110,000 per year

Degree requirement

Bachelor's Degree

Location requirements

Report this job

See something inaccurate? Let us know and we'll update the listing.

Report job