Nelnet Logo

Nelnet

Sr Application Security Engineer

Posted One Month Ago
Remote
2 Locations
135K-150K Annually
Senior level
Remote
2 Locations
135K-150K Annually
Senior level
Lead hands-on application security testing and secure code review across priority apps. Perform SAST/DAST/SCA/container scans and web/API testing, integrate automated checks into CI/CD, coach Security Champions, apply threat modeling and AI-assisted tooling, and produce clear vulnerability reports with remediation guidance to engineering and management.
The summary above was generated by AI

Nelnet Business Services (NBS), a division of Nelnet, Inc., provides payment technology and education services to more than 1,200 higher education institutions, nearly 12,000 K-12 schools, and millions of individual students, families, and supporters across the globe. Our culture of service enables us to form long-lasting and trusted partnerships, while our focus on creativity and innovative solutions empowers our customer communities to thrive.

We are seeking a Senior Application Security Engineer to lead hands-on application security testing, secure code review, and secure SDLC enablement across moder application environments. This role partners closely with engineering, cloud, and product teams to identify, communicate, and reduce application and services security risks from design through production. The engineer will combine manual testing expertise, automation, threat modeling, and AI assisted tooling to scale the AppSec program, improve developer security practices, and support secure, resilient applications.JOB RESPONSIBILITIES:
  • Lead manual source code review across priority applications, with emphasis on business logic, access-control, authentication, authorization, and data-protection risks.

  • Perform and guide application security testing using SAST, DAST, SCA, container scanning, secrets detection, and web/API testing methodologies.

  • Expand and support the Security Champions program through enablement, coaching, secure coding guidance, and practical developer resources.

  • Develop and improve automated source code review processes and CI/CD security checks to help scale consistent application security coverage.

  • Partner with engineering, cloud, and product teams to embed secure SDLC practices into design, development, testing, release, and production support activities.

  • Create clear vulnerability reports that explain risk, business impact, urgency, and recommended remediation steps for technical and non-technical audiences.

  • Evaluate and apply AI-assisted tooling to accelerate code review, testing, triage, reporting, and secure development workflows

  • Advise teams on threat modeling for web, API, mobile, cloud, and AI-enabled application designs.

Annual compensation range for this role is $135,000 - $150,000 depending on experience.

This position offers a hybrid work option. Nelnet values flexibility and understands the importance of work-life integration. Our hybrid work environment allows associates living within 30 miles of an office location to work remotely for part of the week, while also fostering collaboration and team connection through in-office presence three days per week.

Please note that we are unable to provide visa sponsorship for this position. To be considered, candidates must already be authorized to work in the United States without the need for current or future sponsorship.
 

EDUCATION:

Required:

  • Bachelor’s degree in Computer Science, Cybersecurity, Information Technology, Software Engineering, or a related field; or equivalent combination of education and relevant experience.

Preferred: 

  • Advanced degree or specialized training in application security, cybersecurity, software engineering, cloud security, or related technical discipline.

EXPERIENCE:

Required:

  • 5-7+ years of hands-on application security, software security, or secure software engineering experience

  • Experience integrating security tooling and automated checks into CI/CD pipelines

  • Familiarity and experience conducting secure code review and testing web/API applications using OWASP Top 10 and web testing methodologies

  • Experience effectively assessing, prioritizing, documenting, and communicating vulnerabilities and risk-based remediation guidance to management and engineering audiences

  • Experience with technical report writing and communication 

Preferred: 

  • Experience with AI/LLM-integrated applications, AI security tooling, mobile security, reverse engineering, or advanced application security certifications.
COMPETENCIES/SKILLS: 
  • Cybersecurity Proficiencies in required areas

  • Coding/Programming Languages

  • Automation & Scripting

  • Testing & Quality Assurance

  • Stakeholder Management & Communication

Our benefits package includes medical, dental, vision, HSA and FSA, generous earned time off, 401K/student loan repayment, life insurance & AD&D insurance, employee assistance program, employee stock purchase program, tuition reimbursement, performance-based incentive pay, short- and long-term disability, and a robust wellness program. Click here to learn more about our benefits: Benefits & Perks - Nelnet Inc

Nelnet is committed to providing a welcoming and respectful workplace where all associates have the opportunity to succeed. As an Equal Opportunity Employer, we ensure that all qualified applicants are considered for employment. Employment decisions are made without regard to race, color, religion/creed, national origin, gender, sex, marital status, age, disability, use of a guide dog or service animal, sexual orientation, military/veteran status, or any other status protected by federal, state, or local law. We value the unique contributions of every team member and believe that a positive work environment benefits everyone.  


Qualified individuals with disabilities who require reasonable accommodations in order to apply or compete for positions at Nelnet may request such accommodations by contacting Corporate Recruiting at 402-486-5725 or [email protected].


Nelnet is a Drug Free and Tobacco Free Workplace.


Use of Artificial Intelligence in Hiring

We may use automated or artificial intelligence enabled tools to assist with the initial review of applications, such as identifying relevant skills or experience. These tools are used to support human review and do not make hiring decisions. A recruiter reviews applications and determines which candidates move forward in the hiring process. For more information, see our Privacy Policy and Pre-Use Notice: Automated Tools in Hiring

Similar Jobs

23 Days Ago
Remote
United States
145K-183K Annually
Senior level
145K-183K Annually
Senior level
Fintech • Financial Services
Conduct manual penetration tests and secure code reviews across web applications, APIs, AWS infrastructure, and AI systems. Develop AI-assisted security tooling, test LLM applications and agents, triage SAST findings, tune detection rules, support security reviews before production, and communicate risks and remediation priorities to engineering teams.
Top Skills: Ai AgentsAPIsAWSGoLlmsPythonRubySastSecure SdlcTypescript
2 Days Ago
Remote
USA
169K-220K Annually
Senior level
169K-220K Annually
Senior level
Artificial Intelligence • Healthtech • Software
Hands-on application security engineer responsible for finding and remediating vulnerabilities across a healthcare platform. Duties include offensive security testing, custom tooling, system hardening, security monitoring, PHI protection, AI-assisted vulnerability discovery, secure code review, security training, mentoring, defensive strategy, and disaster recovery resilience.
Top Skills: Ai AgentsAi Vulnerability Discovery FrameworksApplication Security ToolingPenetration Testing ToolsSecurity Monitoring Systems
One Month Ago
Remote or Hybrid
Seattle, WA, USA
182K-288K Annually
Senior level
182K-288K Annually
Senior level
Healthtech • Social Impact • Software
Build and advance application and product security across the engineering organization. Responsibilities include establishing secure defaults, CI guardrails, security requirements, threat modeling, risk assessments, penetration testing, vulnerability remediation, secure coding education, roadmap ownership, and hands-on code review. The role partners closely with product, engineering, DevOps, and services teams to secure applications, microservices, and AI features while enabling efficient development.
Top Skills: Ci/CdDastMicroservicesPenetration TestingSastSbomThreat Modeling

What you need to know about the Seattle Tech Scene

Home to tech titans like Microsoft and Amazon, Seattle punches far above its weight in innovation. But its surrounding mountains, sprinkled with world-famous hiking trails and climbing routes, make the city a destination for outdoorsy types as well. Established as a logging town before shifting to shipbuilding and logistics, the Emerald City is now known for its contributions to aerospace, software, biotech and cloud computing. And its status as a thriving tech ecosystem is attracting out-of-town companies looking to establish new tech and engineering hubs.

Key Facts About Seattle Tech

  • Number of Tech Workers: 287,000; 13% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Amazon, Microsoft, Meta, Google
  • Key Industries: Artificial intelligence, cloud computing, software, biotechnology, game development
  • Funding Landscape: $3.1 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Madrona, Fuse, Tola, Maveron
  • Research Centers and Universities: University of Washington, Seattle University, Seattle Pacific University, Allen Institute for Brain Science, Bill & Melinda Gates Foundation, Seattle Children’s Research Institute

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account