OneMain Financial

Senior Engineer – Cybersecurity Application Security

OneMain Financial$110K — $130K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in Cybersecurity, Computer Science, IT, Engineering, or a related field.
  • 5+ years of application security engineering experience.
  • Proficient in application security platforms (SAST, DAST, SCA, IAST, etc.).
  • Experience securing APIs throughout the development lifecycle.
  • Familiar with integrating security tools into CI/CD pipelines and IAC.
  • Knowledge of application security principles and secure coding practices.
  • Strong communication skills to influence tech stakeholders.

Responsibilities

  • Implement and enhance application security tools for secure software development.
  • Integrate security testing into software delivery pipelines.
  • Develop and maintain application security policies and documentation.
  • Analyze metrics and trends to identify risks and improvements.
  • Collaborate with engineering teams to adopt secure development practices.
  • Support secure SDLC governance and vulnerability management.
  • Contribute to security automation initiatives for efficiency.

Benefits

  • Collaborative work environment with cross-functional teams.
  • Opportunities for continuous learning and professional development.
  • Support for industry certifications and further education.
  • Involvement in cutting-edge technologies related to AI-assisted development.
  • Potential for career growth within a highly regulated industry.
Full Job Description

Key Responsibilities

  • Implement, administer, and continuously improve application security tooling supporting secure software development.
  • Integrate security testing and security controls into software delivery pipelines and engineering workflows.
  • Develop, maintain, and enhance application security standards, policies, procedures, documentation, and operational guidance.
  • Analyze security findings, operational metrics, and compliance trends to identify improvement opportunities and areas of elevated risk.
  • Partner with engineering teams to improve security adoption and enable secure-by-design and secure-by-default development practices.
  • Support secure SDLC governance, vulnerability management, and remediation tracking activities.
  • Collaborate with cybersecurity, architecture, platform, and engineering stakeholders to improve overall application security maturity.
  • Contribute to security automation initiatives that increase operational efficiency and reduce manual effort.
  • Support the secure implementation of emerging software development practices, including AI-assisted development workflows.

Required Qualifications

  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Engineering, or a related field.
  • 5+ years of application security engineering experience.
  • Experience implementing and administering application security platforms, including SAST, DAST, SCA, IAST, container security, API security testing, and software supply chain security capabilities.
  • Experience securing APIs across the development lifecycle, including API discovery, authentication and authorization validation, schema and contract testing, abuse-case analysis, OWASP API Security Top 10 risks, and remediation guidance.
  • Experience integrating security tooling and automated security controls into CI/CD pipelines using infrastructure-as-code (IAC).
  • Experience supporting secure SDLC governance, policy enforcement, compliance reporting, and remediation management.
  • Working knowledge of application security principles, secure coding practices, OWASP Top 10 risks, and common vulnerability remediation techniques.
  • Experience developing and maintaining technical standards, procedures, policies, and security documentation.
  • Strong written and verbal communication skills with the ability to influence technical stakeholders.
  • Ability to independently manage moderately complex security initiatives and contribute to broader cybersecurity objectives.

Preferred Qualifications

  • Industry certifications such as CSSLP, GSEC, CISSP, GWAPT, or similar.
  • Experience supporting financial services, banking, or other highly regulated environments.
  • Experience assessing, implementing, and governing security controls for AI-assisted software development workflows, including secure use of code-generation tools, prompt and output handling, developer guardrails, and risk monitoring.
  • Experience with security automation, scripting, and workflow orchestration.
  • Experience creating executive, engineering, or operational security metrics and dashboards.

About OneMain Financial

OneMain Financial is a consumer finance company that provides personal loans and other financial services. The company was founded in 1912 and is headquartered in Evansville, Indiana. OneMain Financial offers loans for a variety of purposes, including debt consolidation, home improvement, and auto financing. The company operates more than 1,500 branches across the United States. OneMain Financial is a subsidiary of Springleaf Holdings, Inc.
Learn more about OneMain Financial
Size
8,800 employees
Market Cap
$4 billion
Industry
Net Income
$730 million
Founded
1912
5 Year Trend
+5%
Revenue
$4.9 billion
NASDAQ

Similar Jobs

More Jobs at OneMain Financial

More Information Technology Jobs

Find similar Senior Engineer – Cybersecurity Application Security jobs: