We are seeking a Senior Application Security Engineer to lead hands-on application security testing, secure code review, and secure SDLC enablement across moder application environments. This role partners closely with engineering, cloud, and product teams to identify, communicate, and reduce application and services security risks from design through production. The engineer will combine manual testing expertise, automation, threat modeling, and AI assisted tooling to scale the AppSec program, improve developer security practices, and support secure, resilient applications.
JOB RESPONSIBILITIES:Lead manual source code review across priority applications, with emphasis on business logic, access-control, authentication, authorization, and data-protection risks.
Perform and guide application security testing using SAST, DAST, SCA, container scanning, secrets detection, and web/API testing methodologies.
Expand and support the Security Champions program through enablement, coaching, secure coding guidance, and practical developer resources.
Develop and improve automated source code review processes and CI/CD security checks to help scale consistent application security coverage.
Partner with engineering, cloud, and product teams to embed secure SDLC practices into design, development, testing, release, and production support activities.
Create clear vulnerability reports that explain risk, business impact, urgency, and recommended remediation steps for technical and non-technical audiences.
Evaluate and apply AI-assisted tooling to accelerate code review, testing, triage, reporting, and secure development workflows
Advise teams on threat modeling for web, API, mobile, cloud, and AI-enabled application designs.
Annual compensation range for this role is $135,000 - $150,000 depending on experience.
This position offers a hybrid work option. Nelnet values flexibility and understands the importance of work-life integration. Our hybrid work environment allows associates living within 30 miles of an office location to work remotely for part of the week, while also fostering collaboration and team connection through in-office presence three days per week.
Please note that we are unable to provide visa sponsorship for this position. To be considered, candidates must already be authorized to work in the United States without the need for current or future sponsorship.
EDUCATION:
Required:
Bachelor’s degree in Computer Science, Cybersecurity, Information Technology, Software Engineering, or a related field; or equivalent combination of education and relevant experience.
Preferred:
Advanced degree or specialized training in application security, cybersecurity, software engineering, cloud security, or related technical discipline.
EXPERIENCE:
Required:
5-7+ years of hands-on application security, software security, or secure software engineering experience
Experience integrating security tooling and automated checks into CI/CD pipelines
Familiarity and experience conducting secure code review and testing web/API applications using OWASP Top 10 and web testing methodologies
Experience effectively assessing, prioritizing, documenting, and communicating vulnerabilities and risk-based remediation guidance to management and engineering audiences
Experience with technical report writing and communication
Preferred:
- Experience with AI/LLM-integrated applications, AI security tooling, mobile security, reverse engineering, or advanced application security certifications.
COMPETENCIES/SKILLS: Cybersecurity Proficiencies in required areas
Coding/Programming Languages
Automation & Scripting
Testing & Quality Assurance
Stakeholder Management & Communication
Our benefits package includes medical, dental, vision, HSA and FSA, generous earned time off, 401K/student loan repayment, life insurance & AD&D insurance, employee assistance program, employee stock purchase program, tuition reimbursement, performance-based incentive pay, short- and long-term disability, and a robust wellness program. Click here to learn more about our benefits: