Fullstack Software Engineer, Information Security Team

Tesla Motors
Austin, TX, United States
19 days ago
Apply on jobs.localjobnetwork.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Working hours
Regular working hours

Tech stack

Application Programming Interfaces (APIs) Amazon Web Services HTML5 User Authentication Microsoft Azure Cascading Style Sheets (CSS) Cloud Computing Code Review Cyber Security Databases Continuous Integration Cross-Site Request Forgery
+34 more
Data Validation Database Security DevOps Identity and Access Management Python (Programming Language) Key Management Node.Js NoSQL OAuth Open Web Application Security Role-Based Access Control Runbook Secure Coding Session Management SonarQube SQL Databases TypeScript Web Application Frameworks Web Performance Optimization ReactJS Cross-Site Scripting (XSS) Amazon Virtual Private Cloud (VPC) Backend Rate Limiting Containerization Webpack Kubernetes Information Technology Front End Software Development Restful APIs Docker Static Application Security Testing Microservices Dynamic Application Security Testing

Job description

We are seeking a highly skilled and security-conscious Full Stack Engineer to design, develop, and maintain secure, high-performance web applications and backend systems. You will work across the entire stack - from frontend interfaces to backend services, databases, and infrastructure - while ensuring that security is a foundational principle at every layer. This role demands a strong understanding of secure coding practices, threat modeling, and compliance standards. You’ll collaborate with product, design, security, and DevOps teams to deliver systems that are not only fast and scalable, but also resilient to attacks and aligned with industry best practices. What You’ll Do

  • Design, build, and maintain secure full-stack applications using modern frameworks and tools, with security as a core requirement
  • Build and secure RESTful APIs and microservices using Node.js, Python, or Go, with strict input validation, rate limiting, and authentication/authorization controls
  • Design and manage database schemas with security in mind: enforce least-privilege access, prevent injection attacks (SQL, NoSQL), and ensure data encryption at rest and in transit
  • Implement and maintain secure CI/CD pipelines with automated security scanning (SAST/DAST), dependency checks, and policy enforcement
  • Integrate authentication and authorization mechanisms (e.g., OAuth2, JWT, SSO, RBAC) and enforce secure session management
  • Apply secure coding standards and conduct regular code reviews with a focus on vulnerabilities (e.g., XSS, CSRF, insecure deserialization)
  • Participate in threat modeling for new features and systems, identifying risks early in the design phase
  • Collaborate with the Security and DevOps teams to harden infrastructure, monitor for anomalies, and respond to incidents
  • Troubleshoot and remediate security issues in production, including root cause analysis and patching
  • Contribute to security documentation, incident response playbooks, and internal training on secure development practices

Requirements

  • Degree in Computer Science, Engineering, or a related field or equivalent practical experience
  • 3-5 years of professional experience in full stack development with a strong focus on security
  • Proficiency in modern frontend technologies: React, TypeScript, HTML5, CSS3, Webpack, REST APIs
  • Strong backend development skills in Node.js, Python, or Go, with experience implementing secure APIs
  • Experience with database security: SQL/NoSQL injection prevention, role-based access control, encryption
  • Hands-on experience with cloud platforms (AWS, GCP, or Azure) and secure infrastructure patterns (IAM, VPC, WAF, etc.)
  • Familiarity with containerization (Docker) and orchestration (Kubernetes) with security best practices (pod security policies, image scanning)
  • Experience with CI/CD security tools: SAST (SonarQube, Snyk), DAST, dependency scanning (Dependabot, Renovate), and secrets management
  • Understanding of security frameworks and standards: OWASP Top 10, NIST, ISO 27001, SOC 2, or GDPR
  • Excellent problem-solving skills, attention to detail, and a proactive mindset toward identifying and mitigating risks

Benefits & conditions

Along with competitive pay, as a full-time Tesla employee, you are eligible for the following benefits at day 1 of hire:

  • Medical plans > plan options with $0 payroll deduction
  • Family-building, fertility, adoption and surrogacy benefits
  • Dental (including orthodontic coverage) and vision plans, both have options with a $0 paycheck contribution
  • Company Paid (Health Savings Accounts) HSA Contribution when enrolled in the High-Deductible medical plan with HSA
  • Healthcare and Dependent Care Flexible Spending Accounts (FSA)
  • 401(k) with employer match, Employee Stock Purchase Plans, and other financial benefits
  • Company paid Basic Life, AD&D
  • Short-term and long-term disability insurance (90 day waiting period)
  • Employee Assistance Program
  • Sick and Vacation time (Flex time for salary positions, Accrued hours for Hourly positions), and Paid Holidays
  • Back-up childcare and parenting support resources
  • Voluntary benefits to include: critical illness, hospital indemnity, accident insurance, theft & legal services, and pet insurance
  • Weight Loss and Tobacco Cessation Programs
  • Tesla Babies program
  • Commuter benefits
  • Employee discounts and perks program

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on jobs.localjobnetwork.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:44 min

Playing synthesized backend audio objects in browsers

Lee Boonstra · LIVE

2:49 min

Adopting OAuth best practices and removing outdated grants

Alexander Schwartz Alexander Schwartz · World Congress 2026 Europe

2:37 min

Comparing traditional SQL tables versus NoSQL non-tabular databases

Stanimira Vlaeva · JS Congress

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

3:03 min

Building robust applications with standard web platforms

Dennie Declercq · LIVE

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

Videos

See all

Related articles

See all