> Markdown version of [/jobs/ext/2571972-fullstack-software-engineer-information-security-team](https://www.wearedevelopers.com/jobs/ext/2571972-fullstack-software-engineer-information-security-team). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Fullstack Software Engineer, Information Security Team - **Company:** Tesla Motors - **Location:** Austin, TX, United States - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Amazon Web Services, HTML5, User Authentication, Microsoft Azure, Cascading Style Sheets (CSS), Cloud Computing, Code Review, Cyber Security, Databases, Continuous Integration, Cross-Site Request Forgery, Data Validation, Database Security, DevOps, Identity and Access Management, Python (Programming Language), Key Management, Node.Js, NoSQL, OAuth, Open Web Application Security, Role-Based Access Control, Runbook, Secure Coding, Session Management, SonarQube, SQL Databases, TypeScript, Web Application Frameworks, Web Performance Optimization, ReactJS, Cross-Site Scripting (XSS), Amazon Virtual Private Cloud (VPC), Backend, Rate Limiting, Containerization, Webpack, Kubernetes, Information Technology, Front End Software Development, Restful APIs, Docker, Static Application Security Testing, Microservices, Dynamic Application Security Testing - **Published:** August 15, 2026 - **Apply:** https://jobs.localjobnetwork.com/apply/add/88044968/1 ## About the Role * Degree in Computer Science, Engineering, or a related field or equivalent practical experience * 3-5 years of professional experience in full stack development with a strong focus on security * Proficiency in modern frontend technologies: React, TypeScript, HTML5, CSS3, Webpack, REST APIs * Strong backend development skills in Node.js, Python, or Go, with experience implementing secure APIs * Experience with database security: SQL/NoSQL injection prevention, role-based access control, encryption * Hands-on experience with cloud platforms (AWS, GCP, or Azure) and secure infrastructure patterns (IAM, VPC, WAF, etc.) * Familiarity with containerization (Docker) and orchestration (Kubernetes) with security best practices (pod security policies, image scanning) * Experience with CI/CD security tools: SAST (SonarQube, Snyk), DAST, dependency scanning (Dependabot, Renovate), and secrets management * Understanding of security frameworks and standards: OWASP Top 10, NIST, ISO 27001, SOC 2, or GDPR * Excellent problem-solving skills, attention to detail, and a proactive mindset toward identifying and mitigating risks ## Description We are seeking a highly skilled and security-conscious Full Stack Engineer to design, develop, and maintain secure, high-performance web applications and backend systems. You will work across the entire stack - from frontend interfaces to backend services, databases, and infrastructure - while ensuring that security is a foundational principle at every layer. This role demands a strong understanding of secure coding practices, threat modeling, and compliance standards. You'll collaborate with product, design, security, and DevOps teams to deliver systems that are not only fast and scalable, but also resilient to attacks and aligned with industry best practices. What You'll Do * Design, build, and maintain secure full-stack applications using modern frameworks and tools, with security as a core requirement * Build and secure RESTful APIs and microservices using Node.js, Python, or Go, with strict input validation, rate limiting, and authentication/authorization controls * Design and manage database schemas with security in mind: enforce least-privilege access, prevent injection attacks (SQL, NoSQL), and ensure data encryption at rest and in transit * Implement and maintain secure CI/CD pipelines with automated security scanning (SAST/DAST), dependency checks, and policy enforcement * Integrate authentication and authorization mechanisms (e.g., OAuth2, JWT, SSO, RBAC) and enforce secure session management * Apply secure coding standards and conduct regular code reviews with a focus on vulnerabilities (e.g., XSS, CSRF, insecure deserialization) * Participate in threat modeling for new features and systems, identifying risks early in the design phase * Collaborate with the Security and DevOps teams to harden infrastructure, monitor for anomalies, and respond to incidents * Troubleshoot and remediate security issues in production, including root cause analysis and patching * Contribute to security documentation, incident response playbooks, and internal training on secure development practices ## Related Videos - [Leveraging Real time data in FSIs](https://www.wearedevelopers.com/videos/806-leveraging-real-time-data-in-fsis) - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [The Resilience of the World Wide Web](https://www.wearedevelopers.com/videos/1281-the-resilience-of-the-world-wide-web) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [NoSQL Data Modeling for Front-end Developers](https://www.wearedevelopers.com/videos/297-nosql-data-modeling-for-front-end-developers) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) ## Related Articles - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [The Best X (Twitter) Accounts for Developers](https://www.wearedevelopers.com/magazine/294-the-best-x-twitter-accounts-for-developers) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [The Best Software Developer Blogs to Read](https://www.wearedevelopers.com/magazine/156-the-best-software-developer-blogs-to-read)