> Markdown version of [/jobs/ext/2587939-cybersecurity-application-security-engineer](https://www.wearedevelopers.com/jobs/ext/2587939-cybersecurity-application-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cybersecurity Application Security Engineer - **Company:** Nelnet - **Location:** Lincoln, NE, United States (Remote available) - **Experience:** Experienced - **Salary:** $90,000.0 - $125,000.0 - **Contract:** Permanent contract - **Skills:** Java (Programming Language), JavaScript (Programming Language), PHP (Programming Language), Artificial Intelligence, Software System Penetration Testing, Bash Shell, C Sharp (Programming Language), Code Review, Cyber Security, Continuous Integration, Information Leak Prevention, Programming Tools, Python (Programming Language), Node.Js, Open Web Application Security, Systems Development Life Cycle, Reverse Engineering, Secure Coding, Session Management, Mobile Security, Systems Integration, TypeScript, Web Testing, Diagnostic Tools, Scripting, Large Language Models, Software Security, GWAPT, Static Application Security Testing, Vulnerability Analysis, Dynamic Application Security Testing - **Published:** August 15, 2026 - **Apply:** https://dejobs.org/x/x/699DAB0F0F484AEAA0245FD0CC31BE70/job/ ## About the Role * 2-4 years of hands-on application security experience * Experience integrating security tooling and automated checks into CI/CD pipelines * Familiarity and experience with OWASP Top 10 and web testing methodologies * Experience with effectively assessing and communicating risks and appropriate levels of urgency to management and engineering staff * Experience with technical report writing and communication, * Strong manual code review experience in at least one major language (Java, JavaScript/TypeScript, C#, PHP, etc.) * Solid threat-modeling expertise (STRIDE, attack trees, misuse cases) for both traditional systems and AI/LLM-integrated features * Proficiency with SAST, SCA, DAST, web and mobile pentesting, container scanners, secrets-detection tools, and ideally AI-security scanning platforms * Experience integrating security tooling and automated checks into CI/CD pipeline * Scripting/automation skills (Python, Bash, Node) for building custom tooling and automating manual processes * Good understanding of AI/LLM attack surfaces including prompt injection, insecure output handling, model-data leakage, and RAG vulnerabilities * Strong knowledge of web/API security concepts (session management, secure storage, transport security) * Excellent organizational, presentation, verbal, and written communication skills * Ability to effectively assess and communicate risks and appropriate levels of urgency to management and engineering staff * Aptitude for self-study, setting and achieving long term goals * Actively seeks to remain technically current and increase expertise and abilities * Challenges prevailing assumptions when appropriate * Willing to adapt to changing technology and business landscapes * Considers change as opportunities to be challenged and grow * Ability to adapt style of communications to match audience and information sharing needs Wants: * Experience performing secure code reviews or building internal developer tooling. * Previous work with AI or LLM-integrated applications , model security, or prompt safety. * Experience with mobile security , reverse engineering, or platform-specific secure coding. * Certifications such as OSWE, OSCP, GWAPT, GCSA, GCPN, or ML security certs (not required but beneficial). * Ability to mentor junior developers/engineers in secure design and coding practices. ## Description We are seeking a highly skilled Application Security Engineer with strong experience across secure code review, penetration testing, automation, and modern SDLC practices-including emerging AI/LLM security. In this role, you will partner closely with engineering, cloud, and product teams to safeguard our applications, services, and AI-driven components from design through production. You will combine hands-on technical testing with scalable automation and developer enablement to mature our AppSec program and ensure secure, resilient applications at speed. This position requires work in support of the Company's contract with the United States Department of Education ("ED"). As such, the United States Government requires that any applicant for this position must complete United States Government security clearance. Effective June 1, 2018, ED has informed Nelnet that security clearance applications for foreign nationals are not being accepted or processed. In light of this direction from ED, Nelnet will be unable to hire applicants without United States citizenship for such positions., * Manual Source Code Review * SAST/DAST scanning * Expand the Security Champions program * Develop automated source code review processes * Work with product teams to ensure secure SDLC processes are in place * Provide detail vulnerability reports to businesses ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [Stop using Node.js like in 2020! What changed and what you can do today with Node.js](https://www.wearedevelopers.com/videos/100011-stop-using-node-js-like-in-2020-what-changed-and-what-you-can-do-today-with-node-js) - [Can Machines Dream of Secure Code? Emerging AI Security Risks in LLM-driven Developer Tools](https://www.wearedevelopers.com/videos/1217-can-machines-dream-of-secure-code-emerging-ai-security-risks-in-llm-driven-developer-tools) - [Intermediate Bitcoin Script](https://www.wearedevelopers.com/videos/25-intermediate-bitcoin-script) - [Stop Using Node.js Like It’s 2020! - Alfonso Graziano](https://www.wearedevelopers.com/videos/1863-stop-using-node-js-like-it-s-2020-alfonso-graziano) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers)