Sr Application Security Engineer

Nelnet
Lincoln, NE, United States
27 days ago
Apply on nelnet.wd1.myworkdayjobs.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Compensation
$135,000.0 - $150,000.0
Working hours
Regular working hours

Tech stack

Application Programming Interfaces (APIs) Artificial Intelligence Business Logic User Authentication Cloud Computing Security Code Review Cyber Security Continuous Integration Open Web Application Security Reverse Engineering Secure Coding Mobile Security
+10 more
Software Engineering Systems Integration Web Testing Large Language Models Software Security Information Technology Api Management Static Application Security Testing Programming Languages Dynamic Application Security Testing

Job description

We are seeking a Senior Application Security Engineer to lead hands-on application security testing, secure code review, and secure SDLC enablement across moder application environments. This role partners closely with engineering, cloud, and product teams to identify, communicate, and reduce application and services security risks from design through production. The engineer will combine manual testing expertise, automation, threat modeling, and AI assisted tooling to scale the AppSec program, improve developer security practices, and support secure, resilient applications., * Lead manual source code review across priority applications, with emphasis on business logic, access-control, authentication, authorization, and data-protection risks.

  • Perform and guide application security testing using SAST, DAST, SCA, container scanning, secrets detection, and web/API testing methodologies.
  • Expand and support the Security Champions program through enablement, coaching, secure coding guidance, and practical developer resources.
  • Develop and improve automated source code review processes and CI/CD security checks to help scale consistent application security coverage.
  • Partner with engineering, cloud, and product teams to embed secure SDLC practices into design, development, testing, release, and production support activities.
  • Create clear vulnerability reports that explain risk, business impact, urgency, and recommended remediation steps for technical and non-technical audiences.
  • Evaluate and apply AI-assisted tooling to accelerate code review, testing, triage, reporting, and secure development workflows
  • Advise teams on threat modeling for web, API, mobile, cloud, and AI-enabled application designs.

Requirements

Required:

  • Bachelor’s degree in Computer Science, Cybersecurity, Information Technology, Software Engineering, or a related field; or equivalent combination of education and relevant experience.

Preferred:

  • Advanced degree or specialized training in application security, cybersecurity, software engineering, cloud security, or related technical discipline.

EXPERIENCE:

Required:

  • 5-7+ years of hands-on application security, software security, or secure software engineering experience
  • Experience integrating security tooling and automated checks into CI/CD pipelines
  • Familiarity and experience conducting secure code review and testing web/API applications using OWASP Top 10 and web testing methodologies
  • Experience effectively assessing, prioritizing, documenting, and communicating vulnerabilities and risk-based remediation guidance to management and engineering audiences
  • Experience with technical report writing and communication

Preferred:

  • Experience with AI/LLM-integrated applications, AI security tooling, mobile security, reverse engineering, or advanced application security certifications.

COMPETENCIES/SKILLS:

  • Cybersecurity Proficiencies in required areas
  • Coding/Programming Languages
  • Automation & Scripting
  • Testing & Quality Assurance
  • Stakeholder Management & Communication

Benefits & conditions

Annual compensation range for this role is $135,000 - $150,000 depending on experience.

This position offers a hybrid work option. Nelnet values flexibility and understands the importance of work-life integration. Our hybrid work environment allows associates living within 30 miles of an office location to work remotely for part of the week, while also fostering collaboration and team connection through in-office presence three days per week.

About the company

Nelnet Business Services (NBS), a division of Nelnet, Inc., provides payment technology and education services to more than 1,200 higher education institutions, nearly 12,000 K-12 schools, and millions of individual students, families, and supporters across the globe. Our culture of service enables us to form long-lasting and trusted partnerships, while our focus on creativity and innovative solutions empowers our customer communities to thrive.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on nelnet.wd1.myworkdayjobs.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:22 min

Addressing the shortage of application security specialists

Joseph Katsioloudes Joseph Katsioloudes · World Congress 2025

3:39 min

Addressing code review surrender and process exploitation

Laura Tacho Laura Tacho · World Congress 2026 Europe

7:35 min

Addressing inconsistent screen reader and browser environments

Dirk Ginader · LIVE

2:59 min

Applying secure coding practices and proactive system monitoring

Mihaela-Roxana Ghidersa · LIVE

10:35 min

Teaching and coaching security concepts for lasting impact

Tanya Janca · World Congress 2021

26:47 min

Exploring pathways to application security careers and research workflows

Vandana Verma Sehgal · LIVE

Videos

See all

Related articles

See all