Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy, and consent to receive emails from Rise
Jobs / Job page
Cybersecurity Application Security Engineer image - Rise Careers
Job details

Cybersecurity Application Security Engineer

Nelnet is a diversified and innovative company committed to enriching lives through the power of service as a student loan servicer, professional services company, consumer loan originator and servicer, payments processor, renewable energy solutions, and K-12 and higher education expert. For over 40 years, Nelnet has been serving its customers, associates, and communities.

The perks of working at Nelnet go beyond our benefits package. When you join the Nelnet team, you're part of a community invested in the success of each individual. That support comes through in our work, as we are united by our mission of creating opportunities for people where they live, learn, and work.

We are seeking a highly skilled Application Security Engineer with strong experience across secure code review, penetration testing, automation, and modern SDLC practices—including emerging AI/LLM security. In this role, you will partner closely with engineering, cloud, and product teams to safeguard our applications, services, and AI-driven components from design through production. You will combine hands-on technical testing with scalable automation and developer enablement to mature our AppSec program and ensure secure, resilient applications at speed.

This position offers a hybrid work option. Nelnet values flexibility and understands the importance of work-life integration. Our hybrid work environment allows associates Living within 30 miles of an office location to work remotely for part of the week, while also fostering collaboration and team connection through in-office presence three days per week.

Please note that we are unable to provide visa sponsorship for this position. To be considered, candidates must already be authorized to work in the United States without the need for current or future sponsorship.

Job Description

  • Manual Source Code Review

  • SAST/DAST scanning

  • Expand the Security Champions program

  • Develop automated source code review processes

  • Work with product teams to ensure secure SDLC processes are in place

  • Provide detail vulnerability reports to businesses

EXPERIENCE:

  • 2–4 years of hands-on application security experience

  • Experience integrating security tooling and automated checks into CI/CD pipelines

  • Familiarity and experience with OWASP Top 10 and web testing methodologies

  • Experience with effectively assessing and communicating risks and appropriate levels of urgency to management and engineering staff

  • Experience with technical report writing and communication

COMPETENCIES – SKILLS/KNOWLEDGE/ABILITIES:

Needs:

  • Strong manual code review experience in at least one major language (Java, JavaScript/TypeScript, C#, PHP, etc.)

  • Solid threat-modeling expertise (STRIDE, attack trees, misuse cases) for both traditional systems and AI/LLM-integrated features

  • Proficiency with SAST, SCA, DAST, web and mobile pentesting, container scanners, secrets-detection tools, and ideally AI-security scanning platforms

  • Experience integrating security tooling and automated checks into CI/CD pipeline

  • Scripting/automation skills (Python, Bash, Node) for building custom tooling and automating manual processes

  • Good understanding of AI/LLM attack surfaces including prompt injection, insecure output handling, model-data leakage, and RAG vulnerabilities

  • Strong knowledge of web/API security concepts (session management, secure storage, transport security)

    • Excellent organizational, presentation, verbal, and written communication skills

    • Ability to effectively assess and communicate risks and appropriate levels of urgency to management and engineering staff

    • Aptitude for self-study, setting and achieving long term goals

    • Actively seeks to remain technically current and increase expertise and abilities

    • Challenges prevailing assumptions when appropriate

    • Willing to adapt to changing technology and business landscapes

    • Considers change as opportunities to be challenged and grow

    • Ability to adapt style of communications to match audience and information sharing needs

Wants:

  • Experience performing secure code reviews or building internal developer tooling.

  • Previous work with AI or LLM-integrated applications, model security, or prompt safety.

  • Experience with mobile security, reverse engineering, or platform-specific secure coding.

  • Certifications such as OSWE, OSCP, GWAPT, GCSA, GCPN, or ML security certs (not required but beneficial).

  • Ability to mentor junior developers/engineers in secure design and coding practices.

Pay range for this role is $90,000-$125,000 annually, depending on experience.

#LI-CW1
#LI-Hybrid

#LI-REMOTE

 

Our benefits package includes medical, dental, vision, HSA and FSA, generous earned time off, 401K/student loan repayment, life insurance & AD&D insurance, employee assistance program, employee stock purchase program, tuition reimbursement, performance-based incentive pay, short- and long-term disability, and a robust wellness program. Click here to learn more about our benefits: LINK.

Nelnet is committed to providing a welcoming and respectful workplace where all associates have the opportunity to succeed. As an Equal Opportunity Employer, we ensure that all qualified applicants are considered for employment. Employment decisions are made without regard to race, color, religion/creed, national origin, gender, sex, marital status, age, disability, use of a guide dog or service animal, sexual orientation, military/veteran status, or any other status protected by federal, state, or local law. We value the unique contributions of every team member and believe that a positive work environment benefits everyone.  

Qualified individuals with disabilities who require reasonable accommodations in order to apply or compete for positions at Nelnet may request such accommodations by contacting Corporate Recruiting at 402-486-5725 or corporaterecruiting@nelnet.net.

Nelnet is a Drug Free and Tobacco Free Workplace.

Average salary estimate

$107500 / YEARLY (est.)
min
max
$90000K
$125000K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

Similar Jobs
Photo of the Rise User

An experienced technology leader is needed to head global engineering efforts, implement AI-driven development, and deliver secure, high-impact healthcare software solutions.

Photo of the Rise User

Verisoul is hiring an in-person Platform Engineer in Austin to architect and ship the core APIs, SDKs, and verification infrastructure that power its fraud-detection product.

Photo of the Rise User
Posted 11 hours ago

Intuitive is hiring a Staff Agentic AI Developer to architect and build safe, scalable autonomous agent systems for clinical and complex workflows using C#, Python, and cloud-native services.

Posted 14 hours ago

Auctor seeks a Senior Backend Software Engineer in New York to architect and build scalable backend systems powering AI-first enterprise services.

Photo of the Rise User

Senior engineering role focused on designing and implementing scalable, secure backend and blockchain systems within Visa’s payments and crypto program.

Photo of the Rise User
Posted 14 hours ago

Coram AI is hiring an Infrastructure Software Engineer to design, build, and operate the cloud and edge systems that power its AI-enabled IoT security platform.

Photo of the Rise User
Gravie Hybrid No location specified
Posted 2 hours ago

Lead a core engineering team at Gravie as a hands-on Engineering Team Lead, blending coding, architecture, and people management to deliver innovative health benefits software.

Photo of the Rise User
Posted 22 hours ago

Lead the strategy and technical execution for enterprise-grade Gen AI agents at Visa, focusing on prompt engineering, scalable architectures, and reliable deployment to support business-critical workflows.

Photo of the Rise User

Illumio is hiring a Senior Software Engineer (Cloud Security) in Sunnyvale to build containerized, distributed services that provide real-time visibility and security recommendations across cloud environments.

Posted 18 hours ago

Design and deliver high-reliability Android applications for military logistics, focusing on performance, resilience, and real-world field deployments.

Photo of the Rise User
StubHub Hybrid Los Angeles, California, United States
Posted 6 hours ago

Software Engineer I (AI Enablement) to build internal AI tooling, prototype LLM agents, and help teams safely and effectively adopt generative AI across StubHub.

Posted 24 hours ago

UW–Stevens Point is hiring a hybrid Software Engineer/Developer I to develop, test, and support campus applications and systems.

Photo of the Rise User
Posted 15 hours ago
Inclusive & Diverse
Mission Driven
Work/Life Harmony
Diversity of Opinions
Friends Outside of Work
Empathetic
Collaboration over Competition
Fast-Paced
Transparent & Candid
Medical Insurance
Dental Insurance
Vision Insurance
Disability Insurance
Learning & Development
401K Matching
Paid Time-Off
WFH Reimbursements
Paid Holidays
Equity
Flex-Friendly

Replit is looking for a Staff Software Engineer to own and scale monetization systems, creating robust billing infrastructure and seamless payment experiences.

We live to serve our customers, associates, and communities.

8 jobs
MATCH
Calculating your matching score...
FUNDING
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
EMPLOYMENT TYPE
Full-time, hybrid
DATE POSTED
December 19, 2025
Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!