Nelnet logo
Nelnet
Posted 39 days agoVerified live 11h ago

Cybersecurity Application Security Engineer

Brief overview

Remote
$90k–$125k/yrStated range
2+ yrsMinimum
34 H-1B approvalsDept. of Labor
11 green cardsCertified filings
Clearance requiredU.S. government
Manual Source Code ReviewSASTSCADASTOWASP Top 10Threat ModelingCI/CD Security IntegrationPythonBashNode.jsAI/LLM SecurityWeb and API SecurityWritten and Verbal Communication

About the company

Nelnet provides business, communications, and financial services.

Visa sponsorship history

4 years sponsoring, last filed FY2026

Data powered by U.S. Department of Labor. This does not guarantee sponsorship for this specific role.
34H-1B approved
100%approval rate
5new H-1B hires
11PERM certified
$125,000median wage / yr
H-1B Petition ApprovalsVisas USCIS actually granted: the strongest sign the company sponsors.
202311
20249
20259
20265
LCA Certified ApplicationsAn early filing step, not a visa approval: it signals intent, not confirmed sponsorship.
20234
20242
20253
20262
Green Card (PERM) FilingsCertified green card filings: a long-term commitment to international hires.
20234
20241
20255
20261
Top sponsored roles
Senior Software EngineerSoftware Engineer IIIT Business AnalystData Analyst ISenior Software Engineer - NBS
Sponsored employees from
IndiaMalaysia

Job description

Summary

Nelnet is a diversified company providing student loan servicing, professional services, consumer lending, payment processing, renewable energy solutions, and education services. The Application Security Engineer will protect applications, services, and AI-driven components through secure code reviews, penetration testing, security automation, secure SDLC practices, and developer enablement.

Responsibilities

  • Manual Source Code Review
  • SAST/DAST scanning
  • Expand the Security Champions program
  • Develop automated source code review processes
  • Work with product teams to ensure secure SDLC processes are in place
  • Provide detail vulnerability reports to businesses

Skills

  • 2–4 years of hands-on application security experience
  • Experience integrating security tooling and automated checks into CI/CD pipelines
  • Familiarity and experience with OWASP Top 10 and web testing methodologies
  • Experience with effectively assessing and communicating risks and appropriate levels of urgency to management and engineering staff
  • Experience with technical report writing and communication
  • Strong manual code review experience in at least one major language (Java, JavaScript/TypeScript, C#, PHP, etc.)
  • Solid threat-modeling expertise (STRIDE, attack trees, misuse cases) for both traditional systems and AI/LLM-integrated features
  • Proficiency with SAST, SCA, DAST, web and mobile pentesting, container scanners, secrets-detection tools, and ideally AI-security scanning platforms
  • Experience integrating security tooling and automated checks into CI/CD pipeline
  • Scripting/automation skills (Python, Bash, Node) for building custom tooling and automating manual processes
  • Good understanding of AI/LLM attack surfaces including prompt injection, insecure output handling, model-data leakage, and RAG vulnerabilities
  • Strong knowledge of web/API security concepts (session management, secure storage, transport security)
  • Excellent organizational, presentation, verbal, and written communication skills
  • Ability to effectively assess and communicate risks and appropriate levels of urgency to management and engineering staff
  • Aptitude for self-study, setting and achieving long term goals
  • Actively seeks to remain technically current and increase expertise and abilities
  • Challenges prevailing assumptions when appropriate
  • Willing to adapt to changing technology and business landscapes
  • Considers change as opportunities to be challenged and grow
  • Ability to adapt style of communications to match audience and information sharing needs
  • Ability to mentor junior developers/engineers in secure design and coding practices
  • To be considered, candidates must already be authorized to work in the United States without the need for current or future sponsorship
  • Any applicant for this position must complete United States Government security clearance
  • The United States Government requires that any applicant for this position must complete United States Government security clearance
  • Applicants without United States citizenship
  • Experience performing **secure code reviews** or building internal developer tooling
  • Previous work with **AI or LLM-integrated applications**, model security, or prompt safety
  • Experience with **mobile security**, reverse engineering, or platform-specific secure coding
  • Certifications such as OSWE, OSCP, GWAPT, GCSA, GCPN, or ML security certs (not required but beneficial)

Qualifications

Must Haves

  • 2–4 years of hands-on application security experience
  • Experience integrating security tooling and automated checks into CI/CD pipelines
  • Familiarity and experience with OWASP Top 10 and web testing methodologies
  • Experience with effectively assessing and communicating risks and appropriate levels of urgency to management and engineering staff
  • Experience with technical report writing and communication
  • Strong manual code review experience in at least one major language (Java, JavaScript/TypeScript, C#, PHP, etc.)
  • Solid threat-modeling expertise (STRIDE, attack trees, misuse cases) for both traditional systems and AI/LLM-integrated features
  • Proficiency with SAST, SCA, DAST, web and mobile pentesting, container scanners, secrets-detection tools, and ideally AI-security scanning platforms
  • Experience integrating security tooling and automated checks into CI/CD pipeline
  • Scripting/automation skills (Python, Bash, Node) for building custom tooling and automating manual processes
  • Good understanding of AI/LLM attack surfaces including prompt injection, insecure output handling, model-data leakage, and RAG vulnerabilities
  • Strong knowledge of web/API security concepts (session management, secure storage, transport security)
  • Excellent organizational, presentation, verbal, and written communication skills
  • Ability to effectively assess and communicate risks and appropriate levels of urgency to management and engineering staff
  • Aptitude for self-study, setting and achieving long term goals
  • Actively seeks to remain technically current and increase expertise and abilities
  • Challenges prevailing assumptions when appropriate
  • Willing to adapt to changing technology and business landscapes
  • Considers change as opportunities to be challenged and grow
  • Ability to adapt style of communications to match audience and information sharing needs
  • Ability to mentor junior developers/engineers in secure design and coding practices
  • To be considered, candidates must already be authorized to work in the United States without the need for current or future sponsorship
  • any applicant for this position must complete United States Government security clearance
  • The United States Government requires that any applicant for this position must complete United States Government security clearance
  • applicants without United States citizenship

Nice to Haves

  • Experience performing **secure code reviews** or building internal developer tooling
  • Previous work with **AI or LLM-integrated applications**, model security, or prompt safety
  • Experience with **mobile security**, reverse engineering, or platform-specific secure coding
  • Certifications such as OSWE, OSCP, GWAPT, GCSA, GCPN, or ML security certs (not required but beneficial)

Benefits

  • Medical insurance
  • Dental insurance
  • Vision insurance
  • HSA
  • FSA
  • Generous earned time off
  • 401K/student loan repayment
  • Life insurance & AD&D insurance
  • Employee assistance program
  • Employee stock purchase program
  • Tuition reimbursement
  • Performance-based incentive pay
  • Short- and long-term disability
  • Robust wellness program
  • Hybrid work option: associates living within 30 miles of an office location can work remotely for part of the week, with in-office presence three days per week.

More jobs like this