Summary
Nelnet is a diversified company providing student loan servicing, professional services, consumer lending, payment processing, renewable energy solutions, and education services. The Application Security Engineer will protect applications, services, and AI-driven components through secure code reviews, penetration testing, security automation, secure SDLC practices, and developer enablement.
Responsibilities
- Manual Source Code Review
- SAST/DAST scanning
- Expand the Security Champions program
- Develop automated source code review processes
- Work with product teams to ensure secure SDLC processes are in place
- Provide detail vulnerability reports to businesses
Skills
- 2–4 years of hands-on application security experience
- Experience integrating security tooling and automated checks into CI/CD pipelines
- Familiarity and experience with OWASP Top 10 and web testing methodologies
- Experience with effectively assessing and communicating risks and appropriate levels of urgency to management and engineering staff
- Experience with technical report writing and communication
- Strong manual code review experience in at least one major language (Java, JavaScript/TypeScript, C#, PHP, etc.)
- Solid threat-modeling expertise (STRIDE, attack trees, misuse cases) for both traditional systems and AI/LLM-integrated features
- Proficiency with SAST, SCA, DAST, web and mobile pentesting, container scanners, secrets-detection tools, and ideally AI-security scanning platforms
- Experience integrating security tooling and automated checks into CI/CD pipeline
- Scripting/automation skills (Python, Bash, Node) for building custom tooling and automating manual processes
- Good understanding of AI/LLM attack surfaces including prompt injection, insecure output handling, model-data leakage, and RAG vulnerabilities
- Strong knowledge of web/API security concepts (session management, secure storage, transport security)
- Excellent organizational, presentation, verbal, and written communication skills
- Ability to effectively assess and communicate risks and appropriate levels of urgency to management and engineering staff
- Aptitude for self-study, setting and achieving long term goals
- Actively seeks to remain technically current and increase expertise and abilities
- Challenges prevailing assumptions when appropriate
- Willing to adapt to changing technology and business landscapes
- Considers change as opportunities to be challenged and grow
- Ability to adapt style of communications to match audience and information sharing needs
- Ability to mentor junior developers/engineers in secure design and coding practices
- To be considered, candidates must already be authorized to work in the United States without the need for current or future sponsorship
- Any applicant for this position must complete United States Government security clearance
- The United States Government requires that any applicant for this position must complete United States Government security clearance
- Applicants without United States citizenship
- Experience performing **secure code reviews** or building internal developer tooling
- Previous work with **AI or LLM-integrated applications**, model security, or prompt safety
- Experience with **mobile security**, reverse engineering, or platform-specific secure coding
- Certifications such as OSWE, OSCP, GWAPT, GCSA, GCPN, or ML security certs (not required but beneficial)
Qualifications
Must Haves
- 2–4 years of hands-on application security experience
- Experience integrating security tooling and automated checks into CI/CD pipelines
- Familiarity and experience with OWASP Top 10 and web testing methodologies
- Experience with effectively assessing and communicating risks and appropriate levels of urgency to management and engineering staff
- Experience with technical report writing and communication
- Strong manual code review experience in at least one major language (Java, JavaScript/TypeScript, C#, PHP, etc.)
- Solid threat-modeling expertise (STRIDE, attack trees, misuse cases) for both traditional systems and AI/LLM-integrated features
- Proficiency with SAST, SCA, DAST, web and mobile pentesting, container scanners, secrets-detection tools, and ideally AI-security scanning platforms
- Experience integrating security tooling and automated checks into CI/CD pipeline
- Scripting/automation skills (Python, Bash, Node) for building custom tooling and automating manual processes
- Good understanding of AI/LLM attack surfaces including prompt injection, insecure output handling, model-data leakage, and RAG vulnerabilities
- Strong knowledge of web/API security concepts (session management, secure storage, transport security)
- Excellent organizational, presentation, verbal, and written communication skills
- Ability to effectively assess and communicate risks and appropriate levels of urgency to management and engineering staff
- Aptitude for self-study, setting and achieving long term goals
- Actively seeks to remain technically current and increase expertise and abilities
- Challenges prevailing assumptions when appropriate
- Willing to adapt to changing technology and business landscapes
- Considers change as opportunities to be challenged and grow
- Ability to adapt style of communications to match audience and information sharing needs
- Ability to mentor junior developers/engineers in secure design and coding practices
- To be considered, candidates must already be authorized to work in the United States without the need for current or future sponsorship
- any applicant for this position must complete United States Government security clearance
- The United States Government requires that any applicant for this position must complete United States Government security clearance
- applicants without United States citizenship
Nice to Haves
- Experience performing **secure code reviews** or building internal developer tooling
- Previous work with **AI or LLM-integrated applications**, model security, or prompt safety
- Experience with **mobile security**, reverse engineering, or platform-specific secure coding
- Certifications such as OSWE, OSCP, GWAPT, GCSA, GCPN, or ML security certs (not required but beneficial)
Benefits
- Medical insurance
- Dental insurance
- Vision insurance
- HSA
- FSA
- Generous earned time off
- 401K/student loan repayment
- Life insurance & AD&D insurance
- Employee assistance program
- Employee stock purchase program
- Tuition reimbursement
- Performance-based incentive pay
- Short- and long-term disability
- Robust wellness program
- Hybrid work option: associates living within 30 miles of an office location can work remotely for part of the week, with in-office presence three days per week.