Application Security Engineer developing security solutions for Nelnet's application security program. Collaborating with IT and business teams to enhance security posture and educate developers.
Responsibilities
Develop and maintain applications to support our application security concepts
Develop security reference implementations
Integrate security into our build and deploy pipelines
Maintain security controls and measure implementation across technology platforms, .NET, Java, Cloud, etc
Enable controls to monitor our development supply chain (i.e.third party dependencies)
Remediate and facilitate the resolution of vulnerabilities
Participate and facilitate Risk Assessment and Threat Modeling
Serve as an auditing, consulting, and training resource to all Nelnet product teams
Perform appropriate vulnerability scanning – static and dynamic analysis
Work with external entities that are performing vulnerability scans
Participate in tool and vendor selection process from a security perspective.
Create and update learning resources for application security
Develop and present on application security topics for a wide variety of audiences
Stay informed about application security best practices across Nelnet development platforms including web, mobile, and cloud
Requirements
BS / MS in Computer Science, Engineering, related discipline or equivalent experience
Minimum 2 years of experience in web application software development.
Minimum 1 years of experience focused on Application Security.
Understanding of a variety of application development architectures, platforms, methodologies, and supporting operating system
Experience identifying and protecting against web application and web-service security vulnerabilities including those found in the OWASP Top 10 and CWE Top 25
Knowledge of authentication and authorization, cryptography, and API security
Ability to identify, triage, manage, and remediate security vulnerabilities
Experience with build processes and CI/CD
Knowledge of cloud technologies
Experience with web and API development technologies such as .NET, Java, NPM, Angular, React
Operations Application Engineer at Fiserv, ensuring reliability of business applications and high - performance systems. Involves automation, monitoring, and incident response in Fintech services.
Project Application Engineer defining system requirements and specifications for Industrial Systems in Roanoke, VA. Collaborating with clients and suppliers for successful project execution.
Serve as a technical expert in CFD tools helping customers realize their value. Deliver software demonstrations, training, and support as part of a collaborative team.
Principal Security Engineer at Binti focusing on securing software applications for social services. Conducting assessments, responding to incidents, and improving security architecture in a collaborative environment.
Technical expert in industry‑leading CFD tools such as ANSYS Fluent and CFX. Partnering with account managers and customers to drive pre - sales success and deliver impactful technical support.
Lead Applications Engineer for Power Island Mechanical Systems developing SMR plant technology solutions. Collaborating with internal teams and external partners for technical proposals and designs.
Application Engineer providing technical and commercial solutions to support Data Center sales team. Collaborating closely with customers and internal teams for effective project delivery.
Customer Application Support Engineer providing technical support for Linux BSP and driver integration issues at NXP. Collaborating with customers during product development phases for embedded applications.
Senior Customer Application Engineer at NXP leading technical support for power and motor control applications. Engaging with Indian customers and global teams for mass production deployments.
Application Support Engineer providing technical support for logistics applications with a focus on troubleshooting and performance monitoring. Collaborating with development and business teams for issue resolution in a hybrid work environment.