Cybersecurity Application Security Engineer

Nelnet
Harrisburg, PA

Nelnet is a diversified and innovative company committed to enriching lives through the power of service as a student loan servicer, professional services company, consumer loan originator and servicer, payments processor, renewable energy solutions, and K-12 and higher education expert. For over 40 years, Nelnet has been serving its customers, associates, and communities.

The perks of working at Nelnet go beyond our benefits package. When you join the Nelnet team, you're part of a community invested in the success of each individual. That support comes through in our work, as we are united by our mission of creating opportunities for people where they live, learn, and work.

We are seeking a highly skilled Application Security Engineer with strong experience across secure code review, penetration testing, automation, and modern SDLC practices-including emerging AI/LLM security. In this role, you will partner closely with engineering, cloud, and product teams to safeguard our applications, services, and AI-driven components from design through production. You will combine hands-on technical testing with scalable automation and developer enablement to mature our AppSec program and ensure secure, resilient applications at speed.

This position requires work in support of the Company's contract with the United States Department of Education ("ED"). As such, the United States Government requires that any applicant for this position must complete United States Government security clearance. Effective June 1, 2018, ED has informed Nelnet that security clearance applications for foreign nationals are not being accepted or processed. In light of this direction from ED, Nelnet will be unable to hire applicants without United States citizenship for such positions.

This position offers a hybrid work option. Nelnet values flexibility and understands the importance of work-life integration. Our hybrid work environment allows associates Living within 30 miles of an office location to work remotely for part of the week, while also fostering collaboration and team connection through in-office presence three days per week.

Please note that we are unable to provide visa sponsorship for this position. To be considered, candidates must already be authorized to work in the United States without the need for current or future sponsorship.

Job Description

  • Manual Source Code Review

  • SAST/DAST scanning

  • Expand the Security Champions program

  • Develop automated source code review processes

  • Work with product teams to ensure secure SDLC processes are in place

  • Provide detail vulnerability reports to businesses

EXPERIENCE:

  • 2-4 years of hands-on application security experience

  • Experience integrating security tooling and automated checks into CI/CD pipelines

  • Familiarity and experience with OWASP Top 10 and web testing methodologies

  • Experience with effectively assessing and communicating risks and appropriate levels of urgency to management and engineering staff

  • Experience with technical report writing and communication

COMPETENCIES - SKILLS/KNOWLEDGE/ABILITIES:

Needs:

  • Strong manual code review experience in at least one major language (Java, JavaScript/TypeScript, C#, PHP, etc.)

  • Solid threat-modeling expertise (STRIDE, attack trees, misuse cases) for both traditional systems and AI/LLM-integrated features

  • Proficiency with SAST, SCA, DAST, web and mobile pentesting, container scanners, secrets-detection tools, and ideally AI-security scanning platforms

  • Experience integrating security tooling and automated checks into CI/CD pipeline

  • Scripting/automation skills (Python, Bash, Node) for building custom tooling and automating manual processes

  • Good understanding of AI/LLM attack surfaces including prompt injection, insecure output handling, model-data leakage, and RAG vulnerabilities

  • Strong knowledge of web/API security concepts (session management, secure storage, transport security)

  • Excellent organizational, presentation, verbal, and written communication skills

  • Ability to effectively assess and communicate risks and appropriate levels of urgency to management and engineering staff

  • Aptitude for self-study, setting and achieving long term goals

  • Actively seeks to remain technically current and increase expertise and abilities

  • Challenges prevailing assumptions when appropriate

  • Willing to adapt to changing technology and business landscapes

  • Considers change as opportunities to be challenged and grow

  • Ability to adapt style of communications to match audience and information sharing needs

Wants:

  • Experience performing secure code reviews or building internal developer tooling.

  • Previous work with AI or LLM-integrated applications , model security, or prompt safety.

  • Experience with mobile security , reverse engineering, or platform-specific secure coding.

  • Certifications such as OSWE, OSCP, GWAPT, GCSA, GCPN, or ML security certs (not required but beneficial).

  • Ability to mentor junior developers/engineers in secure design and coding practices.

Pay range for this role is $90,000-$125,000 annually, depending on experience.

#LI-CW1

#LI-Hybrid

#LI-REMOTE

Our benefits package includes medical, dental, vision, HSA and FSA, generous earned time off, 401K/student loan repayment, life insurance & AD&D insurance, employee assistance program, employee stock purchase program, tuition reimbursement, performance-based incentive pay, short- and long-term disability, and a robust wellness program. Click here to learn more about our benefits: LINK ( .

Nelnet is committed to providing a welcoming and respectful workplace where all associates have the opportunity to succeed. As an Equal Opportunity Employer, we ensure that all qualified applicants are considered for employment. Employment decisions are made without regard to race, color, religion/creed, national origin, gender, sex, marital status, age, disability, use of a guide dog or service animal, sexual orientation, military/veteran status, or any other status protected by federal, state, or local law. We value the unique contributions of every team member and believe that a positive work environment benefits everyone.

Qualified individuals with disabilities who require reasonable accommodations in order to apply or compete for positions at Nelnet may request such accommodations by contacting Corporate Recruiting at 402-486-5725 or [email protected] .

Nelnet is a Drug Free and Tobacco Free Workplace.

You may know Nelnet as the nation's largest student loan servicer - but we do more than that. A lot more. We're also a professional services company, consumer loan originator and servicer, payment processor, renewable energy innovator, and K-12 and higher education expert (and that's just a shortlist). For over 40 years, we've been serving our customers, associates, and communities to make dreams possible.

EEO Info ( | EEO Letter ( | EPPA Info ( | FMLA Info (

Posted 2026-05-03

Recommended Jobs

Lifesharing Provider for Adults w/ Intellectual Disabilities, Schuylkill Region

Access Services
Reading, PA

What is Lifesharing? Lifesharing is an opportunity for you to open your home and share your life with an adult with an intellectual disability. Do I get to choose who lives with me? W…

View Details
Posted 2026-01-14

FPOB for Faculty Opportunity 1 Hour to Pittsburgh

B.E.L. Associates, Inc.
Pittsburgh, PA

Family Medicine Core Faculty Opportunity for Family Medicine with OB - outside of Pittsburgh, PA. Seeking full-time core faculty member/s who are committed to teaching, supervising and administrative…

View Details
Posted 2026-04-16

Concrete Finisher

Maker Construction Corp.
New Castle, PA

Job Description Job Description Role Summary Install, place, finish, and repair concrete across residential and commercial scopes including flatwork, decorative/stamped concrete, exposed aggre…

View Details
Posted 2026-04-10

Server/Host (Altoona)

UPMC - University of Pittsburgh Medical Center
Altoona, PA

Server/Host (Host Diet Clerk) UPMC Altoona has immediate openings for Host Diet Clerks (in our Nutrition Services department). We are looking for friendly faces to help provide excellent experience…

View Details
Posted 2026-05-01

Superintendent, Norristown Area School District

Alma Advisory Group
Norristown, PA

About Our District Norristown Area School District (NASD) represents 3 municipalities; Norristown (known locally as the Borough), and the Townships of East Norriton and West Norriton, all located …

View Details
Posted 2026-02-22

Travel Registered Nurse LTC Job

New Holland, PA

Job Overview TLC Nursing Associates, Inc. is seeking an experienced Registered Nurse (RN) – Long-Term Care (LTC) for travel assignments . This role involves providing compassionate and skille…

View Details
Posted 2026-04-03

Licensed Insurance Customer Service

State Farm Agency - Easton, PA
Easton, PA

Position Overview Successful State Farm Agent is seeking a qualified professional to join their winning team for the role of Licensed Customer Service Representative - State Farm Agent Team Member.…

View Details
Posted 2025-08-30

Sales Design Consultant.

Renuity
Philadelphia, PA

Sales Design Consultant- Up to $140,000 Closet America , a proud company of the Renuity family, where innovation and excellence drive everything we do. As part of a powerful network of seven of …

View Details
Posted 2026-04-24

Senior Electrical Engineer

QorTek, Inc.
Linden, PA

Job description: QorTek is seeking an on-site Senior Electrical Engineer to take on challenges in our Electronics R&D team. This exclusive group of engineers is responsible for the design and develop…

View Details
Posted 2026-04-03

Fiscal Operations Intern

WESTMORELANDFAYETTE WORKFORCE INVESTMENT BOARD
Youngwood, PA

Fiscal Operations Intern Westmoreland-Fayette Workforce Investment Board | Youngwood, PA Summary The Westmoreland-Fayette Workforce Investment Board (WFWIB) is the leader in regional …

View Details
Posted 2026-04-17