Enable job alerts via email!

Staff Application Security Engineer

NerdWallet, Inc

United States

Remote

USD 90,000 - 150,000

Full time

30+ days ago

Boost your interview chances

Create a job specific, tailored resume for higher success rate.

Job summary

Join a forward-thinking company as a Staff Application Security Engineer, where you'll lead high-priority security initiatives and safeguard the software ecosystem. You'll play a key role in integrating security into the development process, conducting assessments, and mentoring junior engineers. This innovative firm values collaboration and offers a supportive environment for personal and professional growth. Enjoy a range of perks, including comprehensive health plans, generous leave policies, and opportunities for community engagement. If you're passionate about security and eager to make a difference, this role is perfect for you.

Benefits

Industry-leading health care plans
Rejuvenation Policy - Vacation Time Off
Mental health support
Paid sabbatical
Monthly Wellness Stipend
Work from home equipment stipend
Employee Resource Groups
Hackathons and team events
401K with company match
Disability and Life Insurance

Qualifications

  • 8+ years of experience in security engineering or related fields.
  • Proven ability to lead security initiatives and mentor junior engineers.

Responsibilities

  • Identify risks in the SDLC and develop security tooling.
  • Drive initiatives like Supply Chain Security and Authentication improvements.

Skills

Security Engineering
Agile Development
Cloud Environments (AWS)
Application Security Testing Tools (SAST, DAST, SCA)
Infrastructure as Code (Terraform)
Containers (Docker, Kubernetes)
Continuous Integration (Jenkins, GitHub Actions)
Technical Design Review
Threat Modeling
Security Code Review

Tools

Jira
GitHub

Job description

NerdWallet is looking for a Staff Application Security Engineer to help advance our Security Engineering team by leading high-priority product security initiatives. This person will play a pivotal role in securing NerdWallet’s software ecosystem, reducing the risk of breaches, and building trust with customers and stakeholders. By proactively addressing security challenges, this role will help safeguard NerdWallet’s reputation, assets, and data.

The Staff Application Security Engineer will be responsible for securing NerdWallet products, by identifying risks early in the SDLC and developing application security tooling & processes to promote a ‘shift left’ security culture. You will be responsible for developing and scaling the security function by integrating security in the application development process, conducting security-related research and assessments, developing custom automated security and anti-fraud solutions, providing security analysis/design/training to the organization, and developing the technical skills of junior security engineers.

Where you can make an impact:
  • Ensure the timely delivery of high-priority product security initiatives
  • Be a strategic advisor to the Application and Product Security Program
  • Drive key initiatives like Supply Chain Security, Authentication, and Authorization improvements
  • Participate in expanding and maturing NerdWallet’s SSDLC program and its early adoption
  • Partner with cross-functional teams to identify product and application vulnerabilities and propose potential remediation opportunities and prioritization
  • Design and develop security tools and processes to be leveraged by development teams
  • Work closely with engineering to sustain processes or convert manual integrations to automated pipeline activities
  • Help build the Red Team
  • Be a technical mentor to junior members of the team and help develop their skills
Your experience:

We recognize not everyone will meet all of the criteria. If you meet most of the criteria below and you’re excited about the opportunity and willing to learn, we’d love to hear from you.

  • 8 + years of professional experience as a security engineer, software engineer, site reliability engineer, penetration tester/red team member, or security consultant
  • 5+ years of experience working in Agile development, with expertise in technologies such as cloud environments (e.g., AWS), application security testing tools (e.g., SAST, DAST, SCA), infrastructure as code (e.g., Terraform), containers (e.g., Docker, Kubernetes), continuous integration (e.g., Jenkins, GitHub Actions), integration of security testing tools into CI pipelines, defect tracking (e.g., Jira), and source code management (e.g., GitHub)
  • Advanced knowledge of: Python, Typescript, and other languages (Go, PHP)
  • High-level understanding of: security weaknesses, exploits, attacks and mitigations
  • In-depth knowledge of common application and network protocols, cryptographic primitives, authentication and authorization protocols, as well as common security threats, including attack techniques, evasive techniques, and preventative and defensive methods
  • Experience leading or participating in Security Development Lifecycle Practices, Threat Modeling, Technical Design Review, and Security Code Review
  • Proven success as a collaborator with the ability to convey high-level security concepts to team members across the organization and technical and non-technical stakeholders at all levels
Where:
  • This role will be remote (based in the U.S.).
What we offer:

Work Hard, Stay Balanced (Life’s a series of balancing acts, eh?)

  • Industry-leading medical, dental, and vision health care plans for employees and their dependents
  • Rejuvenation Policy – Vacation Time Off + 11 holidays + 4 Mental Health Days Off
  • New Parent Leave for employees with a newborn child or a child placed with them for adoption or foster care
  • Mental health support
  • Paid sabbatical for Nerds to recharge, gain knowledge and pursue their interests
  • Health and Dependent Care FSA and HSA Plan with monthly NerdWallet contribution
  • Monthly Wellness Stipend, Cell Phone Stipend, and Wifi Stipend
  • Work from home equipment stipend and co-working space subsidy

Have Some Fun! (Nerds are fun, too)

  • Nerd-led group initiatives – Employee Resource Groups for Parents, Diversity, and Inclusion, Women, LGBTQIA, and other communities
  • Hackathons and team events across all teams and departments
  • Company-wide events like NerdLove (employee appreciation) and our annual Charity Auction
  • Our Nerds love to make an impact by paying it forward – Take 8 hours of volunteer time off per quarter and donate to your favorite causes with a company match

Plan for your future (And when you retire on your island, remember the little people)

  • 401K with company match
  • Be the first to test and benefit from our new financial products and tools
  • Financial wellness, guidance, and unlimited access to a Certified Financial Planner (CFP) through Northstar
  • Disability and Life Insurance with employer-paid premiums

NerdWallet is committed to pursuing and hiring a diverse workforce and is proud to be an equal opportunity employer. We prohibit discrimination and harassment on the basis of any characteristic protected by applicable federal, state, or local law, so all qualified applicants will receive consideration for employment.

Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.

Similar jobs

Staff, Application Security Engineer

Twilio

Remote

CAD 143,000 - 178,000

30+ days ago

Staff Product Security Engineer

DataDirect Networks

Remote

USD 100,000 - 150,000

9 days ago

Staff Information Security Engineer

N-Power Medicine, Inc.

Remote

USD 145,000 - 183,000

12 days ago

Staff Product Security Engineer

Data Direct Networks

Remote

USD 100,000 - 150,000

2 days ago
Be an early applicant

Staff Security Engineer New Remote US

Mozilla Corporation

Remote

USD 138,000 - 217,000

6 days ago
Be an early applicant

Staff Security Engineer

Mozilla

Remote

USD 138,000 - 217,000

4 days ago
Be an early applicant

Staff Security Engineer

CVS Health

Remote

USD 80,000 - 100,000

4 days ago
Be an early applicant

Associate Network Security Engineer

ModernCyber LLC

Melbourne

Remote

USD 60,000 - 100,000

21 days ago

Staff Security Engineer

Tines

Remote

USD 80,000 - 100,000

30+ days ago