Remote Otter LogoRemoteOtter

Staff Application Security Engineer - Remote

Posted 9 weeks ago
Software Development
Full Time
USA
$152,000 - $282,000 USD/year

⚠️ This job is archived. Find available remote jobs here.

Overview

NerdWallet is looking for a Staff Application Security Engineer to help advance our Security Engineering team by leading high-priority product security initiatives. This person will play a pivotal role in securing NerdWallet’s software ecosystem, reducing the risk of breaches, and building trust with customers and stakeholders. By proactively addressing security challenges, this role will help safeguard NerdWallet’s reputation, assets, and data.

In Short

  • Ensure the timely delivery of high-priority product security initiatives
  • Be a strategic advisor to the Application and Product Security Program
  • Drive key initiatives like Supply Chain Security, Authentication, and Authorization improvements
  • Participate in expanding and maturing NerdWallet’s SSDLC program and its early adoption
  • Partner with cross-functional teams to identify product and application vulnerabilities and propose potential remediation opportunities and prioritization
  • Design and develop security tools and processes to be leveraged by development teams
  • Work closely with engineering to sustain processes or convert manual integrations to automated pipeline activities
  • Help build the Red Team
  • Be a technical mentor to junior members of the team and help develop their skills

Requirements

  • 8 + years of professional experience as a security engineer, software engineer, site reliability engineer, penetration tester/ red team member, or security consultant
  • 5+ years of experience working in Agile development, with expertise in technologies such as cloud environments (e.g., AWS), application security testing tools (e.g., SAST, DAST, SCA), infrastructure as code (e.g., Terraform), containers (e.g., Docker, Kubernetes), continuous integration (e.g., Jenkins, GitHub Actions), integration of security testing tools into CI pipelines, defect tracking (e.g., Jira), and source code management (e.g., GitHub)
  • Advanced knowledge of: Python, Typescript, and other languages (Go, PHP)
  • High-level understanding of: security weaknesses, exploits, attacks and mitigations
  • In-depth knowledge of common application and network protocols, cryptographic primitives, authentication and authorization protocols, as well as common security threats, including attack techniques, evasive techniques, and preventative and defensive methods
  • Experience leading or participating in Security Development Lifecycle Practices, Threat Modeling, Technical Design Review, and Security Code Review
  • Proven success as a collaborator with the ability to convey high-level security concepts to team members across the organization and technical and non-technical stakeholders at all levels

Benefits

  • Industry-leading medical, dental, and vision health care plans for employees and their dependents
  • Rejuvenation Policy – Vacation Time Off + 11 holidays + 4 Mental Health Days Off
  • New Parent Leave for employees with a newborn child or a child placed with them for adoption or foster care
  • Mental health support
  • Paid sabbatical for Nerds to recharge, gain knowledge and pursue their interests
  • Health and Dependent Care FSA and HSA Plan with monthly NerdWallet contribution
  • Monthly Wellness Stipend, Cell Phone Stipend, and Wifi Stipend
  • Work from home equipment stipend and co-working space subsidy
  • Nerd-led group initiatives – Employee Resource Groups for Parents, Diversity, and Inclusion, Women, LGBTQIA, and other communities
  • Hackathons and team events across all teams and departments
  • Company-wide events like NerdLove (employee appreciation) and our annual Charity Auction
  • Our Nerds love to make an impact by paying it forward – Take 8 hours of volunteer time off per quarter and donate to your favorite causes with a company match
  • 401K with company match
  • Be the first to test and benefit from our new financial products and tools
  • Financial wellness, guidance, and unlimited access to a Certified Financial Planner (CFP) through Northstar
  • Disability and Life Insurance with employer-paid premiums
NerdWallet logo

NerdWallet

NerdWallet is a remote-first company dedicated to helping consumers make informed financial decisions. With a focus on product security, NerdWallet is committed to safeguarding its software ecosystem and building trust with customers and stakeholders. The company fosters a culture of proactive security measures, integrating security into the software development lifecycle, and emphasizes collaboration across teams. NerdWallet values diversity and offers a range of benefits to support the well-being of its employees, including healthcare stipends, vacation time, and financial planning resources.

Share This Job!

Save This Job!

Similar Jobs:

NerdWallet logo

Staff Application Security Engineer - Remote

NerdWallet

9 weeks ago

NerdWallet is seeking a Staff Application Security Engineer to lead product security initiatives and enhance the security of its software ecosystem.

Canada
Full-time
Software Development
$153,000 - $231,000 CAD/year
NerdWallet logo

Staff Application Security Engineer - Remote

NerdWallet

9 weeks ago

NerdWallet is seeking a Staff Application Security Engineer to lead product security initiatives and enhance the security of its software ecosystem.

USA
Full-time
Software Development
$152,000 - $282,000 USD/year
Ironclad logo

Staff Application Security Engineer - Remote

Ironclad

23 weeks ago

Ironclad is looking for an Application Security Engineer to enhance their application security program.

United States
Full-time
Software Development
$190,000 - $210,000/year
Forma logo

Staff Application Security Engineer - Remote

Forma

34 weeks ago

Forma is seeking a Staff Application Security Engineer to enhance their security framework and protect data integrity.

United States
Full-time
Software Development
Engine logo

Staff/Senior Application Security Engineer - Remote

Engine

8 weeks ago

Engine is looking for a Staff/Senior Application Security Engineer to ensure the security and integrity of its applications and software systems.

Worldwide
Full-time
Software Development