Job Closed
This listing is no longer active.
Security Engineer II – Application
Location
United States
Posted
83 days ago
Salary
$127K - $207K / year
Seniority
Mid Level
Job Description
Security Engineer II – Application
NerdWallet
• Partner closely with engineering teams across the company to reduce security risk throughout the software development lifecycle • Contribute to initiatives that strengthen NerdWallet’s security posture by improving tooling, workflows, and standards that help engineers build secure software while maintaining a great developer experience • Help scale NerdWallet’s application security program through automation, tooling, and developer enablement • Partner with engineering and product teams to identify and remediate security gaps across multiple systems while balancing business priorities • Build tools, processes, and automation that improve security posture visibility for engineers and leadership • Review pull requests and provide actionable guidance on secure coding practices • Support operational work during security investigations or incidents affecting applications • Help integrate security practices into the secure development lifecycle (SDLC) across teams
Job Requirements
- 2+ years of experience in application security, software engineering, or a related security role
- Experience identifying, triaging, and remediating security vulnerabilities in applications
- Experience working with software deployed in cloud environments, particularly AWS
- Proficient in Python or another scripting language used for automation
- Comfortable reading and reviewing JavaScript or similar application code
- Experience or interest in building automation, tooling, or processes that improve application security workflows
- Comfortable learning new programming languages, frameworks, or security tools as needed
Benefits
- Industry-leading medical, dental, and vision health care plans for employees and their dependents
- Rejuvenation Policy – Flexible Vacation Time Off + 11 holidays + holiday company shutdown
- New Parent Leave for employees with a newborn child or a child placed with them for adoption or foster care
- Mental health support
- Paid sabbatical after 5 years for Nerds to recharge, gain knowledge, and pursue their interests
- Health and Dependent Care FSA and HSA Plan with monthly NerdWallet contribution
- Monthly Wellness Stipend, Cell Phone Stipend, and Wifi Stipend (Only remote Nerds are eligible for the Wifi Stipend)
- Work from home equipment stipend and co-working space subsidy (Only remote Nerds are eligible for these stipends)
- Nerd-led group initiatives – Employee Resource Groups for Parents, Diversity, and Inclusion, Women, LGBTQIA, and other communities
- Hackathons and team events across all teams and departments
- Company-wide events like NerdLove (employee appreciation) and our annual Charity Auction
- Our Nerds love to make an impact by paying it forward – Take 8 hours of volunteer time off per quarter and donate to your favorite causes with a company match
- 401K with 4% company match
- Be the first to test and benefit from our new financial products and tools
- Financial wellness, guidance, and unlimited access to a Certified Financial Planner (CFP) through Northstar
- Disability and Life Insurance with employer-paid premiums
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
Security Engineer
SUSESUSE is a global leader in innovative, reliable, and secure enterprise open source solutions, including SUSE® Linux Suite, SUSE® Rancher Suite, SUSE® Edge Suite, and SUSE® AI Suite. More than 60% of the Fortune 500 rely on SUSE to power their mission-critical workloads, enabling them to innovate everywhere – from the data center to the cloud, to the edge and beyond. SUSE puts the “open” back in open source, collaborating with partners and communities to give customers the agility to tackle innovation challenges today and the freedom to evolve their strategy and solutions tomorrow.
• Lead and contribute to the security of software solutions. • Manage the quality and performance of security measures. • Conduct thorough quality and performance testing of security features and systems. • Establish and enforce robust software engineering processes within the security team. • Collaborate with cross-functional teams to integrate security into the entire software development lifecycle (SDLC). • Stay abreast of the latest security threats, vulnerabilities, and industry best practices.
Type of Requisition: Regular Clearance Level Must Currently Possess: None Clearance Level Must Be Able to Obtain: None Public Trust/Other Required: SSBI (T5) Job Family: IT Infrastructure and Operations Job Qualifications: Skills: Access Management, Electronic Health Records (EHR), Information Technology Project Management, Single Sign-On (SSO)Certifications: NoneExperience: 8 + years of related experienceUS Citizenship Required: No Job Description: GDIT has been supporting the IHS mission for 20+ years; working with the agency to provide integral services to raise health access and availability to 2.6 million American Indians and Alaska Natives. You'll be part of modernizing an Electronic Health Record (EHR) platform to enable better data access, patient experience, and quality of care for 567 tribes, 37 states and over 600 medical facilities. Our work depends on an Identity and Access Management (IAM) Sustainment Lead joining our team to support the Indian Health Service (IHS) Electronic Health Records Modernization (EHRM) program. As an Identity and Access Management Sustainment Lead supporting the IHS EHRM program, you will be responsible for driving IAM initiatives across GDIT IHS EHRM Engineering and Sustainment teams, and with various IHS customer teams. This position is fully remote, US based. This role requires you to obtain and maintain an in-depth Public Trust Level 5. This investigation will review personal and criminal behavior, financial conduct, foreign influence, as well as other adjudications. HOW THIS ROLE WILL MAKE AN IMPACT: - Will be responsible for leading, designing, and technical integration of Identity and Access Management (IAM) frameworks, systems, and protocols for the IHS Modernization program. - Significant focus on designing IAM processes for concurrent, multi-facility rollout of a large, cloud-based instance of Oracle Health (Cerner Millennium) EHR. - Effort will initially focus on Pilot facility and first grouping of additional facilities; responsibilities will shift towards sustainment and support processes over time. - Significant interaction with various IHS customer-side teams, including end-user systems support and engineering, networking infrastructure, and cybersecurity. - Will be responsible for SSO, authentication and access controls ensuring confidentiality, integrity and availability of IAM systems and data. - Prepares and maintains documentation for processes and procedures per Government requests. - Maintains current knowledge of rapidly changing technology and works with management to evolve current processes. REQUIRED QUALIFICATIONS AND EXPERIENCE: - Bachelor’s degree or equivalent combination of education and experience. - 8+ years of experience supporting medium to large IT projects to include performance reporting and system setup. - Significant experience with Oracle Health (Cerner Millennium) software, specifically role-based access, user positions, and Millennium core concepts - Significant experience with industry-based IAM authentication and authorization software, such as Okta, Active Directory, ServiceNOW - Extensive understanding of expense and timekeeping management, process, and policies. - Training/education/experience in task coordination; functional knowledge of IT project management concepts and tools. - Must be able to obtain and maintain a Public Trust Level 5 clearance. - Ability to travel up to 25% of the year, if needed. DESIRED QUALIFICATIONS AND EXPERIENCE: - 8+ years of relevant analyst experience. - Experience with large, federal programs and/or contracts. - Task management experience and/or skills. - Excellent organizational and time management skills; ability to manage frequently changing priorities of competing importance. - Ability to communicate and interact effectively with internal/external teams including key stakeholders, various customer teams, and/or executive leadership. - Ability to work and support the work of others across multiple U.S. time zones. - Ability to work independently with minimal supervision and within tight deadlines, following detailed written policies, processes, procedures, and work instructions. - Ability to produce high-quality documentation that contributes to the overall success of the program. GDIT IS YOUR PLACE: - Full-flex work week to own your priorities at work and at home. - 401K with company match. - Comprehensive health and wellness packages. - Internal mobility team dedicated to helping you own your career. - Professional growth opportunities including paid education and certifications. - Cutting-edge technology you can learn from. - Rest and recharge with paid vacation and holidays. #IHSJobs #GDITFedHealthJobs #EHR #IHSEHRM The likely salary range for this position is $149,469 - $189,750. This is not, however, a guarantee of compensation or salary. Rather, salary will be set based on experience, geographic location and possibly contractual requirements and could fall outside of this range. Scheduled Weekly Hours: 40 Travel Required: 10-25% Telecommuting Options: Remote Work Location: Any Location / Remote Additional Work Locations: Total Rewards at GDIT: Our benefits package for all US-based employees includes a variety of medical plan options, some with Health Savings Accounts, dental plan options, a vision plan, and a 401(k) plan offering the ability to contribute both pre and post-tax dollars up to the IRS annual limits and receive a company match. To encourage work/life balance, GDIT offers employees full flex work weeks where possible and a variety of paid time off plans, including vacation, sick and personal time, holidays, paid parental, military, bereavement and jury duty leave. GDIT typically provides new employees with 15 days of paid leave per calendar year to be used for vacations, personal business, and illness and an additional 10 paid holidays per year. Paid leave and paid holidays are prorated based on the employee’s date of hire. The GDIT Paid Family Leave program provides a total of up to 160 hours of paid leave in a rolling 12 month period for eligible employees. To ensure our employees are able to protect their income, other offerings such as short and long-term disability benefits, life, accidental death and dismemberment, personal accident, critical illness and business travel and accident insurance are provided or available. We regularly review our Total Rewards package to ensure our offerings are competitive and reflect what our employees have told us they value most. We are GDIT. A global technology and professional services company that delivers consulting, technology and mission services to every major agency across the U.S. government, defense and intelligence community. Our 30,000 experts extract the power of technology to create immediate value and deliver solutions at the edge of innovation. We operate across 50 countries worldwide, offering leading capabilities in digital modernization, AI/ML, Cloud, Cyber and application development. Together with our clients, we strive to create a safer, smarter world by harnessing the power of deep expertise and advanced technology. Join our Talent Community to stay up to date on our career opportunities and events atgdit.com/tc. Equal Opportunity Employer / Individuals with Disabilities / Protected Veterans
Head of Risk, Security
Bio-TechneEmpowering scientists & clinicians by providing high-quality reagents, analytical instruments, & precision diagnostics.
• Mature and execute Akoya’s enterprise risk management (ERM) framework. • Develop and track key risk indicators (KRIs) aligned with business OKRs. • Lead third-party risk management across fintech partners, vendors, and service providers. • Conduct product risk assessments across new open finance capabilities. • Support regulatory readiness related to CFPB Section 1033 and evolving open banking requirements. • Lead day-to-day execution of Akoya’s cybersecurity program across product, infrastructure, and corporate environments. • Operationalize secure-by-design principles across SDLC in partnership with Engineering. • Oversee vulnerability management, penetration testing, red teaming, and incident response. • Drive continuous improvement of zero-trust cloud architectures (AWS-centric). • Enhance monitoring, automation, and threat intelligence capabilities. • Own operational execution of SOC 2 Type II and other certifications. • Ensure alignment with NIST, ISO 27001/27002, GLBA, SOX, PCI (as applicable). • Partner closely with Legal and Product on regulatory interpretation and implementation. • Respond to due diligence inquiries from financial institutions, fintechs, investors, and regulators. • Oversee corporate IT governance in partnership with the IT Systems Administrator (end-user security, device management, identity, remote access). • Ensure strong IAM, endpoint protection, DLP, encryption, and secure collaboration tooling. • Align IT and Security controls with remote-first operating model. • Lead and mentor security engineers, risk analysts, and IT personnel. • Build scalable team structure aligned with growth in API volume and institutional adoption. • Foster a strong security culture where accountability and transparency are embedded across functions. • Act as a senior advisor to ELT. • Interface directly with security and risk leaders at major financial institutions and fintech clients. • Support sales and customer conversations requiring deep technical credibility. • Represent Akoya in industry forums and working groups (e.g., FDX-aligned initiatives).
• Work with a nimble passionate security team, collaborating with development and product. • Conduct vulnerability triage: handle internal and external vulnerability reports, and more importantly: go beyond investigating and write fixes yourself. • Review code and help make decisions about secure coding decisions. • Review new product features to ensure they are designed with security in mind • Collaborate with other developers and teams for long term security success. • Code solutions for preventative measures and generating alerts. • Use your detective work to get to the AH-HA! moment when you find and replicate the root cause of an issue and figure out how to fix it. • You will care and be involved in our product, mission, and success - way beyond checking off tasks.




