Security Engineer II (AppSec)
NerdWallet - San Francisco, CA
Apply NowJob Description
If you were here 6 months ago, here are some things you might have worked on:Designed and implemented a dashboard for on call activities for the team.Helped triage and respond to security findings and alerts generated by application security toolsCompleted a penetration test of an external system, and participated in red team campaigns.Collaborated with engineers to remediate vulnerabilities and improve secure coding practicesContributed to automation or tooling that improves visibility into application security risksWhere you can make an impact:Help scale NerdWallet's application security program through automation, tooling, and developer enablementPartner with engineering and product teams to identify and remediate security gaps across multiple systems while balancing business prioritiesBuild tools, processes, and automation that improve security posture visibility for engineers and leadershipReview pull requests and provide actionable guidance on secure coding practicesSupport operational work during security investigations or incidents affecting applicationsHelp integrate security practices into the secure development lifecycle (SDLC) across teamsYou are:Familiar with common web application vulnerabilities and mitigation techniques, such as the OWASP Top 10Pragmatic in your approach to reducing risk, balancing security improvements with product and engineering prioritiesCurious and motivated to continuously grow your application security knowledge and skillsComfortable asking questions, seeking guidance, collaborating, and debating with teammates when working through complex problemsCommitted to fostering a respectful, blameless, and collaborative engineering cultureInterested in helping engineers understand and adopt secure development practicesYour experience:2+ years of experience in application security, software engineering, or a related security roleExperience identifying, triaging, and remediating security vulnerabilities in applicationsExperience working with software deployed in cloud environments, particularly AWSProficient in Python or another scripting language used for automationComfortable reading and reviewing JavaScript or similar application codeExperience or interest in building automation, tooling, or processes that improve application security workflowsComfortable learning new programming languages, frameworks, or security tools as neededWhere:This role will be remote (based in the U.S.).We believe great work can be done anywhere. No matter where you are based, NerdWallet offers benefits and perks to support the physical, financial, and emotional well being of you and your family.What we offer:Work Hard, Stay Balanced (Life's a series of balancing acts, eh?)Industry-leading medical, dental, and vision health care plans for employees and their dependentsRejuvenation Policy - Flexible Vacation Time Off + 11 holidays + holiday company shutdownNew Parent Leave for employees with a newborn child or a child placed with them for adoption or foster careMental health supportPaid sabbatical after 5 years for Nerds to recharge, gain knowledge, and pursue their interestsHealth and Dependent Care FSA and HSA Plan with monthly NerdWallet contributionMonthly Wellness Stipend, Cell Phone Stipend, and Wifi Stipend (Only remote Nerds are eligible for the Wifi Stipend)Work from home equipment stipend and co-working space subsidy (Only remote Nerds are eligible for these stipends)Have Some Fun! (Nerds are fun, too)Nerd-led group initiatives - Employee Resource Groups for Parents, Diversity, and Inclusion, Women, LGBTQIA, and other communitiesHackathons and team events across all teams and departmentsCompany-wide events like NerdLove (employee appreciation) and our annual Charity AuctionOur Nerds love to make an impact by paying it forward - Take 8 hours of volunteer time off per quarter and donate to your favorite causes with a company matchPlan for your future (And when you retire on your island, remember the little people)401K with 4% company matchBe the first to test and benefit from our new financial products and toolsFinancial wellness, guidance, and unlimited access to a Certified Financial Planner (CFP) through NorthstarDisability and Life Insurance with employer-paid premiumsIf you are based in California, we encourage you to read this important information for California residents linked here.NerdWallet is committed to pursuing and hiring a diverse workforce and is proud to be an equal opportunity employer. We prohibit discrimination and harassment on the basis of any characteristic protected by applicable federal, state, or local law, so all qualified applicants will receive consideration for employment.NerdWallet will consider qualified applicants with a criminal history pursuant to the California Fair Chance Act and the San Francisco Fair Chance Act, which requires this notice, as well as the Los Angeles Fair Chance Act, which requires this notice.NerdWallet participates in the Department of Homeland Security U.S. Citizenship and Immigration Services E-Verify program for all US locations. For more information, please see:E-Verify Participation Poster (English+Spanish/Español)Right to Work Poster (English) / (Spanish/Español)#LI-DNI #J-18808-Ljbffr
Created: 2026-04-20