热门公司

招聘

职位NerdWallet

Security Engineer II (Application)

NerdWallet

Security Engineer II (Application)

NerdWallet

NerdWallet US

·

On-site

·

Full-time

·

4w ago

At Nerd Wallet, we’re on a mission to bring clarity to all of life’s financial decisions and every great mission needs a team of exceptional Nerds. We’ve built an inclusive, flexible, and candid culture where you’re empowered to grow, take smart risks, and be unapologetically yourself (cape optional). Whether remote or in-office, we support how you thrive best. We invest in your well-being, development, and ability to make an impact because when one Nerd levels up, we all do.

We are seeking a Security Engineer II to join our Application Security team. The Application Security team enables Nerd Wallet’s mission—to provide clarity for all of life’s financial decisions, by helping ensure the products and services we design and build safeguard our users’ data and trust.

In this role, you’ll partner closely with engineering teams across the company to reduce security risk throughout the software development lifecycle. You’ll contribute to initiatives that strengthen Nerd Wallet’s security posture by improving tooling, workflows, and standards that help engineers build secure software while maintaining a great developer experience.

This role is ideal for someone who enjoys solving security challenges collaboratively, building scalable solutions, and helping engineers integrate security practices into their day-to-day work. You’ll have the opportunity to grow your application security expertise while contributing meaningfully to a maturing security program.

This role will report to a Business Information Security Officer.

IF YOU WERE HERE 6 MONTHS AGO, HERE ARE SOME THINGS YOU MIGHT HAVE WORKED ON:

  • Designed and implemented a dashboard for on call activities for the team.

  • Helped triage and respond to security findings and alerts generated by application security tools

  • Completed a penetration test of an external system, and participated in red team campaigns.

  • Collaborated with engineers to remediate vulnerabilities and improve secure coding practices

  • Contributed to automation or tooling that improves visibility into application security risks

WHERE YOU CAN MAKE AN IMPACT:

  • Help scale Nerd Wallet’s application security program through automation, tooling, and developer enablement

  • Partner with engineering and product teams to identify and remediate security gaps across multiple systems while balancing business priorities

  • Build tools, processes, and automation that improve security posture visibility for engineers and leadership

  • Review pull requests and provide actionable guidance on secure coding practices

  • Support operational work during security investigations or incidents affecting applications

  • Help integrate security practices into the secure development lifecycle (SDLC) across teams

YOU ARE:

  • Familiar with common web application vulnerabilities and mitigation techniques, such as the OWASP Top 10

  • Pragmatic in your approach to reducing risk, balancing security improvements with product and engineering priorities

  • Curious and motivated to continuously grow your application security knowledge and skills

  • Comfortable asking questions, seeking guidance, collaborating, and debating with teammates when working through complex problems

  • Committed to fostering a respectful, blameless, and collaborative engineering culture

  • Interested in helping engineers understand and adopt secure development practices

YOUR EXPERIENCE:

  • 2+ years of experience in application security, software engineering, or a related security role

  • Experience identifying, triaging, and remediating security vulnerabilities in applications

  • Experience working with software deployed in cloud environments, particularly AWS

  • Proficient in Python or another scripting language used for automation

  • Comfortable reading and reviewing JavaScript or similar application code

  • Experience or interest in building automation, tooling, or processes that improve application security workflows

  • Comfortable learning new programming languages, frameworks, or security tools as needed

WHERE:

  • This role will be remote (based in the U.S.).

  • We believe great work can be done anywhere. No matter where you are based, Nerd Wallet offers benefits and perks to support the physical, financial, and emotional well being of you and your family.

WHAT WE OFFER:

Work Hard, Stay Balanced (Life’s a series of balancing acts, eh?)

  • Industry-leading medical, dental, and vision health care plans for employees and their dependents

  • Rejuvenation Policy – Flexible Vacation Time Off + 11 holidays + holiday company shutdown

  • New Parent Leave for employees with a newborn child or a child placed with them for adoption or foster care

  • Mental health support

  • Paid sabbatical after 5 years for Nerds to recharge, gain knowledge, and pursue their interests

  • Health and Dependent Care FSA and HSA Plan with monthly Nerd Wallet contribution

  • Monthly Wellness Stipend, Cell Phone Stipend, and Wifi Stipend (Only remote Nerds are eligible for the Wifi Stipend)

  • Work from home equipment stipend and co-working space subsidy (Only remote Nerds are eligible for these stipends)

Have Some Fun! (Nerds are fun, too)

  • Nerd-led group initiatives – Employee Resource Groups for Parents, Diversity, and Inclusion, Women, LGBTQIA, and other communities

  • Hackathons and team events across all teams and departments

  • Company-wide events like Nerd Love (employee appreciation) and our annual Charity Auction

  • Our Nerds love to make an impact by paying it forward – Take 8 hours of volunteer time off per quarter and donate to your favorite causes with a company match

Plan for your future (And when you retire on your island, remember the little people)

  • 401K with 4% company match

  • Be the first to test and benefit from our new financial products and tools

  • Financial wellness, guidance, and unlimited access to a Certified Financial Planner (CFP) through Northstar

  • Disability and Life Insurance with employer-paid premiums

If you are based in California, we encourage you to read this important information for California residents linked here https://www.nerdwallet.com/privacy-policy.

Nerd Wallet is committed to pursuing and hiring a diverse workforce and is proud to be an equal opportunity employer. We prohibit discrimination and harassment on the basis of any characteristic protected by applicable federal, state, or local law, so all qualified applicants will receive consideration for employment.

NerdWallet will consider qualified applicants with a criminal history pursuant to the California Fair Chance Act and the San Francisco Fair Chance Act, which requires this notice https://www.sf.gov/sites/default/files/2022-12/FCO%20poster2020_0.pdf, as well as the Los Angeles Fair Chance Act, which requires this notice https://dcba.lacounty.gov/wp-content/uploads/2024/08/FCOE-Official-Notice-Eng-Final-8.30.2024.pdf.

Nerd Wallet participates in the Department of Homeland Security U.S. Citizenship and Immigration Services E-Verify program for all US locations. For more information, please see:

  • E-Verify Participation Poster (English+Spanish/Español https://www.e-verify.gov/sites/default/files/everify/posters/EVerifyParticipationPoster.pdf)

  • Right to Work Poster (English) https://www.uscis.gov/sites/default/files/USCIS/Verification/E-Verify/E-Verify_Native_Documents/OSC_Right_to_Work_Poster.pdf / (Spanish/Español) https://www.uscis.gov/sites/default/files/USCIS/Verification/E-Verify/E-Verify_Native_Documents/OSC_Right_to_Work_Poster_ES.pdf

总浏览量

0

申请点击数

0

模拟申请者数

0

收藏

0

关于NerdWallet

NerdWallet

NerdWallet is an American personal finance company, founded in 2009 by Tim Chen and Jacob Gibson. It has a website and app that earns money by promoting financial products to its users.

201-500

员工数

San Francisco

总部位置

$1.5B

企业估值

评价

3.9

10条评价

工作生活平衡

3.2

薪酬

3.8

企业文化

4.1

职业发展

3.7

管理层

3.0

72%

推荐给朋友

优点

Flexible hours and schedule

Supportive management and colleagues

Growth and advancement opportunities

缺点

Heavy workload and long hours

Stressful during peak times

Lack of leadership direction

薪资范围

48个数据点

Senior/L5

Senior/L5 · Security Engineer II

1份报告

$234,130

年薪总额

基本工资

$180,100

股票

-

奖金

-

$234,130

$234,130

面试经验

2次面试

难度

2.5

/ 5

时长

14-28周

录用率

50%

体验

正面 50%

中性 50%

负面 0%

面试流程

1

Application Review

2

Recruiter Screen

3

Technical Phone Screen

4

Onsite/Virtual Interviews

5

Team Matching

6

Offer

常见问题

Coding/Algorithm

Technical Knowledge

Behavioral/STAR

System Design

Culture Fit