Tesla
Tesla

Fullstack Software Engineer, Information Security Team

RoleFull Stack
LevelMid Level
LocationAustin, TX, United States
WorkOn-site
TypeFull-time
PostedToday
Apply now

About the role

What to Expect
We are seeking a highly skilled and security-conscious Full Stack Engineer to design, develop, and maintain secure, high-performance web applications and backend systems. You will work across the entire stack — from frontend interfaces to backend services, databases, and infrastructure — while ensuring that security is a foundational principle at every layer.
This role demands a strong understanding of secure coding practices, threat modeling, and compliance standards. You’ll collaborate with product, design, security, and DevOps teams to deliver systems that are not only fast and scalable, but also resilient to attacks and aligned with industry best practices.
What You’ll Do

  • Design, build, and maintain secure full-stack applications using modern frameworks and tools, with security as a core requirement
  • Build and secure RESTful APIs and microservices using Node.js, Python, or Go, with strict input validation, rate limiting, and authentication/authorization controls
  • Design and manage database schemas with security in mind: enforce least-privilege access, prevent injection attacks (SQL, NoSQL), and ensure data encryption at rest and in transit
  • Implement and maintain secure CI/CD pipelines with automated security scanning (SAST/DAST), dependency checks, and policy enforcement
  • Integrate authentication and authorization mechanisms (e.g., OAuth2, JWT, SSO, RBAC) and enforce secure session management
  • Apply secure coding standards and conduct regular code reviews with a focus on vulnerabilities (e.g., XSS, CSRF, insecure deserialization)
  • Participate in threat modeling for new features and systems, identifying risks early in the design phase
  • Collaborate with the Security and DevOps teams to harden infrastructure, monitor for anomalies, and respond to incidents
  • Troubleshoot and remediate security issues in production, including root cause analysis and patching
  • Contribute to security documentation, incident response playbooks, and internal training on secure development practices

What You’ll Bring

  • Degree in Computer Science, Engineering, or a related field or equivalent practical experience
  • 3–5 years of professional experience in full stack development with a strong focus on security
  • Proficiency in modern frontend technologies: React, TypeScript, HTML5, CSS3, Webpack, REST APIs
  • Strong backend development skills in Node.js, Python, or Go, with experience implementing secure APIs
  • Experience with database security: SQL/NoSQL injection prevention, role-based access control, encryption
  • Hands-on experience with cloud platforms (AWS, GCP, or Azure) and secure infrastructure patterns (IAM, VPC, WAF, etc.)
  • Familiarity with containerization (Docker) and orchestration (Kubernetes) with security best practices (pod security policies, image scanning)
  • Experience with CI/CD security tools: SAST (Sonar Qube, Snyk), DAST, dependency scanning (Dependabot, Renovate), and secrets management
  • Understanding of security frameworks and standards: OWASP Top 10, NIST, ISO 27001, SOC 2, or GDPR
  • Excellent problem-solving skills, attention to detail, and a proactive mindset toward identifying and mitigating risks

About Tesla

Austin

Headquarters