Senior Engineer – Cybersecurity Application Security

Posted Yesterday
Be an Early Applicant
Irving, TX, USA
In-Office
Senior level
Fintech
The Role
Implement and improve application security tooling across the secure software development lifecycle. Integrate security testing and controls into CI/CD pipelines, administer SAST, DAST, SCA, IAST, container, API, and supply-chain security capabilities, and support vulnerability remediation, governance, compliance reporting, and security automation. Partner with engineering and architecture teams to promote secure-by-design practices, develop security standards and documentation, and govern emerging AI-assisted development workflows.
Summary Generated by Built In

Key Responsibilities

  • Implement, administer, and continuously improve application security tooling supporting secure software development.
  • Integrate security testing and security controls into software delivery pipelines and engineering workflows.
  • Develop, maintain, and enhance application security standards, policies, procedures, documentation, and operational guidance.
  • Analyze security findings, operational metrics, and compliance trends to identify improvement opportunities and areas of elevated risk.
  • Partner with engineering teams to improve security adoption and enable secure-by-design and secure-by-default development practices.
  • Support secure SDLC governance, vulnerability management, and remediation tracking activities.
  • Collaborate with cybersecurity, architecture, platform, and engineering stakeholders to improve overall application security maturity.
  • Contribute to security automation initiatives that increase operational efficiency and reduce manual effort.
  • Support the secure implementation of emerging software development practices, including AI-assisted development workflows.

Required Qualifications

  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Engineering, or a related field.
  • 5+ years of application security engineering experience.
  • Experience implementing and administering application security platforms, including SAST, DAST, SCA, IAST, container security, API security testing, and software supply chain security capabilities.
  • Experience securing APIs across the development lifecycle, including API discovery, authentication and authorization validation, schema and contract testing, abuse-case analysis, OWASP API Security Top 10 risks, and remediation guidance.
  • Experience integrating security tooling and automated security controls into CI/CD pipelines using infrastructure-as-code (IAC).
  • Experience supporting secure SDLC governance, policy enforcement, compliance reporting, and remediation management.
  • Working knowledge of application security principles, secure coding practices, OWASP Top 10 risks, and common vulnerability remediation techniques.
  • Experience developing and maintaining technical standards, procedures, policies, and security documentation.
  • Strong written and verbal communication skills with the ability to influence technical stakeholders.
  • Ability to independently manage moderately complex security initiatives and contribute to broader cybersecurity objectives.

Preferred Qualifications

  • Industry certifications such as CSSLP, GSEC, CISSP, GWAPT, or similar.
  • Experience supporting financial services, banking, or other highly regulated environments.
  • Experience assessing, implementing, and governing security controls for AI-assisted software development workflows, including secure use of code-generation tools, prompt and output handling, developer guardrails, and risk monitoring.
  • Experience with security automation, scripting, and workflow orchestration.
  • Experience creating executive, engineering, or operational security metrics and dashboards.

OneMain Holdings, Inc. is an Equal Employment Opportunity (EEO) employer. Qualified applicants will receive consideration for employment without regard to age, ancestry, citizenship status, color, creed, culture, disability, ethnicity, gender, gender identity or expression, genetic information or history, marital status, military status, national origin, nationality, pregnancy, race, religion, sex, sexual orientation, socioeconomic status, transgender or on any other basis protected by law.

Skills Required

  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Engineering, or a related field
  • 5+ years of application security engineering experience
  • Experience implementing and administering SAST, DAST, SCA, IAST, container security, API security testing, and software supply chain security platforms
  • Experience securing APIs across the development lifecycle, including API discovery, authentication and authorization validation, schema and contract testing, abuse-case analysis, OWASP API Security Top 10 risks, and remediation guidance
  • Experience integrating security tooling and automated security controls into CI/CD pipelines using Infrastructure as Code
  • Experience supporting secure SDLC governance, policy enforcement, compliance reporting, and remediation management
  • Working knowledge of application security principles, secure coding practices, OWASP Top 10 risks, and vulnerability remediation techniques
  • Experience developing and maintaining technical standards, procedures, policies, and security documentation
  • Strong written and verbal communication skills with the ability to influence technical stakeholders
  • Ability to independently manage moderately complex security initiatives and contribute to broader cybersecurity objectives
  • Industry certifications such as CSSLP, GSEC, CISSP, GWAPT, or similar
  • Experience supporting financial services, banking, or other highly regulated environments
  • Experience assessing, implementing, and governing security controls for AI-assisted software development workflows
  • Experience with security automation, scripting, and workflow orchestration
  • Experience creating executive, engineering, or operational security metrics and dashboards

OneMain Financial Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about OneMain Financial and has not been reviewed or approved by OneMain Financial.

  • Retirement Support Retirement benefits include a 401(k) with a dollar-for-dollar match up to 4% after six months, supporting long-term savings. An employee stock purchase plan with a 10% discount adds another ownership-oriented reward element.
  • Leave & Time Off Breadth Time-off offerings include vacation that can grow to five weeks, paid holidays, personal days, sick time, and three paid volunteer days. Paid parental leave is offered at 100% pay for six weeks, adding to the overall leave mix.
  • Flexible Benefits A broad menu of benefits spans HSAs/FSAs, disability coverage, life and long-term care solutions, tuition reimbursement, and voluntary options like pet insurance and legal assistance. Backup child/elder care and adoption assistance further widen the set of selectable supports.

OneMain Financial Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Baltimore, Maryland
5,386 Employees
Year Founded: 1912

What We Do

OneMain provides personal loans with one on one, local service at branches nationwide. Our personalized loan solutions offer customers a simple and straightforward loan application, fixed rates, fixed payments, clear terms and multiple payment options.

Similar Jobs

MetLife Logo MetLife

Recruiter

Fintech • Information Technology • Insurance • Financial Services • Big Data Analytics
Remote or Hybrid
United States
43000 Employees
95K-125K Annually

CrowdStrike Logo CrowdStrike

Analyst I, Falcon Complete (Remote, PST/MST)

Cloud • Computer Vision • Information Technology • Sales • Security • Cybersecurity
Remote or Hybrid
USA
11000 Employees
85K-120K Annually

CrowdStrike Logo CrowdStrike

Analyst I, Falcon Complete (Remote, PST/MST)

Cloud • Computer Vision • Information Technology • Sales • Security • Cybersecurity
Remote or Hybrid
USA
11000 Employees
85K-120K Annually

CrowdStrike Logo CrowdStrike

Consultant

Cloud • Computer Vision • Information Technology • Sales • Security • Cybersecurity
Remote or Hybrid
USA
11000 Employees
115K-160K Annually

Similar Companies Hiring

Hanover Park Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
42 Employees
Kepler  Thumbnail
Artificial Intelligence • Fintech • Software
New York, New York
9 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account