Senior Security Developer
Listed on 2026-09-24
-
IT/Tech
Cybersecurity
Our mission is to provide a positive, empowering, and transparent property financing experience that is simple from start to finish. Our team consists of skilled technology experts, caring mortgage specialists, and a diverse marketing team, all working together to lead change in the mortgage industry.
At nesto, we're proud of- Our clients love our positive, empowering, and transparent mortgage financing experience.
- Our 4.5-star Google reviews speak for themselves!
- We won the 2023 & 2024 CLA Lender of the Year award, recognizing our excellence in lending services.
- We are a B Corp certified organization, highlighting our dedication to making a positive impact on our society and our planet.
- Our highly skilled, diverse, and collaborative team, makes everything possible!
- Our Mortgage Cloud platform gives financial institutions full access to nesto’s proprietary technology, powering a better client experience, from start to finish.
We're a fast-paced, interdisciplinary team working on multiple tech projects simultaneously. Our team is diverse and works on different products and nesto experiences that are all interconnected.
We are looking for a Cloud Security Developer to join our dynamic team. In this role, you will play a critical role in designing, implementing, and maintaining cloud security solutions to protect our cloud-based systems and applications. You will work closely with our development and operations teams to ensure the security and integrity of our cloud infrastructure.
We celebrate a variety of perspectives and experiences. We are not looking for someone who checks every single box - we’re looking for lifelong learners and people who can make us better with their unique experiences.
What you'll be doing- Implement and maintain robust security controls to protect our cloud infrastructure and applications.
- Discover, remediate, and validate security issues across cloud infrastructure.
- Perform architectural/design reviews through a security lens and provide timely, actionable requirements and recommendations.
- Collaborate with security leadership, compliance, and engineering teams to execute security strategies.
- Build, deploy, and manage security tools such as WAF, IDS/IPS, workload protection, GCP Command Center, and Azure Security Center, etc.
- Propose and contribute to security and compliance improvements for nesto CI/CD pipelines and deployment processes.
- Automate infrastructure provisioning and deployment processes using Infrastructure as Code (IaC) tools like Terraform or Pulumi.
- Design and operate scalable processes to provision cloud access and maintain least privilege.
- Participate in and support the incident detection and response process by enhancing observability and alerting and assisting the incident response team.
- Self-organize and prioritize activities independently.
- Support audits and first‑party security questionnaires.
- Conduct and oversee security assessments and threat modeling exercises.
- Implement security controls within Kubernetes.
- Build Dev Sec Ops tools/integrations.
- 5+ years of experience working on a team focused on infrastructure and/or security.
- 5+ years of development experience (ideally GoLang, Type Script/JS).
- Knowledge of common web application vulnerabilities and the OWASP Top 10 framework.
- The ability to analyze and act on results from DAST and SAST tools (e.g., Tenable, Snyk).
- Skilled in Dev Sec Ops principles and familiarity with CI/CD pipelines (Git Hub Actions, Argo CD, Azure Dev Ops) to perform automated security testing.
- Experience deploying and customizing security tools to address threats and lower risk, including vulnerability scanners, static analyzers, web application firewalls (WAFs), intrusion detection/prevention systems…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).