NFL - Junior Application Security Engineer
Indexed description
Junior Application Security Engineer (6 month contract)
The NFL Information Security Office is seeking a Junior Application Security Engineer to help protect and secure applications used and developed across the League. This role will support the Application & Offensive Security team by helping enforce application security standards, improve secure SDLC adoption, triage findings from AppSec tools, maintain application and API inventory data, and communicate security risk to technology and business stakeholders.
The ideal candidate has foundational technical knowledge, a strong interest in application security, and the ability to learn quickly while working across security, IT, development, risk, and business teams. This role is a strong fit for someone early in their security career who wants hands-on exposure to code scanning, vulnerability management, threat modeling, API security, application architecture, penetration testing support, and real-world security operations.
Responsibilities
• Support application security policy enforcement and secure SDLC adoption across NFL applications.
• Assist with SAST, DAST, SCA, API security testing, mobile application security testing, and penetration testing coordination.
• Triage, route, and track findings from application security tools and related AppSec sources.
• Help maintain inventories of NFL applications, APIs, ownership data, and business criticality context.
• Serve as a first-line support contact for AppSec-related questions from IT and business lines.
• Assist application teams with threat modeling, architecture diagrams, and security testing expectations.
• Communicate findings in a clear, risk-based manner for application owners, technical teams, Risk, and Governance.
• Support vulnerability remediation tracking, re-scans, validation, and reporting.
• Create or maintain scripts and lightweight automation to improve AppSec workflows.
• Participate in vulnerability disclosure, application assessments, and offensive security activities under senior team guidance.
Required Qualifications
• Foundational understanding of application security, secure coding, vulnerability management, and SDLC concepts.
• Familiarity with scripting or programming languages such as Python, Go, Ruby, JavaScript, TypeScript, PowerShell, or Bash.
• Basic understanding of networking, HTTP, APIs, operating systems, and web application architecture.
• Familiarity with common AppSec testing concepts such as SAST, SCA, DAST, API testing, mobile testing, and penetration testing.
• Ability to analyze technical findings and communicate clearly with technical and non-technical stakeholders.
• Analytical skills, curiosity, accountability, and ability to complete tasks with minimal supervision.
Preferred Qualifications NFL Information Security Office
• Experience with application scanners, web proxies, vulnerability management tools, source code repositories, or CI/CD pipelines.
• Exposure to cloud-based applications, APIs, containers, or modern software delivery environments.
• Experience creating scripts or automation to support security workflows.
• Coursework, internship, certification, lab, or project experience in cybersecurity, software engineering, computer science, or a related technical field.
Why This Role Matters
• This role helps strengthen the NFL’s application security program by improving coverage across applications, APIs, vulnerability triage, secure SDLC enablement, and business-line support.
The position adds hands-on capacity to help reduce security risk, improve remediation follow-up, and mature AppSec practices across the League.
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search