Security Software Engineer, AI & Automation
At NerdWallet, we're building tools and experiences that help people make smarter financial decisions. As a Security Software Engineer focused on AI and Automation, you'll help strengthen the security, reliability, and trust behind those experiences by designing AI-powered security systems that make secure software development more scalable and effective across our engineering organization.
In this role, you'll partner closely with security engineering and infrastructure teams to build automation and AI-powered solutions that help identify vulnerabilities, improve security reviews, and reduce risk across our platforms. You'll take ownership of security engineering initiatives that combine software development, AI systems experience, and security-first thinking to solve meaningful problems at scale.
You'll have room to bring new ideas, influence how AI and automation practices evolve at NerdWallet, and shape the future of security tooling within a team that values curiosity, informed risk-taking, and thoughtful problem-solving.
This role reports to the AI Security Manager.
Projects you may be working on in this position include:
Designing and building multi-agent LLM systems and routing logic that automate threat modeling, security design review, policy Q&A, and vulnerability analysis at scale
Developing retrieval-augmented generation (RAG) pipelines and semantic search systems across large code and documentation repositories
Creating automated code review capabilities that help identify insecure patterns and improve software quality earlier in the development lifecycle
Designing integrations with tools such as GitHub, Slack, Jira, Confluence, and cloud platforms to embed security guidance into everyday engineering workflows
Developing REST APIs and platform services with authentication, authorization, rate limiting, observability, and secure handling of sensitive data
Designing and maintaining scalable data processing pipelines for large codebases and document repositories, including extraction, indexing, stream processing, batch jobs, and parallel execution
Improving AI application security through controls such as prompt injection prevention, sensitive data filtering, supply chain security, and secure handling of model inputs and outputs
Enhancing NerdWallet's secure software development lifecycle (SSDLC) through automation, tooling, and developer-friendly security practices
Partnering with engineering teams to prioritize and remediate application and infrastructure security risks
Supporting incident response and on-call needs by contributing security engineering expertise, tooling, automation, and analysis when security issues arise
Identifying new opportunities for automation and AI augmentation across the security team, bringing fresh eyes and independent thinking to a growing backlog of high-impact work
Where you can make an impact:
Serve as technical lead on high-priority initiatives, taking ownership of technically complex work and collaborating across teams to deliver practical, measurable security outcomes
Help shape how AI and automation are securely adopted across NerdWallet's engineering ecosystem
Build tools and platforms that make security more accessible, scalable, and actionable for development teams
Improve the speed and quality of security reviews through thoughtful automation and security-first design
Strengthen customer trust by helping protect NerdWallet's products, systems, and sensitive data
Serve as an internal subject matter expert on AI and automation, advising on appropriate use cases, limitations, and risks to both technical and non-technical stakeholders
Your experience:
3+ years of software engineering or security engineering experience
Strong proficiency in Python or Go for building production-grade backend services, APIs, and data pipelines; comfort moving between languages is expected
Experience building and maintaining backend services including REST APIs, authentication, authorization, rate limiting, streaming, and observability
Working knowledge of application security concepts including common vulnerability classes such as injection, broken authentication, cross-site scripting, insecure authorization, and secrets exposure; experience with threat modeling and SSDLC practices
Hands-on experience building AI-powered systems using LLM APIs, including retrieval-augmented generation (RAG) pipelines, multi-agent architectures, and semantic search; working understanding of AI-specific security risks such as prompt injection, sensitive data exposure, and secure handling of model inputs and outputs
Genuine interest in AI and how it applies to security, not just as a tool to use, but as a domain to understand deeply, including its limitations and risks
Experience developing and operating distributed systems and cloud-based environments, including message queues, NoSQL databases, AWS, containers, Kubernetes or ECS, serverless, and infrastructure as code
Understanding of caching and performance patterns including Redis, semantic caching, TTLs, and cache invalidation
Strong communication skills, able to explain complex AI and security concepts clearly to both technical and non-technical audiences, and confident advising stakeholders on tradeoffs and limitations
Where:
This role will be remote (based in the U.S.).
We believe great work can be done anywhere. No matter where you are based, NerdWallet offers benefits and perks to support the physical, financial, and emotional well being of you and your family.
What we offer:
Work Hard, Stay Balanced (Life’s a series of balancing acts, eh?)
Industry-leading medical, dental, and vision health care plans for employees and their dependents
Rejuvenation Policy – Flexible Vacation Time Off + 11 holidays + holiday company shutdown
New Parent Leave for employees with a newborn child or a child placed with them for adoption or foster care
Mental health support
Paid sabbatical after 5 years for Nerds to recharge, gain knowledge, and pursue their interests
Health and Dependent Care FSA and HSA Plan with monthly NerdWallet contribution
Monthly Wellness Stipend, Cell Phone Stipend, and Wifi Stipend (Only remote Nerds are eligible for the Wifi Stipend)
Work from home equipment stipend and co-working space subsidy (Only remote Nerds are eligible for these stipends)
Have Some Fun! (Nerds are fun, too)
Nerd-led group initiatives – Employee Resource Groups for Parents, Diversity, and Inclusion, Women, LGBTQIA, and other communities
Hackathons and team events across all teams and departments
Company-wide events like NerdLove (employee appreciation) and our annual Charity Auction
Our Nerds love to make an impact by paying it forward – Take 8 hours of volunteer time off per quarter and donate to your favorite causes with a company match
Plan for your future (And when you retire on your island, remember the little people)
401K with 4% company match
Be the first to test and benefit from our new financial products and tools
Financial wellness, guidance, and unlimited access to a Certified Financial Planner (CFP) through Northstar
Disability and Life Insurance with employer-paid premiums
If you are based in California, we encourage you to read this important information for California residents linked here.
NerdWallet is committed to pursuing and hiring a diverse workforce and is proud to be an equal opportunity employer. We prohibit discrimination and harassment on the basis of any characteristic protected by applicable federal, state, or local law, so all qualified applicants will receive consideration for employment.
NerdWallet will consider qualified applicants with a criminal history pursuant to the California Fair Chance Act and the San Francisco Fair Chance Act, which requires this notice, as well as the Los Angeles Fair Chance Act, which requires this notice.
NerdWallet participates in the Department of Homeland Security U.S. Citizenship and Immigration Services E-Verify program for all US locations. For more information, please see:
E-Verify Participation Poster (English+Spanish/Español)
Right to Work Poster (English) / (Spanish/Español)
#LI-Remote
#LI-4
As published by ashby
Name, Email, Resume
- Preferred First Name
- Phone Number
- Cover Letter upload · optional
- What is your current or most recent company?
- LinkedIn URL
- Other website optional
- Do you have professional experience building and operating backend services or distributed systems using Python or Go in a cloud-based environment? yes / no
- Have you built or contributed to production or internal AI-powered systems using LLM APIs, retrieval-augmented generation (RAG), semantic search, or multi-agent workflows? If yes, briefly describe your involvement.
- Have you worked on a security-focused project, tool, or initiative? yes / no
- Describe an AI-powered application, automation, or software tool you personally built or significantly contributed to. What problem did it solve and what was your role?
- Why do you want to work at NerdWallet? written answer
- Have you ever worked at NerdWallet? yes / no
- How did you hear about this job? choose one
- If other, please specify: optional
- Do you currently reside in the country this role is listed in? yes / no
- Are you subject to a non-competition agreement or any other agreement which would preclude or restrict your employment at NerdWallet or any other NerdWallet subsidiary? yes / no
- If yes, please specify the jurisdiction (state, province, or country) and provide details about your agreements: written answer · optional
- Are you authorized to work in the country this role is listed in? yes / no
- Do you need, or will you need in the future, any immigration related support or sponsorship from NerdWallet in order to begin or continue employment with NerdWallet? yes / no