Senior Software Engineer, Application Security - AV and Software Infrastructure
Tech Stack
Tag name is followed by "@" symbol and proficiency level value.
About proficiency levels:
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
AI
API @ 4
CI/CD @ 3
Communication @ 4
Distributed Systems @ 4
Go @ 7
IaC
Java @ 7
Kubernetes @ 3
OAuth @ 4
Python @ 7
Security @ 4
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
Details
NVIDIA’s Autonomous Vehicle Infrastructure and Software Infrastructure teams build platforms that engineers use to develop, test, and deliver software at scale. The application security engineer will help secure the services, APIs, developer tools, and data platforms behind these workflows.
The role involves working closely with software engineers and NVIDIA’s security teams to identify risks, build protections, and make secure development easier. Work will span architecture, code, and production systems, with particular attention to identity, authorization, sensitive data, and the software development lifecycle.
Responsibilities
- Review application designs and code, develop threat models, and help teams address security risks before deployment.
- Design and implement authentication and authorization controls for APIs, services, and applications, including service identities, tenant isolation, and resource-level access.
- Build reusable libraries, tooling, and reference implementations that make secure patterns straightforward to adopt.
- Improve how applications handle credentials, secrets, sensitive data, and security-relevant logging.
- Integrate practical security checks into development and CI/CD workflows, with actionable findings and clear remediation paths.
- Investigate application vulnerabilities, develop fixes with service owners, and add regression coverage.
- Partner with infrastructure and corporate security teams to prioritize improvements and measure their effectiveness.
Requirements
- 12+ years of relevant experience and a BS or MS in Computer Science, Computer Engineering, or a related field, or equivalent experience.
- Experience building and operating production software, with substantial work in application or product security.
- Strong programming skills in Go, Python, Java, C++, or a comparable language, and the ability to review and modify unfamiliar code.
- Practical understanding of web and API security, authentication, authorization, and common vulnerability classes.
- Experience with threat modeling and security reviews for distributed systems.
- Ability to turn security findings into concrete engineering changes and prioritize work based on risk and impact.
- Clear communication and experience working collaboratively with engineering teams.
Preferred Qualifications
- Experience with OAuth 2.0, OpenID Connect, service identity, and authorization policy systems.
- Experience securing multi-tenant services, data platforms, or developer infrastructure.
- Familiarity with Kubernetes, cloud IAM, infrastructure as code, and CI/CD systems.
- Experience improving vulnerability detection or dependency security while reducing noisy findings.
- A record of building security capabilities that engineering teams adopt and use.
Compensation and Benefits
- Base salary range: $224,000–$356,500 USD, determined based on location, experience, and the pay of employees in similar positions.
- Eligible for equity and benefits.
- Applications will be accepted at least until October 9, 2026.
NVIDIA is committed to fostering an inclusive work environment and is an equal opportunity employer. NVIDIA also uses AI tools in its recruiting processes.