AppSec Jobs
← Back to all jobs

Navy Federal Credit Union

Senior Cyber Security Analyst (CAAT)

Vienna, Virginia, United StatesWebsite

Full details on LinkedIn

The complete job description, requirements, and application details are available on the original posting.


About Navy Federal Credit Union

Navy Federal Credit Union (NFCU) is the largest credit union in the world, established in 1933. Originally serving Navy Department employees, it expanded its membership in 1954 to include Navy and Marine Corps officers, and has since grown to over 11 million members, including enlisted personnel and Department of Defense employees. Headquartered in Vienna, Virginia, NFCU offers a wide range of financial services tailored to the military community. These include banking services like checking and savings accounts, loans for vehicles and homes, various credit card options, investment services, and insurance products. NFCU also provides digital banking solutions for convenient account management and specialized military benefits, such as financial education and deployment assistance. The credit union is committed to meeting the unique financial needs of military members and their families.

Industry

financial services

Employees

26,000

1176 engineers

Revenue

$9.3B

Website

Visit →

Security at Navy Federal Credit Union

Compiled from public job postings, careers pages, and company materials. Data may not reflect current state — verify during interviews.

3 Intel Signals

Security Philosophy

Stated AppSec Mission: "Our responsibilities include incident detection and response, penetration testing, application security"(: Navy Federal responsibilities described by CISO). Developer Enablement vs. Gatekeeping: "If security becomes a blocker, you've lost the room.""The Security Champions Program provides development teams support to incorporate application security activities". Risk Philosophy: "enabling the business, helping to develop secure, quick-to-market products". Stated Pain Points or Goals (Verbatim): "documented security requirements in NFCU's Security Standards". Gaps & Contradictions: Information not publicly available for explicit, public AppSec mission statements beyond leadership interview quotes. No public contradictions found among available sources.

Security Team

Org Structure & Reporting Line: "Our responsibilities include incident detection and response, penetration testing, application security"( interpretation: CISO lists application security within his remit). Key Public-Facing Leaders: Mike Newborn, Chief Information Security Officer. Key Quote: "If security becomes a blocker, you've lost the room."Team Size Estimate (as_of:): Information not publicly available (no authoritative public headcount or consolidated AppSec team size found). Active AppSec Job Postings (as_of:): Count: At least 3 AppSec-related postings identified (internships and job listings). Common Skill/Tool Patterns: Job postings emphasize Security Champions, standards/controls, and security governance knowledge (NIST/FFIEC references in job descriptions). Specific AppSec tool names (SAST/SCA/DAST) are not listed in public job postings. Gaps & Contradictions: No public org chart or reporting-chain document found. Team size and dedicated AppSec headcount are not publicly available.

Key Initiatives

Security Champions Program: Status: Evidence Found. "The Security Champions Program provides development teams support to incorporate application security activities". "Support Navy Federal's Security Champions Program by coordinating activities". "Shift Left"in Practice: Information not publicly available (specific pre-commit/IDE/CI/CD practices). Vulnerability Management Process: Intake: "Discovered a Site Vulnerability? Report It Here". Triage/Remediation: Public details of triage SLAs and remediation workflow: Information not publicly available. Secure SDLC Artifacts: "documented security requirements in NFCU's Security Standards". "enabling the business, helping to develop secure, quick-to-market products". Recent Initiatives (Last 6 Months): No public evidence of distinct new AppSec tool rollouts or policy changes in the last six months. Information not publicly available for other recent initiatives. Gaps & Contradictions: No public, detailed descriptions of AppSec operational workflows (CI/CD integration, SAST/SCA tool lists, triage SLAs, or remediation ownership). Specific shift-left technical practices and toolchain evidence are not available publicly.

Preparing for an AppSec interview?

Get the weekly briefing 2,000+ security pros trust.