Driving Possibility
Application Security Engineer II
Location
United States
Posted
2 days ago
Salary
$85.7K - $125.7K / year
Seniority
Mid Level
Job Description
Application Security Engineer II
Credit Acceptance
Role Description The Application Security Engineer is responsible for securing the software and applications that Credit Acceptance builds, buys, and operates. This role partners closely with engineering, product, architecture, and business teams to ensure that applications handling sensitive consumer, dealer, and loan data are designed, developed, and deployed in a secure manner, meeting both internal security standards and the regulatory expectations of a financial services environment. This position focuses on embedding security into the software development lifecycle by providing hands-on technical guidance, performing threat modeling and application security reviews, defining secure design patterns and guardrails, and supporting engineering teams as they build and maintain modern web, mobile, API, and cloud-based applications. This position will work from home; occasional planned travel to an assigned Southfield, Michigan office location may be required. However, this position is permitted to work at a Southfield, Michigan office location if requested by the team member. Outcomes and Activities - Partner with engineering and architecture teams to design and review application architectures (web, mobile, API, and microservices) for security, privacy, and regulatory compliance. - Perform security reviews of applications and services at each stage of the SDLC, including: - Design - Code - Building pipelines - Dependencies - Infrastructure-as-code - Third-party components - Identify and mitigate risks such as: - Injection - Authentication/authorization - Injection and session management flaws (OWASP Top 10, ASVS) - Insecure handling of NPI, PII, and payment data - Management of open-source dependency vulnerabilities and software supply chain risks - Insecure cloud configurations, secrets management, and exposed APIs - Support threat modeling and risk assessments for new and existing applications, assisting teams in implementing practical mitigations. - Assess and help mitigate security risks introduced by AI-assisted and agentic development tools (e.g., GitHub Copilot, Claude Code, LiteLLM). Governance, Standards, and Policy - Contribute to and operationalize application security standards, secure coding guidelines, and secure design patterns used across the company. - Evaluate application security tooling (SAST, DAST, SCA, IAST, secrets scanning, ASPM) and vendors to ensure alignment with security, privacy, and compliance requirements. - Support compliance with regulatory and industry frameworks (e.g., PCI DSS, GLBA, NIST SSDF, SOX) in collaboration with legal, compliance, audit, and risk partners. - Contribute to standards and guardrails for secure use of AI-assisted development tools and agentic coding workflows. Collaboration & Advisory - Act as a trusted security advisor to Engineering, Product, and DevOps teams building, maintaining, and operating applications at Credit Acceptance. - Participate in design reviews, sprint planning, and architecture working sessions focused on secure development and deployment. - Provide guidance on the secure use of frameworks, libraries, APIs, authentication systems, and cloud services that interact with company systems and data. - Advise engineering teams on safe adoption of AI coding assistants and agentic development tools. Continuous Improvement - Stay current on application security threats, vulnerabilities, and best practices, including emerging risks across web, mobile, API, and cloud-native applications. - Recommend improvements to tooling, processes, and controls to strengthen the company's application security posture and shift security left in the SDLC. - Contribute to internal documentation, secure coding training, and security enablement for developers and engineering teams. Qualifications - Bachelor’s Degree or equivalent experience - 3+ years of experience in application security, product security, or secure software development. - 2+ years of hands-on experience performing application security reviews, penetration testing, threat modeling, or secure code review. Preferred - Experience securing modern web, mobile, and API-based applications in a regulated industry (e.g., financial services, healthcare). - Familiarity with the OWASP Top 10, OWASP ASVS, and OWASP SAMM, and with software supply chain frameworks such as SLSA. - Experience with cloud platforms (e.g., AWS, Azure, GCP) and containerized environments. - Knowledge of regulatory and compliance considerations relevant to financial services (e.g., PCI DSS, GLBA, SOX). - Experience embedding security into software development workflows (DevSecOps) and CI/CD pipelines. - Hands-on experience with application security tooling such as SAST, DAST, SCA, IAST, secrets scanning, or ASPM platforms. - Relevant certifications (e.g., GWAPT, GWEB, OSWE, CSSLP, CISSP) a plus. - Familiarity with security considerations for AI-assisted development environments (e.g., GitHub Copilot, Claude Code) and LLM gateway/proxy tooling (e.g., LiteLLM). Knowledge and Skills - Strong understanding of modern software development practices, frameworks, and architectures (web, mobile, API, microservices, serverless). - Working knowledge of common application vulnerabilities and exploitation techniques, and the controls that mitigate them. - Understanding of authentication, authorization, identity, cryptography, and secure data handling patterns. - Familiarity with threat modeling, security testing, and risk assessment techniques. - Ability to read and reason about code in one or more common programming languages. - Working knowledge of AI-assisted and agentic software development tools (e.g., GitHub Copilot, Claude Code, LiteLLM) and the security risks they introduce in the SDLC. - Ability to communicate security risks and recommendations clearly to both technical and non-technical audiences. Target Compensation A competitive base salary range from $85,695 – $125,685. This position is eligible for an annual variable cash bonus, between 7.5 - 15%. Bonus amounts are based on individual performance. Final compensation within the range is influenced by many factors including role-specific skills, depth and experience level, industry background, relevant education, and certifications. Candidates who reside in the following major metropolitan areas may be eligible for a premium on top of the posted range based on their specific zone: San Francisco, Seattle, Boston, New York City, Los Angeles, and San Diego. Benefits - Excellent benefits package that includes 401(K) match, adoption assistance, parental leave, tuition reimbursement, comprehensive medical/dental/vision, and many nonstandard benefits that make us a Great Place to Work. Company Values - Positive by maintaining resiliency and focusing on solutions. - Respectful by collaborating and actively listening. - Insightful by cultivating innovation, accumulating business and role-specific knowledge, demonstrating self-awareness, and making quality decisions. - Direct by effectively communicating and conveying courage. - Earnest by taking accountability, applying feedback, and effectively planning and priority setting. Expectations - Remain compliant with our policies, processes, and legal guidelines. - All other duties as assigned. - Attendance as required by department.
Related Guides
Related Categories
Related Job Pages
More Application Engineer Jobs
Staff Application Security Engineer
Agility RoboticsWe build robots made for work, engineered to work in nearly any environment, alongside people.
• Security Development Lifecycle (SDLC) Integration: Drive the implementation of security practices throughout the entire software development process, from design review through deployment. • Application Security Testing: Perform offensive penetration testing and defensive (Blue Team) testing on web applications, internal services, and robot-side software to identify and remediate vulnerabilities. • Automation and Tooling: Implement and manage security tools, including Static Application Security Testing (SAST) or Dynamic Application Security Testing (DAST) or runtime vulnerability assessments, and Software Bill of Materials (SBOM) systems. Implementation of these systems using tools such as JFrog Artifactory, GitHub Advanced Security, Datadog, Wiz or Snyk. • Code Review and Governance: Define and enforce security policies for source code, including mandatory GitHub security practices and review procedures. • Vulnerability Management: Manage the lifecycle of identified vulnerabilities, prioritizing remediation efforts based on risk to the fleet, proprietary code, and cloud infrastructure. • Collaboration: Partner with development, platform, and infrastructure teams to ensure security requirements are met without hindering engineering velocity.
Senior Application Security Engineer
Agility RoboticsWe build robots made for work, engineered to work in nearly any environment, alongside people.
• Security Development Lifecycle (SDLC) Integration: Support security practices throughout the entire software development process, from design review through deployment. • Application Security Testing: Perform offensive penetration testing on web applications, internal services, and robot-side software to identify and remediate vulnerabilities. • Automation and Tooling: Support security tools, including Static Application Security Testing (SAST) or Dynamic Application Security Testing (DAST) or runtime vulnerability assessments, and Software Bill of Materials (SBOM) systems. Experience with systems such as Artifactory and GitHub Security. • Threat Modeling and Security Reviews: Support threat modeling including security reviews of major software releases. • Vulnerability Management: Manage the lifecycle of identified vulnerabilities, prioritizing remediation efforts based on risk to the fleet, proprietary code, and cloud infrastructure. • Collaboration: Partner with development, platform, and infrastructure teams to ensure security requirements are met without hindering engineering velocity.
VistA Pharmacy Applications Release Verifier
GovCIOGovCIO is a service-disabled-veteran-owned small business (SDVOSB) that offers technology services to improve business performance for government organizations.
Role Description GovCIO is seeking a VistA Pharmacy Applications Release Verifier (Remote/Part-Time) to join our Patient Care Services Product line, in the Office of Information Technology at the Department of Veterans Affairs. The candidate will support the release management and package verification of VistA-related patches using the National Patch Module (NPM) on FORUM. This position will be a fully remote within the United States with core hours of operation from Monday to Friday 8 AM to 5 PM ET. - Collaborate closely with development teams, Health Infrastructure and Systems Management (HISM) VistA Applications teams, Software Quality Assurance (SQA), and VHA Initial Operating Capability (IOC) test sites throughout the full patch lifecycle. - Ensure all requirements, validations, and release steps are executed according to VistA Patch Release standards. - Coordinate end-to-end VistA patch testing and release activities using the National Patch Module (NPM). - Perform Verifier responsibilities, including checklist execution, review validation, compliance date alignment, and patch status updates. - Manage release artifacts by moving builds, executables, and documentation to the National File Server as required. - Analyze defect incidents, reproduce issues, conduct assessments, and document findings for defect resolution. - Maintain Problem Incident updates throughout development, testing, and verification phases. - Evaluate enhancement requirements by reviewing user stories and validating expected functionality. - Create Patch Stubs following VistA Patch Template standards, including Packman and Host File formats. - Develop complete Patch Descriptions with accurate installation steps and required supporting documentation. - Upload KIDS Builds to NPM on FORUM and document progress in Problem Incidents. - Coordinate with other Verifiers or Functional Analysts when development overlaps across product areas. - Conduct technical preparation activities such as checksum verification and routine backups. - Update routines using approved VistA tools (KIDS Utilities, ^XINDEX) and submit Data Dictionary changes to the DBA. - Validate ICR usage, submit new or updated ICR requests, and coordinate HL7 messaging reviews for impacted components. - Support FDA impact reviews and assess external system impacts, engaging stakeholders as needed. - Assist developer unit testing, coordinate peer code reviews, and support SQA using the VistA SQA Checklist. - Prepare all required SQA and UAT distribution materials, including developer checklists, documentation, and versioned Host File Builds. Qualifications - Master's with 10 years (or commensurate experience) - Strong understanding of software development lifecycles (SDLC), Agile/SAFe, and CI/CD pipelines. - Proven experience coordinating complex, multiteam releases in enterprise or mission-critical environments. - Exceptional communication, facilitation, and stakeholder management skills. - Ability to manage multiple releases simultaneously with tight deadlines. - Strong analytical, organizational, and problem-solving skills. Requirements - Ability to obtain and maintain a Suitability/Public Trust clearance Preferred Skills and Experience - Experience working within the Department of Veterans Affairs (VA) or other federal healthcare environments. - Familiarity with NPM, KIDS Builds, HL7 messaging, Data Dictionary structures, and VistA architecture. - Experience with incident/problem management and structured testing methodologies. SAFe ITIL, PMP, or Agile certification(s). - Experience with automated testing, monitoring, and deployment tooling. - Strong understanding of risk, compliance, and audit requirements for production systems. Posted Salary Range USD $55.00 - USD $60.00 /Hr.
Senior Application Security Engineer
vCluster LabsvCluster Labs is a venture-backed tech startup headquartered in San Francisco, California, with a distributed, remote-first team spanning eight time zones. Foun
Lead end-to-end security for products, perform deep-dive security reviews, manage vulnerability lifecycles, and integrate security checks into workflows to ensure a robust security posture in multi-tenant environments.


