CareerPlanGet AI match score →

Application Security Engineer II

New York, NY, US🌐 Remote💼 Full-time💰 $85,000–$125,000🗓 2026-06-07 → 2026-08-01

Core

Securing software and applications handling sensitive consumer, dealer, and loan data by embedding security into the software development lifecycle.

Role type

Application Security Engineer

Builds

Modern web, mobile, API, and cloud-based applications for a used and new car financing company

Domain

Financial services / Application Security

Deliverable

production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work

Required skills

Threat modeling, secure design patterns, SDLC security integration, OWASP Top 10 mitigation, NPI/PII/payment data protection, open-source dependency management, cloud security configuration, secrets management, API security, AI-assisted development security review, SAST/DAST/SCA/IAST tool evaluation, regulatory compliance (PCI DSS, GLBA, NIST SSDF, SOX)

Preferred skills

Experience with agentic development tools, AI coding assistant governance, secure coding training delivery

Technologies

GitHub Copilot, Claude Code, LiteLLM, SAST, DAST, SCA, IAST, ASPM, microservices, cloud-native frameworks

Responsibilities

Partner with engineering and architecture teams to design and review application architectures for security and compliance; Perform security reviews of applications and services at each stage of the SDLC; Identify and mitigate risks including injection flaws, insecure data handling, and supply chain vulnerabilities; Support threat modeling and risk assessments for new and existing applications; Evaluate application security tooling and vendors; Contribute to and operationalize application security standards and secure coding guidelines; Act as a trusted security advisor to Engineering, Product, and DevOps teams; Stay current on application security threats and best practices.

Seniority

Mid-level IC

Rewrite
## Responsibilities - Secure the software and applications that Credit Acceptance builds, buys, and operates. - Partner with engineering, product, architecture, and business teams to ensure applications handling sensitive consumer, dealer, and loan data are designed, developed, and deployed securely, meeting internal security standards and regulatory expectations. - Embed security into the software development lifecycle by providing hands-on technical guidance, performing threat modeling and application security reviews, defining secure design patterns and guardrails, and supporting engineering teams in building and maintaining modern web, mobile, API, and cloud-based applications. - Work from home; occasional planned travel to an assigned Southfield, Michigan office location may be required. - Perform security reviews of applications and services at each stage of the SDLC, including design, code, building pipelines, dependencies, infrastructure-as-code, and third-party components. - Identify and mitigate risks such as injection, authentication/authorization flaws, insecure handling of NPI, PII, and payment data, open-source dependency vulnerabilities, insecure cloud configurations, secrets management, and exposed APIs. - Support threat modeling and risk assessments for new and existing applications, assisting teams in implementing practical mitigations. - Assess and help mitigate security risks introduced by AI-assisted and agentic development tools, including review of AI-generated code, exposure of source code or secrets to external models, and proper use of internal LLM gateways. ## Requirements - Customer Empathy: Ability to understand the perspectives, pain points, and experiences of customers. - Engineering Excellence: Bring great craftsmanship and thought leadership to deliver an outstanding product that delights customers and solves for the business. - One Team: Collaborative approach across the organization, working together seamlessly as a single, cohesive team. ## Nice to Have - Experience with AI-assisted development tools and agentic coding workflows. - Familiarity with regulatory and industry frameworks such as PCI DSS, GLBA, NIST SSDF, SOX. - Experience with application security tooling (SAST, DAST, SCA, IAST, secrets scanning, ASPM) and vendors. ## Benefits - Great Place to Work culture. - Flexible work environment. - Professional development and continuous improvement opportunities. - Casual work environment. - Work-life balance.
Sourced via efinancialcareers · Listed on CareerPlan, which tracks 70,000+ jobs from 20+ sources.
Apply on eFinancialCareers ↗