Application Security Engineer II
Core
Securing software and applications handling sensitive consumer, dealer, and loan data by embedding security into the software development lifecycle.
Role type
Application Security Engineer
Builds
Modern web, mobile, API, and cloud-based applications for a used and new car financing company
Domain
Financial services / Application Security
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Threat modeling, secure design patterns, SDLC security integration, OWASP Top 10 mitigation, NPI/PII/payment data protection, open-source dependency management, cloud security configuration, secrets management, API security, AI-assisted development security review, SAST/DAST/SCA/IAST tool evaluation, regulatory compliance (PCI DSS, GLBA, NIST SSDF, SOX)
Preferred skills
Experience with agentic development tools, AI coding assistant governance, secure coding training delivery
Technologies
GitHub Copilot, Claude Code, LiteLLM, SAST, DAST, SCA, IAST, ASPM, microservices, cloud-native frameworks
Responsibilities
Partner with engineering and architecture teams to design and review application architectures for security and compliance; Perform security reviews of applications and services at each stage of the SDLC; Identify and mitigate risks including injection flaws, insecure data handling, and supply chain vulnerabilities; Support threat modeling and risk assessments for new and existing applications; Evaluate application security tooling and vendors; Contribute to and operationalize application security standards and secure coding guidelines; Act as a trusted security advisor to Engineering, Product, and DevOps teams; Stay current on application security threats and best practices.
Seniority
Mid-level IC