Application Security Engineer II
Core
Securing software and applications handling sensitive consumer, dealer, and loan data by embedding security into the software development lifecycle.
Role type
Application Security Engineer
Builds
Modern web, mobile, API, and cloud-based applications for a used and new car financing company
Domain
Financial services / Application Security
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Application security reviews, threat modeling, secure code review, OWASP Top 10/ASVS knowledge, software supply chain risk management, cloud security (AWS/Azure/GCP), DevSecOps integration, SAST/DAST/SCA/IAST tooling, AI-assisted development security
Preferred skills
Regulated industry experience (financial services/healthcare), SLSA framework familiarity, containerized environments, regulatory compliance (PCI DSS/GLBA/SOX), CI/CD pipeline security, security certifications (GWAPT/GWEB/OSWE/CSSLP/CISSP), LLM gateway/proxy tooling
Technologies
AWS, Azure, GCP, GitHub Copilot, Claude Code, LiteLLM, SAST, DAST, SCA, IAST, ASPM
Responsibilities
Partner with engineering/architecture to design secure application architectures; Perform security reviews across SDLC stages (design, code, pipelines, dependencies); Identify and mitigate risks (OWASP Top 10, NPI/PII handling, supply chain, cloud configs); Support threat modeling and risk assessments; Evaluate application security tooling and vendors; Advise teams on secure use of AI coding assistants and agentic workflows.
Seniority
Mid-level, hands-on IC