Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Application Security Engineer II

$85.7k - $125.69k

Nerdleveltech

The Application Security Engineer is responsible for securing the software and applications that Credit Acceptance builds, buys, and operates. This role partners closely with engineering, product, architecture, and business teams to ensure that applications handling sensitive consumer, dealer, and loan data are designed, developed, and deployed in a secure manner, meeting both internal security standards and the regulatory expectations of a financial services environment. This position focuses on embedding security into the software development lifecycle by providing hands‑on technical guidance, performing threat modeling and application security reviews, defining secure design patterns and guardrails, and supporting engineering teams as they build and maintain modern web, mobile, API, and cloud‑based applications. Outcomes and Activities: This position will work from home; occasional planned travel to an assigned Southfield, Michigan office location may be required. However, this position is permitted to work at a Southfield, Michigan office location if requested by the team member. Partner with engineering and architecture teams to design and review application architectures (web, mobile, API, and microservices) for security, privacy, and regulatory compliance. Perform security reviews of applications and services at each stage of the SDLC, including design, code, building pipelines, dependencies, infrastructure‑as‑code, and third‑party components. Identify and mitigate risks such as: Injection, authentication/authorization, injection and session management flaws (OWASP Top 10, ASVS) Insecure handling of NPI, PII, and payment data Management of open‑source dependency vulnerabilities and software supply chain risks Insecure cloud configurations, secrets management, and exposed APIs Support threat modeling and risk assessments for new and existing applications, assisting teams in implementing practical mitigations. Assess and help mitigate security risks introduced by AI‑assisted and agentic development tools (e.g., GitHub Copilot, Claude Code, LiteLLM), including review of AI‑generated code, exposure of source code or secrets to external models, and proper use of internal LLM gateways. Governance, Standards, and Policy Contribute to and operationalize application security standards, secure coding guidelines, and secure design patterns used across the company. Evaluate application security tooling (SAST, DAST, SCA, IAST, secrets scanning, ASPM) and vendors to ensure alignment with security, privacy, and compliance requirements. Support compliance with regulatory and industry frameworks (e.g., PCI DSS, GLBA, NIST SSDF, SOX) in collaboration with legal, compliance, audit, and risk partners. Contribute to standards and guardrails for secure use of AI‑assisted development tools and agentic coding workflows. Collaboration & Advisory Act as a trusted security advisor to Engineering, Product, and DevOps teams building, maintaining and operating applications at Credit Acceptance. Participate in design reviews, sprint planning, and architecture working sessions focused on secure development and deployment. Provide guidance on the secure use of frameworks, libraries, APIs, authentication systems, and cloud services that interact with company systems and data. Advise engineering teams on safe adoption of AI coding assistants and agentic development tools, including approved usage patterns, data handling expectations, and review of AI‑generated changes. Continuous Improvement Stay current on application security threats, vulnerabilities, and best practices, including emerging risks across web, mobile, API, and cloud‑native applications. Recommend improvements to tooling, processes, and controls to strengthen the company's application security posture and shift security left in the SDLC. Contribute to internal documentation, secure coding training, and security enablement for developers and engineering teams. Competencies Customer Empathy: Customer Empathy is the ability to understand the perspectives, pain points, and experiences of customers. It involves actively putting oneself in the customer's shoes, comprehending their needs and challenges, and using that understanding to provide a better, more customer‑centric experience. Engineering Excellence: Engineering Excellence is about bringing great craftsmanship and thought leadership to deliver an outstanding product that delights customers and solves for the business. This involves the pursuit and achievement of high standards, best practices, innovation, and superior solutions. One Team: A One Team mindset refers to a collaborative approach across the organization, where individuals work together seamlessly, without boundaries, as a single, cohesive team. Shared goals, open communication and mutual support create a sense of collective purpose. This enables teams to navigate challenges and pursue shared objectives more effectively. Owner's Mindset: Owner's Mindset involves adopting a set of behaviors that reflect a sense of responsibility, accountability, strategic thinking, and a proactive approach to managing your domain. As an owner, you understand the business and your domain(s) deeply and solve for the right outcome for the domain(s) and the business. Required Bachelor’s Degree or equivalent experience 3+ years of experience in application security, product security, or secure software development. 2+ years of hands‑on experience performing application security reviews, penetration testing, threat modeling, or secure code review. Preferred Experience securing modern web, mobile, and API‑based applications in a regulated industry (e.g., financial services, healthcare). Familiarity with the OWASP Top 10, OWASP ASVS, and OWASP SAMM, and with software supply chain frameworks such as SLSA. Experience with cloud platforms (e.g., AWS, Azure, GCP) and containerized environments. Knowledge of regulatory and compliance considerations relevant to financial services (e.g., PCI DSS, GLBA, SOX). Experience embedding security into software development workflows (DevSecOps) and CI/CD pipelines. Hands‑on experience with application security tooling such as SAST, DAST, SCA, IAST, secrets scanning, or ASPM platforms. Relevant certifications (e.g., GWAPT, GWEB, OSWE, CSSLP, CISSP) a plus. Familiarity with security considerations for AI‑assisted development environments (e.g., GitHub Copilot, Claude Code) and LLM gateway/proxy tooling (e.g., LiteLLM). Knowledge and Skills Strong understanding of modern software development practices, frameworks, and architectures (web, mobile, API, microservices, serverless). Working knowledge of common application vulnerabilities and exploitation techniques, and the controls that mitigate them. Understanding of authentication, authorization, identity, cryptography, and secure data handling patterns. Familiarity with threat modeling, security testing, and risk assessment techniques. Ability to read and reason about code in one or more common programming languages. Working knowledge of AI‑assisted and agentic software development tools (e.g., GitHub Copilot, Claude Code, LiteLLM) and the security risks they introduce in the SDLC. Ability to communicate security risks and recommendations clearly to both technical and non‑technical audiences. Target Compensation: A competitive base salary range from $85,695 – $125,685. This position is eligible for an annual variable cash bonus, between 7.5 - 15%. Bonus amounts are based on individual performance. Final compensation within the range is influenced by many factors including role‑specific skills, depth and experience level, industry background, relevant education and certifications. Candidates who reside in the following major metropolitan areas may be eligible for a premium on top of the posted range based on their specific zone: San Francisco, Seattle, Boston, New York City, Los Angeles and San Diego. Benefits Excellent benefits package that includes 401(K) match, adoption assistance, parental leave, tuition reimbursement, comprehensive medical/dental/vision and many nonstandard benefits that make us a Great Place to Work Company Values Positive by maintaining resiliency and focusing on solutions Respectful by collaborating and actively listening Insightful by cultivating innovation, accumulating business and role specific knowledge, demonstrating self‑awareness and making quality decisions Direct by effectively communicating and conveying courage Earnest by taking accountability, applying feedback and effectively planning and priority setting Expectations Remain compliant with our policies processes and legal guidelines All other duties as assigned Attendance as required by department Credit Acceptance is dedicated to providing a safe and inclusive working environment for all. As part of our Culture of Compliance, we are proud to be an Equal Opportunity Employer and value our culturally diverse workforce. All qualified applicants will receive consideration for employment regardless of the person’s age, race, color, religion, sex, gender, sexual orientation, gender identity, national origin, veteran or disability status, criminal history, or any other legally protected characteristic. California Residents: Please click here for the California Consumer Privacy Act (CCPA) notice regarding the personal information Credit Acceptance may collect from you. #J-18808-Ljbffr Nerdleveltech

Vacancy posted 3 days ago
Similar jobs that could be interesting for youBased on the Application Security Engineer II in Southfield, MI vacancy
  • $85.7k - $125.69k

    Credit Acceptance Corporation is seeking an Application Security Engineer responsible for securing software and applications within a dynamic team environment. This role involves collaborating with product and engineering teams to ensure the security of applications handling... 
    Suggested
    Remote job

    Credit Acceptance Corporation

    Southfield, MI
    4 days ago
  • $85.7k - $125.69k

     ...provider of used and new car financing across the country.Our Engineering and Analytics Team Members utilize the latest technology to...  ...work environment and Great Place to Work culture!The Application Security Engineer is responsible for securing the software and applications... 
    Suggested
    Casual work
    Work at office
    Work from home
    Shift work

    Credit Acceptance Corporation

    Southfield, MI
    4 days ago
  •  ...Application Engineer II, Division Portable Metrology Summary Applications Engineer - PRESTO (P3) Location: Austin, TX Hybrid Position Hexagon Manufacturing Intelligence business area Portable Metrology division About Hexagon Manufacturing Intelligence... 
    Suggested
    Remote work
    Flexible hours

    Hexagon AB

    Novi, MI
    2 days ago
  • Magna International Inc. is seeking an Application Engineer to join their team in Southfield, Michigan. This role involves supporting engineering projects and managing customer relationships while addressing tasks such as defect management and vehicle testing. Candidates... 
    Suggested

    Magna International Inc.

    Southfield, MI
    2 days ago
  • Magna Electronics, located in Southfield, Michigan, is seeking an Application Engineer for their automotive technologies team. The role involves supporting project leads, managing defects, and facilitating testing on customer vehicles. Candidates should have strong engineering... 
    Suggested

    Magna-International-6df39721

    Southfield, MI
    3 days ago
  •  ...Application Security Engineer Position Description Position Description We are seeking a hands-on Application Security Engineer to embed security through our SDLC, cloud platforms, and machine learning pipelines. You will integrate and automate security... 

    System Soft Technologies

    Detroit, MI
    2 days ago
  •  ...Lead Application Security Engineer The Lead Application Security Engineer provides enterprise-level technical leadership and strategic direction for application security across the organization. This role is a senior individual contributor responsible for defining,... 

    Little Caesars

    Detroit, MI
    2 days ago
  • Tyler Technologies, Inc. is seeking a Software Support Representative to provide basic-level software support to clients. This role focuses on the use and functionality of Tyler’s products, requiring good communication skills and problem-solving abilities. The representative...

    Tyler Technologies, Inc.

    Troy, MI
    3 days ago
  •  ...customer satisfaction and retention. Software Engineer - Full Stack Developer Develop and maintain scalable web applications using .NET technologies and modern front-end...  ...to improve performance, scalability, security, and reliability. Build resilient infrastructure... 
    Contract work
    Remote work

    Tyler Technologies, Inc.

    Troy, MI
    4 days ago
  •  ...leveraging AI, data, and knowledge systems to improve how client‑facing teams operate and how clients access information. Senior Cloud Engineer Overland Park, Kansas | Yarmouth, Maine | Troy, Michigan | Herndon, Virginia Tyler Technologies is currently looking to hire a... 
    Currently hiring
    Remote work

    Tyler Technologies, Inc.

    Troy, MI
    4 days ago
  • Ernst & Young Oman is seeking an Application Security Engineer to optimize security tools and manage application development platforms. You will work closely with a team of cybersecurity professionals to enhance security measures across the software development lifecycle... 
    Flexible hours

    Ernst & Young Oman

    Detroit, MI
    3 days ago
  •  ...The Proposal Application Engineer will develop manufacturing processes and solutions for new automation systems business. You will collaborate with a team of relevant specialists from Sales, Project Management, Engineering, Commissioning & Site Management and Estimating... 

    Comau

    Southfield, MI
    1 day ago
  •  ...What You’ll Do Technical & Engineering Support Analyze customer Requests for Quotes (RFQs) and define technical requirements for...  ...for internal meetings and project turnover. Provide prompt applications-engineering information to Project Managers for smooth... 
    Permanent employment
    Contract work
    Work at office
    Local area

    Dürr Clean Technology Systems

    Southfield, MI
    2 days ago
  •  ...Overview The Applications Engineer is responsible for evaluating requests for proposals, analyzing customer's needs, and developing detailed proposals and project cost estimates. The Applications Engineer supports the job launch process for all proposals resulting... 
    Contract work

    Jatca

    Southfield, MI
    4 days ago
  •  ...Are you ready for a better career? A better future? Job Description As a member of the Connection Systems team, the Application Engineer is responsible to lead customer interaction with onsite customer support. They will support new business developments, product... 

    Lear Corporation

    Southfield, MI
    2 days ago
  •  ...Senior Application Engineer- Conveyance Solutions Technical & Engineering Support Analyze customer Requests for Quotes (RFQs) and define technical requirements for conveyance systems in automotive assembly environments. Develop complete layout and conveyor system... 
    Work at office

    Dürr

    Southfield, MI
    16 hours ago
  •  ...improvement and standardization of designs. Candidate Qualifications: Bachelor of Science in Engineering is preferred but not required Experience in Engineering, Application Engineering a plus Demonstrated knowledge of process equipment design Ability to... 
    Permanent employment
    Contract work
    For contractors
    For subcontractor
    Local area
    Worldwide
    Weekend work

    Dürr

    Southfield, MI
    14 days ago
  • $85.4k - $192.9k

     ...Job Description Protected DC-DC Software Application Engineer We made history and now we work to transform the future - for our customers...  .... Knowledge of diagnostic protocols (e.g., UDS, OBD-II). Familiarity with requirements management tools (e.g., DOORS... 
    Immediate start
    Flexible hours

    Ford Motor Company

    Dearborn, MI
    2 days ago
  • $77.5k - $140.9k

     ...diverse teams and take your career wherever you want it to go. Join EY and help to build a better working world. As an Application Security Engineer, you will be responsible for implementing and managing application development platforms and optimizing security tools to... 
    Summer holiday
    Flexible hours

    Ernst & Young Oman

    Detroit, MI
    3 days ago
  • United Cerebral Palsy of Georgia is looking for a Senior E-Discovery Application Administrator II to provide full-time IT legal support services to a large federal agency. The ideal candidate will develop and maintain complex programs for litigation environment applications... 
    Full time

    United Cerebral Palsy of Georgia

    Detroit, MI
    16 hours ago
  •  ...Senior Application Engineer – Automotive Paint Systems Analyze customer technical specifications and translate requirements into equipment and process solutions. Design and estimate automotive paint shop process equipment, including: Pretreatment (PT/ED) Paint booths... 
    For subcontractor
    Work at office

    Dürr

    Southfield, MI
    16 hours ago
  •  ...offices in Germany and Mexico Support layouts with layout engineer Understand Visio schematics for paint process equipment...  ...also offers advanced automated painting, sealing, and gluing application technologies, as well as high-viscosity material handling solutions... 
    Permanent employment
    Contract work
    For contractors
    For subcontractor
    Work at office
    Local area
    Weekend work

    Dürr Clean Technology Systems

    Southfield, MI
    2 days ago
  •  ...specifications Coordinate major subcontractors including conveyors, paint application, and paint mix Coordinate intercompany activities with offices in Germany and Mexico Develop layouts with layout engineer Develop Visio schematics for paint process equipment... 
    For contractors
    For subcontractor
    Work at office
    Weekend work

    Dürr AG

    Southfield, MI
    1 day ago
  •  ...Description Job Description At Roush, we fuse technology and engineering to provide product development solutions to customers in a...  ...off-road equipment.  A Technical Specialist in Design and Application Engineering focuses on the integration of power systems and... 
    Full time
    Work experience placement

    ROUSH

    Livonia, MI
    8 days ago
  •  ...EOL) business segments. The role works closely with internal engineering, sales, and project teams to develop technically sound and commercially...  ...packages for internal review and customer submission Applications & Process Engineering Support Apply knowledge of assembly... 
    Work at office

    Dürr AG

    Southfield, MI
    16 hours ago
  •  ...the advantage of having both in-person time with colleagues and flexible at-home life optimizations. Learn More: As an Application Engineer (AE), you'll play a key role in shaping how the automotive industry develops and deploys largescale vehicle simulations. By... 
    Work experience placement
    Work at office
    Flexible hours

    The MathWorks Inc

    Novi, MI
    3 days ago
  • $124.13k - $151.71k

     ...Job Description: Senior Application Engineer Collaborate with Innovative 3Mers Around the World Choosing where to grow your career...  ...this position include that corporate policies, procedures and security standards are complied with while performing assigned duties... 
    Full time
    H1b
    Local area
    Relocation package
    Flexible hours

    3M

    Livonia, MI
    7 days ago
  •  ...society. Job Summary Nidec is seeking a results-oriented Applications Engineer to serve as the primary technical interface between our...  ...work with senior management to implement decisive actions that secure Nidec's strategic objectives. Additional Job Details... 
    Shift work

    NIdec Motor

    Troy, MI
    5 days ago
  •  ...The Business Unit can look back on almost fifty years of production and development expertise. As part of a global Team, Application Engineering Team is responsible for designing our components in to leading solutions within the illumination, visualization, and... 
    Worldwide

    ams AG Gr

    Novi, MI
    16 hours ago
  •  ...Dual Role: Field Applications Engineer And Warranty Manager This position is considered a dual role 80% Field Applications engineer 20% Warranty manager. The Field Application Engineer provides technical expertise to help customers find the best after sales solutions... 

    Comau

    Southfield, MI
    4 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Application Security Engineer II. Be the first to apply!