Application Security Engineer II
$85.7k - $125.69kCredit Acceptance
Application Security Engineer
Credit Acceptance is proud to be an award-winning company recognized both locally and nationally across multiple workplace categories. Our world-class culture is shaped by dedicated team members who are driven to succeed as professionals individually and together as a team. Backed by a strong product, exceptional people, and a stable financial foundation, we've grown into a leading provider of used and new car financing across the country.
Our Engineering and Analytics Team Members utilize the latest technology to develop, monitor, and maintain complex practices that help optimize our success. Our Team Members value being challenged, are encouraged to express their ideas, and have the flexibility to enjoy work life balance. We build intrinsic value by partnering with all functions of our business to support their success and make strategic business decisions. We focus on professional development and continuous improvement while enjoying a casual work environment and Great Place to Work culture!
The Application Security Engineer is responsible for securing the software and applications that Credit Acceptance builds, buys, and operates. This role partners closely with engineering, product, architecture, and business teams to ensure that applications handling sensitive consumer, dealer, and loan data are designed, developed, and deployed in a secure manner, meeting both internal security standards and the regulatory expectations of a financial services environment. This position focuses on embedding security into the software development lifecycle by providing hands-on technical guidance, performing threat modeling and application security reviews, defining secure design patterns and guardrails, and supporting engineering teams as they build and maintain modern web, mobile, API, and cloud-based applications.
Outcomes and Activities:
- This position will work from home; occasional planned travel to an assigned Southfield, Michigan office location may be required. However, this position is permitted to work at a Southfield, Michigan office location if requested by the team member.
- Partner with engineering and architecture teams to design and review application architectures (web, mobile, API, and microservices) for security, privacy, and regulatory compliance.
- Perform security reviews of applications and services at each stage of the SDLC, including design, code, building pipelines, dependencies, infrastructure-as-code, and third-party components.
- Identify and mitigate risks such as:
- Injection, authentication/authorization, injection and session management flaws (OWASP Top 10, ASVS)
- Insecure handling of NPI, PII, and payment data
- Management of open-source dependency vulnerabilities and software supply chain risks
- Insecure cloud configurations, secrets management, and exposed APIs
- Support threat modeling and risk assessments for new and existing applications, assisting teams in implementing practical mitigations.
- Assess and help mitigate security risks introduced by AI-assisted and agentic development tools (e.g., GitHub Copilot, Claude Code, LiteLLM), including review of AI-generated code, exposure of source code or secrets to external models, and proper use of internal LLM gateways.
Governance, Standards, and Policy
- Contribute to and operationalize application security standards, secure coding guidelines, and secure design patterns used across the company.
- Evaluate application security tooling (SAST, DAST, SCA, IAST, secrets scanning, ASPM) and vendors to ensure alignment with security, privacy, and compliance requirements.
- Support compliance with regulatory and industry frameworks (e.g., PCI DSS, GLBA, NIST SSDF, SOX) in collaboration with legal, compliance, audit, and risk partners.
- Contribute to standards and guardrails for secure use of AI-assisted development tools and agentic coding workflows.
Collaboration & Advisory
- Act as a trusted security advisor to Engineering, Product, and DevOps teams building, maintaining and operating applications at Credit Acceptance.
- Participate in design reviews, sprint planning, and architecture working sessions focused on secure development and deployment.
- Provide guidance on the secure use of frameworks, libraries, APIs, authentication systems, and cloud services that interact with company systems and data.
- Advise engineering teams on safe adoption of AI coding assistants and agentic development tools, including approved usage patterns, data handling expectations, and review of AI-generated changes.
Continuous Improvement
- Stay current on application security threats, vulnerabilities, and best practices, including emerging risks across web, mobile, API, and cloud-native applications.
- Recommend improvements to tooling, processes, and controls to strengthen the company's application security posture and shift security left in the SDLC.
- Contribute to internal documentation, secure coding training, and security enablement for developers and engineering teams.
Competencies:
- Customer Empathy: Customer Empathy is the ability to understand the perspectives, pain points, and experiences of customers. It involves actively putting oneself in the customer's shoes, comprehending their needs and challenges, and using that understanding to provide a better, more customer-centric experience.
- Engineering Excellence: Engineering Excellence is about bringing great craftsmanship and thought leadership to deliver an outstanding product that delights customers and solves for the business. This involves the pursuit and achievement of high standards, best practices, innovation, and superior solutions.
- One Team: A One Team mindset refers to a collaborative approach across the organization, where individuals work together seamlessly, without boundaries, as a single, cohesive team. Shared goals, open communication and mutual support create a sense of collective purpose. This enables teams to navigate challenges and pursue shared objectives more effectively.
- Owner's Mindset: Owner's Mindset involves adopting a set of behaviors that reflect a sense of responsibility, accountability, strategic thinking, and a proactive approach to managing your domain. As an owner, you understand the business and your domain(s) deeply and solve for the right outcome for the domain(s) and the business.
Required:
- Bachelor's Degree or equivalent experience
- 3+ years of experience in application security, product security, or secure software development.
- 2+ years of hands-on experience performing application security reviews, penetration testing, threat modeling, or secure code review.
Preferred:
- Experience securing modern web, mobile, and API-based applications in a regulated industry (e.g., financial services, healthcare).
- Familiarity with the OWASP Top 10, OWASP ASVS, and OWASP SAMM, and with software supply chain frameworks such as SLSA.
- Experience with cloud platforms (e.g., AWS, Azure, GCP) and containerized environments.
- Knowledge of regulatory and compliance considerations relevant to financial services (e.g., PCI DSS, GLBA, SOX).
- Experience embedding security into software development workflows (DevSecOps) and CI/CD pipelines.
- Hands-on experience with application security tooling such as SAST, DAST, SCA, IAST, secrets scanning, or ASPM platforms.
- Relevant certifications (e.g., GWAPT, GWEB, OSWE, CSSLP, CISSP) a plus.
- Familiarity with security considerations for AI-assisted development environments (e.g., GitHub Copilot, Claude Code) and LLM gateway/proxy tooling (e.g., LiteLLM).
Knowledge and Skills:
- Strong understanding of modern software development practices, frameworks, and architectures (web, mobile, API, microservices, serverless).
- Working knowledge of common application vulnerabilities and exploitation techniques, and the controls that mitigate them.
- Understanding of authentication, authorization, identity, cryptography, and secure data handling patterns.
- Familiarity with threat modeling, security testing, and risk assessment techniques.
- Ability to read and reason about code in one or more common programming languages.
- Working knowledge of AI-assisted and agentic software development tools (e.g., GitHub Copilot, Claude Code, LiteLLM) and the security risks they introduce in the SDLC.
- Ability to communicate security risks and recommendations clearly to both technical and non-technical audiences.
Target Compensation: A competitive base salary range from $85,695 – $125,685. This position is eligible for an annual variable cash bonus, between 7.5 - 15%. Bonus amounts are based on individual performance. Final compensation within the range is influenced by many factors including role-specific skills
$89.3k - $130k
...Description American Specialty Health Incorporated (ASH) is seeking an Application Security Engineer II to join our Information Security department. The primary purpose of this position is to protect and defend the information security posture and information...SuggestedFull timeWork experience placementLocal areaRemote workWork from home$120k - $170k
...Cyber Defense, Application Security Engineer II Location – Irvine, CA Company Overview Hyundai AutoEver America (HAEA), the dynamic IT powerhouse behind Hyundai Motor Corporation, a Fortune 500 global leader in the automotive industry. As a key affiliate, we...SuggestedLocal area$89.3k - $130k
...American Specialty Health Incorporated is looking for an Application Security Engineer II to enhance their Information Security team. The role focuses on protecting information assets from cybersecurity threats, ensuring compliance, and coordinating security measures...SuggestedRemote workWork from homeHome office$128k - $181.25k
...capture moments that reflect who they uniquely are. This is an exciting time for Shutterfly and we are looking for a Senior Application Security Engineer to join our team! In this position you will be an integral part of a developing and expanding Application Security...SuggestedRemote work$115k - $190k
...Requisition ID : 65592 Title :Sr II - Embedded Product Security Engineer Salary Range: Salary Minimum: $115,000 Salary Maximum: $190,000 Seeking... ...to a broader design perspective and considers how an application interacts with the underlying infrastructure or...SuggestedRemote workFlexible hours$157k - $216k
...investing in the next generation of our Application Security capability, a continuous, AI-augmented,... ...defense program built for a SaaS engineering organization where AI agents and human... ...experience or familiarity with SOC 2 Type II, ISO 27001:2022, ISO 42001, SOX, GDPR....Contract workLocal areaRemote work$200k - $245k
...have focused on enabling our clients to securely navigate the digital asset space. With... ...-solving. We are seeking a Senior Application Security Engineer to lead the technical execution of our... ...technical controls to meet SOC 2 Type II and GDPR compliance standards. ~ Deep...Full timeWork at officeWorldwide$165k - $190k
...Senior Application Security Engineer Los Angeles, California, United States Tatari is on a mission to revolutionize TV advertising. Founded in... ...late-stage AdTech company with a recently attained SOC2 Type II attestation, and a clear mandate to mature our security and...Work at office2 days per week- ...Application Security Engineer UniUni is a late-stage last-mile logistics company moving millions of parcels across the United States and Canada... .... We hold an active ISO 27001 certification and SOC 2 Type II attestation, and security is central to how we operate and...Work at officeRemote work
$166k - $200k
...Senior Technical Security Application Engineer, Secured Spaces Costa Mesa, California, United States Anduril Industries is a defense technology... ...ICD-705 IDS and ACS installations, including UL 634 Level II High Security Switches (HSS), UL 639 motion detection sensors...Full timeContract workWork experience placementImmediate start$95k - $105k
...Application Engineer II - Michigan Festo inspires people and organizations around the world with innovative solutions for industrial automation... ...to help employees and their dependents stay healthy, feel secure and maintain a work/life balance. This is just one way we...Temporary workRemote workWorldwideFlexible hours$78k - $90k
...Process Applications Engineer I-II (Semiconductor) Phoenix, AZ Overview Salary Range $78,000.00 - $90,000.00 Salary/year Level Experienced Position Type Full Time Job Shift Day Education Level 4 Year Degree Travel Percentage Up to 25% Description Position...Full timeWork experience placementLocal areaShift work$205k - $275k
...that reality. The opportunity We're looking for a seasoned Application Security Engineer who brings the credibility of a software engineering... ...controls. Exposure to compliance frameworks such as SOC 2 Type II, HITRUST, or FedRAMP. Experience building or maturing a security...Work at officeHome officeFlexible hours2 days per week$150k - $220k
...considered by exception.) Meet our engineers on the Vehicle OS team!... ...vehicle software and AI applications. Learn more about what the team... ...looking for a multifaceted Product Security Engineer who can play a... ...diagnostics protocols (e.g., OBD-II, UDS) and Over-The-Air (OTA)...Full timeFor contractorsFor subcontractorCasual workWork at officeRemote workFlexible hoursDay shift$100k - $155k
Overview As an Application Security Engineer , you will provide technical expertise and solutions to remediate persistent and challenging portfolio-... ...Jenkins, Ansible, Java, C#/.NET, Apache Tomcat, Apache Server, IIS, F5, Oracle, MSSQLSEVER, PostGres Working knowledge and...$71.2k - $92.6k
...Application Engineer II Reporting to the Application Engineering Manager, this position plays a critical role within our organization. The Application Engineer II is responsible for the interpretation of customer specifications and. The Application Engineer II analyzes...Temporary workFor contractorsLocal areaWorldwide- ...Application Engineer II, Division Production Software Hexagon’s Manufacturing Intelligence is seeking an Application Engineer II for the Production Software Division. This is a remote position based in the United States. Responsibilities Provide Technical Support services...Work experience placementRemote workFlexible hours
$77.24k - $117.55k
...Application Engineer Ready to join a global leader in air movement and ventilation? At Greenheck... ...experience in engineering required for level II. COMPENSATION & BENEFITS... ...Health & Family Support Financial Security Learning & Development Rewards...Work experience placementWork at officeWorldwide$107.63k
...Posting Title Application Engineer II Overview Application Engineer II in Washington, D.C. Application development, integration, maintenance... .... Participate in new functionality development to ensure secure, elegant and low maintenance date designs are adopted....$168k - $230k
...with the ultimate goal of enabling human life on Mars. SR. APPLICATION SECURITY ENGINEER (STARLINK) At SpaceX we’re leveraging our experience in building... ..., applicant must be a (i) U.S. citizen or national, (ii) U.S. lawful, permanent resident (aka green card holder), (...Permanent employmentTemporary workWork at officeWorldwideMonday to FridayFlexible hoursWeekend work- ...AVL Test Systems Inc offers a job in the United States (US) as Application Engineer II AVL Test Systems Inc. is looking for an Application Engineer II to add to the Plymouth, MI team. The position will focus on AVL’s electrification market including but not limited...Full timeContract workWork experience placementWork visa
- ...A technology services provider is seeking an E-Discovery Application Administrator II to support federal agencies with IT legal services. The role requires extensive programming experience, exceptional communication skills, and familiarity with IT environments. The ideal...
$86.4k - $129.6k
...Application Engineer II For this U.S. based position, the expected compensation range is $86,400 - $129,600 per year , which includes base pay... ...necessary clearance including but not limited to Homeland Security clearance, background and credit checks. Travel up to 15% to...Permanent employmentTemporary workFlexible hours$78.2k - $101.2k
...Position Summary As a Cybersecurity Engineer II you will be a cybersecurity specialist... ...potential vulnerabilities, executing secure software development and maintenance, collaborating... ...on cybersecurity within the software application development life cycle for commercial...Temporary workFor contractorsWork at officeLocal area- ...United States Government Space Technology Export Regulations, the applicant must be a U.S. citizen, lawful permanent resident of the U.S.,... ...team. We are looking to add several Senior Applications Engineer II to our rapidly growing customer-facing team. In this position...Permanent employmentFull timeContract workWork experience placementLocal area
- ...Vulnerability Management Program that understands Application Security with 5-7 years of security experience.... ...configuration knowledge: Microsoft IIS, Apache Server, Apache Tomcat... ...using automated toolsets Software Engineering career experience Following Certifications...
$77.64k - $126.17k
...Applications Engineer II-Ent To provide support of the Enterprise Resource Planning (ERP) systems. To enhance and maintain the system by analyzing... ...will commit to fostering an environment of heightened security following Information Technology Security Policies and...Work experience placementShift workDay shift- ...Applications Engineer II Responsibilities: Technical responsibility for customer's global account Expertise to coordinate and lead the company's technical support to meet the customers complex local and global catalyst needs Work closely with the customer...Local area
- ...Job Description Summary The Applications Engineer II, ECSA & Application Integration/Interfaces, reports to the Manager of the ECSA & Application Integration/Interfaces team in support of MUSC’s academic, research and healthcare missions. Under direct supervision, the...Work experience placementRemote workRotating shift
$78k - $103k
...restaurants, warehouses and distribution centers, in addition to other applications such as data centers, pharmaceutical and industrial process... ..., GA - This position 100% onsite. The Application Engineer II provides technical support for commercial refrigeration...Temporary workWork at officeWorldwide
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Application Security Engineer II. Be the first to apply!
- application support engineer United States
- senior application security engineer United States
- application engineering manager United States
- project application engineer United States
- network applications engineer United States
- technical application engineer United States
- cnc applications engineer United States
- hydraulic application engineer United States
- application system engineer United States
- application engineer United States

