Application Security Engineer II

Application Security Engineer II

Vollzeit 60000 - 80000 € / Jahr (geschätzt) Homeoffice möglich
Embedded Shishya

Auf einen Blick

  • Aufgaben: Sichere Software und Anwendungen entwickeln und optimieren.
  • Unternehmen: Ausgezeichnetes Unternehmen mit einer großartigen Teamkultur.
  • Vorteile: Attraktives Gehalt, Gesundheitsleistungen, Homeoffice und Weiterbildungsmöglichkeiten.
  • Weitere Informationen: Dynamisches Umfeld mit hervorragenden Karrieremöglichkeiten.
  • Warum dieser Job: Gestalte die Zukunft der Sicherheit in der Softwareentwicklung und mache einen echten Unterschied.
  • Qualifikationen: Erfahrung in Anwendungssicherheit und Teamarbeit erforderlich.

Das prognostizierte Gehalt liegt zwischen 60000 - 80000 € pro Jahr.

Credit Acceptance is proud to be an award-winning company recognized both locally and nationally across multiple workplace categories.

Our world-class culture is shaped by dedicated team members who are driven to succeed as professionals individually and together as a team.

Backed by a strong product, exceptional people, and a stable financial foundation, we’ve grown into a leading provider of used and new car financing across the country.

Our Engineering and Analytics Team Members utilize the latest technology to develop, monitor, and maintain complex practices that help optimize our success.

Our Team Members value being challenged, are encouraged to express their ideas, and have the flexibility to enjoy work life balance.

We build intrinsic value by partnering with all functions of our business to support their success and make strategic business decisions.

We focus on professional development and continuous improvement while enjoying a casual work environment and Great Place to Work culture!

The Application Security Engineer is responsible for securing the software and applications that Credit Acceptance builds, buys, and operates.

This role partners closely with engineering, product, architecture, and business teams to ensure that applications handling sensitive consumer, dealer, and loan data are designed, developed, and deployed in a secure manner, meeting both internal security standards and the regulatory expectations of a financial services environment.

This position focuses on embedding security into the software development lifecycle by providing hands‑on technical guidance, performing threat modeling and application security reviews, defining secure design patterns and guardrails, and supporting engineering teams as they build and maintain modern web, mobile, API, and cloud‑based applications.

  • Outcomes and Activities
  • This position will work from home; occasional planned travel to an assigned Southfield, Michigan office location may be required.

However, this position is permitted to work at a Southfield, Michigan office location if requested by the team member.

  • Partner with engineering and architecture teams to design and review application architectures (web, mobile, API, and microservices) for security, privacy, and regulatory compliance.
  • Perform security reviews of applications and services at each stage of the SDLC, including design, code, building pipelines, dependencies, infrastructure‑as‑code, and third‑party components.

• Identify and mitigate risks such as

  • Injection, authentication/authorization, injection and session management flaws (OWASP Top 10, ASVS)
  • Insecure handling of NPI, PII, and payment data
  • Management of open‑source dependency vulnerabilities and software supply chain risks
  • Insecure cloud configurations, secrets management, and exposed APIs
  • Support threat modeling and risk assessments for new and existing applications, assisting teams in implementing practical mitigations.
  • Assess and help mitigate security risks introduced by AI‑assisted and agentic development tools (e. g., Git Hub Copilot, Claude Code, Lite LLM), including review of AI‑generated code, exposure of source code or secrets to external models, and proper use of internal LLM gateways.
  • Governance, Standards, and Policy
  • Contribute to and operationalize application security standards, secure coding guidelines, and secure design patterns used across the company.
  • Evaluate application security tooling (SAST, DAST, SCA, IAST, secrets scanning, ASPM) and vendors to ensure alignment with security, privacy, and compliance requirements.
  • Support compliance with regulatory and industry frameworks (e. g., PCI DSS, GLBA, NIST SSDF, SOX) in collaboration with legal, compliance, audit, and risk partners.
  • Contribute to standards and guardrails for secure use of AI‑assisted development tools and agentic coding workflows.
  • Collaboration & Advisory
  • Act as a trusted security advisor to Engineering, Product, and Dev Ops teams building, maintaining and operating applications at Credit Acceptance.
  • Participate in design reviews, sprint planning, and architecture working sessions focused on secure development and deployment.
  • Provide guidance on the secure use of frameworks, libraries, APIs, authentication systems, and cloud services that interact with company systems and data.
  • Advise engineering teams on safe adoption of AI coding assistants and agentic development tools, including approved usage patterns, data handling expectations, and review of AI‑generated changes.
  • Continuous Improvement
  • Stay current on application security threats, vulnerabilities, and best practices, including emerging risks across web, mobile, API, and cloud‑native applications.
  • Recommend improvements to tooling, processes, and controls to strengthen the company’s application security posture and shift security left in the SDLC.
  • Contribute to internal documentation, secure coding training, and security enablement for developers and engineering teams.
  • Competencies
  • Customer

Empathy: Customer Empathy is the ability to understand the perspectives, pain points, and experiences of customers.

It involves actively putting oneself in the customer’s shoes, comprehending their needs and challenges, and using that understanding to provide a better, more customer‑centric experience.

  • Engineering

Excellence: Engineering Excellence is about bringing great craftsmanship and thought leadership to deliver an outstanding product that delights customers and solves for the business.

This involves the pursuit and achievement of high standards, best practices, innovation, and superior solutions.

  • One

Team: A One Team mindset refers to a collaborative approach across the organization, where individuals work together seamlessly, without boundaries, as a single, cohesive team.

Shared goals, open communication and mutual support create a sense of collective purpose.

This enables teams to navigate challenges and pursue shared objectives more effectively.

  • Owner’s

Mindset: Owner’s Mindset involves adopting a set of behaviors that reflect a sense of responsibility, accountability, strategic thinking, and a proactive approach to managing your domain.

As an owner, you understand the business and your domain(s) deeply and solve for the right outcome for the domain(s) and the business.

  • Required
  • Bachelor’s Degree or equivalent experience
  • 3+ years of experience in application security, product security, or secure software development.
  • 2+ years of hands‑on experience performing application security reviews, penetration testing, threat modeling, or secure code review.
  • Preferred
  • Experience securing modern web, mobile, and API‑based applications in a regulated industry (e. g., financial services, healthcare).
  • Familiarity with the OWASP Top 10, OWASP ASVS, and OWASP SAMM, and with software supply chain frameworks such as SLSA.
  • Experience with cloud platforms (e. g., AWS, Azure, GCP) and containerized environments.
  • Knowledge of regulatory and compliance considerations relevant to financial services (e. g., PCI DSS, GLBA, SOX).
  • Experience embedding security into software development workflows (Dev Sec Ops) and CI/CD pipelines.
  • Hands‑on experience with application security tooling such as SAST, DAST, SCA, IAST, secrets scanning, or ASPM platforms.
  • Relevant certifications (e. g., GWAPT, GWEB, OSWE, CSSLP, CISSP) a plus.
  • Familiarity with security considerations for AI‑assisted development environments (e. g., Git Hub Copilot, Claude Code) and LLM gateway/proxy tooling (e. g., Lite LLM).
  • Knowledge and Skills
  • Strong understanding of modern software development practices, frameworks, and architectures (web, mobile, API, microservices, serverless).
  • Working knowledge of common application vulnerabilities and exploitation techniques, and the controls that mitigate them.
  • Understanding of authentication, authorization, identity, cryptography, and secure data handling patterns.
  • Familiarity with threat modeling, security testing, and risk assessment techniques.
  • Ability to read and reason about code in one or more common programming languages.
  • Working knowledge of AI‑assisted and agentic software development tools (e. g., Git Hub Copilot, Claude Code, Lite LLM) and the security risks they introduce in the SDLC.
  • Ability to communicate security risks and recommendations clearly to both technical and non‑technical audiences.
  • Target Compensation

A competitive base salary range from $85,695 – $125,685.

This position is eligible for an annual variable cash bonus, between 7.5 - 15%.

Bonus amounts are based on individual performance.

Final compensation within the range is influenced by many factors including role‑specific skills, depth and experience level, industry background, relevant education and certifications.

Candidates who reside in the following major metropolitan areas may be eligible for a premium on top of the posted range based on their specific zone: San Francisco, Seattle, Boston, New York City, Los Angeles and San Diego.

Benefits

  • Excellent benefits package that includes 401(K) match, adoption assistance, parental leave, tuition reimbursement, comprehensive medical/ dental/vision and many nonstandard benefits that make us a Great Place to Work
  • Our Company Values
  • Positive by maintaining resiliency and focusing on solutions
  • Respectful by collaborating and actively listening
  • Insightful by cultivating innovation, accumulating business and role specific knowledge, demonstrating self‑awareness and making quality decisions
  • Direct by effectively communicating and conveying courage
  • Earnest by taking accountability, applying feedback and effectively planning and priority setting

Expectations

  • Remain compliant with our policies processes and legal guidelines
  • All other duties as assigned
  • Attendance as required by department

Credit Acceptance is dedicated to providing a safe and inclusive working environment for all.

As part of our Culture of Compliance, we are proud to be an Equal Opportunity Employer and value our culturally diverse workforce.

All qualified applicants will receive consideration for employment regardless of the person’s age, race, color, religion, sex, gender, sexual orientation, gender identity, national origin, veteran or disability status, criminal history, or any other legally protected characteristic.

California Residents: Please click here for the California Consumer Privacy Act (CCPA) notice regarding the personal information Credit Acceptance may collect from you.

#J-18808-Ljbffr

Application Security Engineer II Arbeitgeber: Embedded Shishya

Jitterbit ist ein hervorragender Arbeitgeber, der Ihnen die Möglichkeit bietet, in einem dynamischen und wachsenden Umfeld zu arbeiten, das sich auf die Integration von Plattformen als Dienstleistung (iPaaS) spezialisiert hat. Mit einem flexiblen, remote-freundlichen Arbeitsmodell und einer Unternehmenskultur, die auf Zusammenarbeit und persönlichem Wachstum basiert, fördern wir Ihre Karriere durch Mentorship und kontinuierliche Entwicklung. Hier haben Sie die Chance, bedeutende Partnerschaften zu entwickeln und die Zukunft der API-Nutzung in geschäftskritischen Prozessen mitzugestalten.

Embedded Shishya

Kontaktdaten:

Embedded Shishya Recruiting-Team

StudySmarter Expertenrat🤫

Wir sind der Meinung, dass du so Application Security Engineer II erhalten könntest

Werde sichtbar in der IT-Sicherheits-Community

In der IT-Sicherheit gibt’s eine Menge Fachkreise und Konferenzen, die super für Networking sind. Schau dir Events wie die "IT-Security Convention" oder regionale Meetups an, um Gleichgesinnte und potenzielle Arbeitgeber wie Embedded Shishya kennenzulernen!

Kollaboriere an Open-Source-Projekten

Zeig dein Können und engagiere dich in Open-Source-Projekten, die auf IT-Sicherheit abzielen. Das ist nicht nur eine tolle Möglichkeit, praktische Erfahrungen zu sammeln, sondern auch, um dein Portfolio zu erweitern und Sichtbarkeit in der Branche zu gewinnen.

Nutze spezielle Jobportale für IT-Sicherheit

Schau auf spezialisierten Jobportalen wie "heise jobs" oder "StepStone" nach offenen Stellen in der IT-Sicherheit. Hier findest du viele Angebote, die nicht immer auf den großen Plattformen gelistet sind. Vergiss nicht, dich direkt auf der Website von Embedded Shishya zu bewerben!

Halte deine Skills up-to-date

In der IT-Sicherheit bleibt nichts stehen, also bleib am Ball! Investiere Zeit in Weiterbildung und besuche Online-Kurse oder Webinare zu aktuellen Sicherheitsthemen. Das zeigt nicht nur dein Engagement, sondern stärkt auch dein Profil bei Embedded Shishya.

Wir glauben, dass du diese Fähigkeiten brauchst, um Application Security Engineer II mit Bravour zu bestehen

Anwendungssicherheit
Sichere Softwareentwicklung
Bedrohungsmodellierung
Sicherheitsüberprüfungen
Penetrationstests
Sichere Codierungsrichtlinien
Regulatorische Compliance

Einige Tipps für deine Bewerbung 🫡

Zeig deine technischen Skills!:Im Bereich IT-Sicherheit ist es wichtig, dass du deine technischen Fähigkeiten klar kommunizierst. Stelle sicher, dass dein Lebenslauf relevante Zertifikate (wie CEH oder CISSP) sowie praktische Erfahrungen bei Sicherheitsprojekten oder Penetrationstests zeigt. Dies wird uns helfen, einen besseren Eindruck von deinem Fachwissen zu bekommen.

Präsentiere dein Wissen über aktuelle Trends:Wir möchten sehen, dass du über die neuesten Entwicklungen im Bereich IT-Sicherheit informiert bist. In deinem Anschreiben kannst du beispielsweise auf ein aktuelles Sicherheitsproblem oder einen neuen Standard eingehen, den du für relevant hältst. Dadurch zeigst du uns, dass du dich aktiv mit dem Thema auseinandersetzt und für die Position brennst.

Mach deine Leidenschaft deutlich:Da es sich um eine Vollzeitposition handelt, ist es wichtig, dass du uns in deinem Anschreiben zeigst, warum du in der IT-Sicherheit arbeiten möchtest. Erzähl uns von deinen Erfahrungen, wie du zur Cyber-Security gekommen bist und was dich motiviert, in dieser Branche zu arbeiten. Deine Motivation spielt eine große Rolle bei der Auswahl!

Referenzen oder Projekte anfügen:Wenn du bereits an interessanten Projekten gearbeitet hast oder relevante Referenzen hast, die deine Fähigkeiten unterstreichen, füge diese in deine Bewerbung hinzu. Das gibt uns einen Einblick in deine praktische Erfahrung und zeigt, was du wirklich drauf hast. Ein Link zu einem GitHub-Profil oder Sicherheitsanalysen, die du durchgeführt hast, wäre hier super hilfreich!

Wie man sich auf ein Vorstellungsgespräch bei Embedded Shishya vorbereitet

Sicherheitsprotokolle dominiert!

Mach dich mit den neuesten Sicherheitsprotokollen und -standards vertraut. Bei Embedded Shishya könnte es sein, dass du in technisch anspruchsvollen Fragen zu Netzwerksicherheit und Schwachstellenmanagement gefordert wirst – zeig, dass du die Grundlagen und die aktuellen Trends im Bereich IT-Sicherheit beherrschst!

Praktische Erfahrung zählt!

Bereite dich darauf vor, über frühere Projekte oder Erfahrungen im Bereich IT-Sicherheit zu sprechen. Es ist wichtig, Beispiele zu haben, wie du Sicherheitslücken identifiziert und behoben hast oder welche Tools du verwendet hast, um Systeme abzusichern. Embedded Shishya sucht nach jemandem, der die Theorie auch anwenden kann!

Teamarbeit nicht vergessen!

IT-Sicherheit ist oft Teamarbeit. Sei bereit, Fragen zu beantworten, wie du in einem Team umgehst, um Sicherheitsprobleme zu lösen. Denk auch an Beispiel-Situationen, in denen du optimal mit anderen zusammengearbeitet hast – das könnte einen großen Unterschied machen!

Motivation und Lernbereitschaft zeigen!

Da es sich um eine Vollzeitstelle handelt, wird Embedded Shishya auch wissen wollen, wie motiviert du bist und welche Schritte du unternimmst, um dein Wissen in der sich ständig weiterentwickelnden Welt der IT-Sicherheit auf dem neuesten Stand zu halten. Das könnte in einem Gespräch über deine Weiterbildung oder zertifikatsbezogenen Pläne relevant sein!