Credit Acceptance

Credit Acceptance

Application Security Engineer II

USA - Remote · Mid

Sponsorship not specified$86k-$126kDetected 30 days ago
ExpressGitAWSGCPAzureCloud PlatformsCI/CDDevOpsLLMsCybersecurityPenetration TestingComplianceAgileSupply ChainLeadershipCommunicationCollaborationCISSP

About the role

  • Our world-class culture is shaped by dedicated team members who are driven to succeed as professionals individually and together as a team.
  • Backed by a strong product, exceptional people, and a stable financial foundation, we've grown into a leading provider of used and new car financing across the country.

Responsibilities

  • Shared goals, open communication and mutual support create a sense of collective purpose.

Requirements

  • Bachelor's Degree or equivalent experience
  • 3+ years of experience in application security, product security, or secure software development.
  • 2+ years of hands‑on experience performing application security reviews, penetration testing, threat modeling, or secure code review.
  • Attendance as required by department

Nice to have

  • Familiarity with the OWASP Top 10, OWASP ASVS, and OWASP SAMM, and with software supply chain frameworks such as SLSA.
  • Experience with cloud platforms (e.g., AWS, Azure, GCP) and containerized environments.
  • Knowledge of regulatory and compliance considerations relevant to financial services (e.g., PCI DSS, GLBA, SOX).
  • Experience embedding security into software development workflows (DevSecOps) and CI/CD pipelines.
  • Hands‑on experience with application security tooling such as SAST, DAST, SCA, IAST, secrets scanning, or ASPM platforms.
  • Relevant certifications (e.g., GWAPT, GWEB, OSWE, CSSLP, CISSP) a plus.
  • Familiarity with security considerations for AI‑assisted development environments (e.g., GitHub Copilot, Claude Code) and LLM gateway/proxy tooling (e.g., LiteLLM).

Skills

  • Strong understanding of modern software development practices, frameworks, and architectures (web, mobile, API, microservices, serverless).
  • Working knowledge of common application vulnerabilities and exploitation techniques, and the controls that mitigate them.
  • Understanding of authentication, authorization, identity, cryptography, and secure data handling patterns.
  • Familiarity with threat modeling, security testing, and risk assessment techniques.
  • Ability to read and reason about code in one or more common programming languages.
  • Ability to communicate security risks and recommendations clearly to both technical and non‑technical audiences.
  • Credit Acceptance is proud to be an award-winning company recognized both locally and nationally across multiple workplace categories.

Compensation

  • A competitive base salary range from $85,695 - $125,685.
  • This position is eligible for an annual variable cash bonus, between 7.5 - 15%.
  • Final compensation within the range is influenced by many factors including role-specific skills, depth and experience level, industry background, relevant education and certifications.

Benefits

  • Excellent benefits package that includes 401(K) match, adoption assistance, parental leave, tuition reimbursement, comprehensive medical/ dental/vision and many nonstandard benefits that make us a Great Place to Work

Company info

  • To be successful in this role,
  • Please click here for the California Consumer Privacy Act (CCPA) notice regarding the personal information Credit Acceptance may collect from you.
  • Play the video below to learn more about our Company culture.
  • Engineering Excellence is about bringing great craftsmanship and thought leadership to deliver an outstanding product that delights customers and solves for the business.

Equal opportunity

  • As part of our Culture of Compliance, we are proud to be an Equal Opportunity Employer and value our culturally diverse workforce.

This listing is sourced directly from Credit Acceptance's careers page and normalized into a canonical job model.