Staff Application Security Specialist

3 days ago


Atlanta, Georgia, United States Credit Acceptance Corporation Full time
About Us

Credit Acceptance Corporation is a leading provider of financing solutions for the automotive industry. We are proud to be an award-winning company with a strong culture of innovation and excellence.

Job Summary

We are seeking a highly skilled Staff Application Security Engineer to join our Information Security team. As a key member of our team, you will be responsible for designing and implementing secure software development practices, identifying and mitigating security risks, and collaborating with cross-functional teams to ensure the confidentiality, integrity, and availability of our software and computer information systems.

Key Responsibilities
  • Develop and maintain a comprehensive security program to support various Software Development Lifecycles (SDLCs)
  • Perform threat modeling, architectural risk analysis, design reviews, code review, and security testing on applications
  • Provide guidance on triaging potential vulnerabilities identified by application security program with context of application and related business knowledge
  • Collaborate cross-functionally to ensure technology is free from security defects
  • Create documentation, knowledge base articles, or diagrams concerning security technologies or their data flows
Requirements
  • Bachelor's degree in Computer Science, Information Systems, or closely related field of study; or equivalent work experience
  • Minimum 8 years of experience with a focus on Application Security Engineering
  • Experience performing threat modeling, design reviews, and secure code reviews on applications and systems
  • Strong familiarity with a broad range of security technologies: SIEM, CASB, SOAR, DLP, and EDR
  • Strong understanding of software composition analysis and creating SBOMs
  • Experience with OWASP
  • Experience with SAST and DAST/IAST tools
  • Expertise with continuous integration and continuous deployment (CI/CD) pipelines as well as how security fits into the delivery process (i.e. DevSecOps)
  • Knowledge of cloud platforms and services, with experience in cloud security
  • Experience with automated software and security testing tools and techniques
  • Experience with Docker and Kubernetes container security
Preferred Experience
  • Professional experience with one or more of the following languages (C#, .NET, Java, etc.)
  • Professional certifications in cyber security (CSSLP, OSCP, etc.)
  • Financial Services industry experience
  • Familiarity with software assurance maturity models
  • Experience developing and training on threat models using STRIDE
  • Experience with ASPM or RASP tools
  • Experience with UVM tools
  • Mobile App testing experience
  • Experience with the following regulatory standards PCI-DSS, ISO 27001, SOX, NYDFS
What We Offer
  • Competitive base salary + an annual variable bonus (cash and equity) will range from $165,000 to 253,750
  • Excellent benefits package that includes 401(K) match, adoption assistance, parental leave, tuition reimbursement, comprehensive medical/ dental/vision and many nonstandard benefits that make us a Great Place to Work
Our Company Values
  • Positive by maintaining resiliency and focusing on solutions
  • Respectful by collaborating and actively listening
  • Insightful by cultivating innovation, accumulating business and role specific knowledge, demonstrating self-awareness and making quality decisions
  • Direct by effectively communicating and conveying courage
  • Earnest by taking accountability, applying feedback and effectively planning and priority setting


  • Atlanta, Georgia, United States Softpath System Full time

    Job Summary:Softpath System is seeking a highly skilled Application Security Specialist to join our team. As a key member of our security team, you will be responsible for conducting remediation validations, manual code reviews, and static code analysis to ensure the security and integrity of our applications.Key Responsibilities: Conduct remediation...


  • Atlanta, Georgia, United States Securitas Electronic Security Inc Full time

    We are seeking a skilled Security Systems Specialist to join our team at Securitas Electronic Security Inc. The ideal candidate will have experience in low voltage electronics and electronic security solutions.The role involves providing service on our products at customer sites, responding to trouble tickets, diagnosing and resolving application issues, and...


  • Atlanta, Georgia, United States Stefanini North America and APAC Full time

    Job Title: Application Security EngineerStefanini North America and APAC is seeking a highly skilled Application Security Engineer to join our team.About the RoleWe are looking for a talented individual to work closely with our client's product teams and engineering groups to ensure secure architectures, patterns, and solutions are created and maintained.Key...


  • Atlanta, Georgia, United States Saxon Global Full time

    Job Title: Application Security TesterWe are seeking a highly skilled Application Security Tester to join our team at Saxon Global. As an Application Security Tester, you will be responsible for identifying weaknesses and vulnerabilities in our applications and systems.Key Responsibilities:Identify and assess vulnerabilities in our applications and...


  • Atlanta, Georgia, United States Insight Global Full time

    Job Title: Application Security EngineerWe are seeking a skilled Application Security Engineer to join our team remotely. As a key member of our security team, you will be responsible for ensuring the security and integrity of our software applications.Job Summary:The successful candidate will have a strong background in application security, with experience...


  • Atlanta, Georgia, United States Better Hire Full time

    About the RoleWe are seeking a highly skilled Application Security Engineer to join our team at Better Hire. As a key member of our security team, you will be responsible for ensuring the security and integrity of our cloud-based applications and infrastructure.Key ResponsibilitiesDesign and implement secure solutions for authentication and authorization,...


  • Atlanta, Georgia, United States Securitas Electronic Security Inc Full time

    At Securitas Electronic Security Inc, we're seeking a skilled Security Systems Specialist to join our team. As a leading provider of security solutions, we deliver cutting-edge systems and services to protect people, customers, and assets.Key Responsibilities:Respond to trouble tickets to ensure application uptime and system performanceWork individually and...


  • Atlanta, Georgia, United States Stefanini Group Full time

    Job Summary:We are seeking a highly skilled Application Security Consultant to join our team at Stefanini Group. The ideal candidate will be responsible for ensuring the security of our organization's applications by identifying vulnerabilities, implementing security measures, and providing recommendations for improvement.Key Responsibilities: Conduct...


  • Atlanta, Georgia, United States Genesis10 Full time

    Job Title: Application Security EngineerGenesis10 is seeking an experienced Application Security Engineer to join our team in Atlanta, GA. This is a 12+ month contract position.Description:We are looking for a skilled Application Security Engineer to conduct Static Application Security Test (SAST), Dynamic Application Security Test (DAST), and Source Code...


  • Atlanta, Georgia, United States FIRST SOFTSOLUTIONS INC Full time

    Job Title: Application & Cloud Container Security EngineerWe are seeking a highly skilled Application & Cloud Container Security Engineer to join our team at First SoftSolutions Inc.Job Summary:The successful candidate will have a deep understanding of cybersecurity and application security testing expertise to identify vulnerabilities in applications. They...


  • Atlanta, Georgia, United States Softpath System Full time

    Job Title: Application SecurityAt Softpath System, we are seeking a highly skilled Application Security professional to join our team. The successful candidate will be responsible for conducting remediation validations, manual code reviews, and static code analysis to ensure the security of our applications.Key Responsibilities:Conduct remediation...

  • Security Specialist

    4 weeks ago


    Atlanta, Georgia, United States Culpepper & Associates Security Services, Inc. Full time

    Job OpportunityCulpepper & Associates Security Services, Inc. is seeking a skilled security professional to join their team in Atlanta, GA.Key Responsibilities:Ensure a secure and safe environment for clients and staffConduct regular patrols and monitor premises as directedProvide direction to clients and visitorsAssess and respond to potential threats or...


  • Atlanta, Georgia, United States CAMP Full time

    Job Title: Application Security EngineerCAMP Systems is a leading provider of aircraft compliance and health management services to the global business aviation industry. As a pioneer in its field, CAMP has established itself as the pre-eminent brand in the industry, with a strong presence in 13 locations worldwide.Our company has grown significantly since...


  • Atlanta, Georgia, United States CAMP Systems International, Inc. Full time

    About CAMP Systems International, Inc.CAMP Systems International, Inc. is a leading provider of aircraft compliance and health management services to the global business aviation industry. With a strong presence in 13 locations worldwide, the company has grown from a single location in 2001 to over 1,300 employees. CAMP's relationships with business aircraft...


  • Atlanta, Georgia, United States ImagineX Consulting Full time

    Job OverviewImagineX Consulting is a software company that helps clients transform their businesses by embracing emerging technologies. We're looking for an Application Security Engineer to join our team.This is a 100% remote position with aggressive salary and bonus packages, and 401K matching. Must be comfortable working standard west coast hours.Key...


  • Atlanta, Georgia, United States ImagineX Consulting Full time

    Job OverviewImagineX Consulting is a software company that helps clients transform their businesses by embracing emerging technologies. We're looking for an Application Security Engineer to join our team.Key ResponsibilitiesProvide guidance and assistance to development personnel in understanding security vulnerabilities and remediation options.Collaborate...


  • Atlanta, Georgia, United States Insight Global Full time

    Security Software Assurance AnalystWe are seeking a skilled Security Software Assurance Analyst to join our team remotely. This role offers a competitive salary range of $45-$70 per hour, with exact compensation varying based on skills, experience, and education.Benefits:Medical, dental, and vision insuranceHSA, FSA, and DCFSA account options401k retirement...


  • Atlanta, Georgia, United States Security 101 Full time

    Job Summary:We are seeking a highly skilled and experienced Senior Electronic Security Systems Specialist to lead our team in installing, programming, and servicing commercial electronic security devices, primarily IP network systems and overall security systems.Key Responsibilities:Install, troubleshoot, program, and test security systems with minimal...


  • Atlanta, Georgia, United States Crescens Full time

    Job Title: Application Support SpecialistJob Summary:Crescens is seeking a skilled Application Support Specialist to provide technical assistance to end-users in a Tier-II support role. The successful candidate will be responsible for resolving complex issues, collaborating with the Tier-I team, and maintaining a log of support issues.Key Responsibilities:...


  • Atlanta, Georgia, United States Credit Acceptance Corporation Full time

    Job SummaryCredit Acceptance Corporation is seeking a highly skilled Staff Application Security Engineer to join our team. As a technical leader, you will be responsible for developing and implementing a comprehensive security program to support various Software Development Lifecycles (SDLCs) and ensuring that software developed in this SDLC is free of...