Credit Acceptance is proud to be an award-winning company recognized both locally and nationally across multiple workplace categories. Our world-class culture is shaped by dedicated team members who are driven to succeed as professionals individually and together as a team. Backed by a strong product, exceptional people, and a stable financial foundation, we've grown into a leading provider of used and new car financing across the country.
Our Engineering and Analytics Team Members utilize the latest technology to develop, monitor, and maintain complex practices that help optimize our success. Our Team Members value being challenged, are encouraged to express their ideas, and have the flexibility to enjoy work life balance. We build intrinsic value by partnering with all functions of our business to support their success and make strategic business decisions. We focus on professional development and continuous improvement while enjoying a casual work environment and Great Place to Work culture!
The Application Security Engineer is responsible for securing the software and applications that Credit Acceptance builds, buys, and operates. This role partners closely with engineering, product, architecture, and business teams to ensure that applications handling sensitive consumer, dealer, and loan data are designed, developed, and deployed in a secure manner, meeting both internal security standards and the regulatory expectations of a financial services environment.
This position focuses on embedding security into the software development lifecycle by providing hands‑on technical guidance, performing threat modeling and application security reviews, defining secure design patterns and guardrails, and supporting engineering teams as they build and maintain modern web, mobile, API, and cloud‑based applications.
Outcomes and Activities:
This position will work from home; occasional planned travel to an assigned Southfield, Michigan office location may be required. However, this position is permitted to work at a Southfield, Michigan office location if requested by the team member.
Partner with engineering and architecture teams to design and review application architectures (web, mobile, API, and microservices) for security, privacy, and regulatory compliance.
Perform security reviews of applications and services at each stage of the SDLC, including design, code, building pipelines, dependencies, infrastructure‑as‑code, and third‑party components.
Identify and mitigate risks such as:
Injection, authentication/authorization, injection and session management flaws (OWASP Top 10, ASVS)
Insecure handling of NPI, PII, and payment data
Management of open‑source dependency vulnerabilities and software supply chain risks
Insecure cloud configurations, secrets management, and exposed APIs
Support threat modeling and risk assessments for new and existing applications, assisting teams in implementing practical mitigations.
Assess and help mitigate security risks introduced by AI‑assisted and agentic development tools (e.g., GitHub Copilot, Claude Code, LiteLLM), including review of AI‑generated code, exposure of source code or secrets to external models, and proper use of internal LLM gateways.
Governance, Standards, and Policy
Collaboration & Advisory
Continuous Improvement
Competencies:
Required:
Preferred:
Knowledge and Skills:
Target Compensation: A competitive base salary range from $85,695 - $125,685. This position is eligible for an annual variable cash bonus, between 7.5 - 15%. Bonus amounts are based on individual performance. Final compensation within the range is influenced by many factors including role-specific skills, depth and experience level, industry background, relevant education and certifications.
Candidates who reside in the following major metropolitan areas may be eligible for a premium on top of the posted range based on their specific zone: San Francisco, Seattle, Boston, New York City, Los Angeles and San Diego.
INDENGLP
#zip
#LI-Remote
Benefits
Our Company Values:
To be successful in this role, Team Members need to be:
Expectations:
Advice!
We understand that your career search may look different than others. Our hiring team wants to make sure that this would be a fit not just for us, but for you long term. If you are actively looking or starting to explore new opportunities, send us your application!
P.S.
We have great details around our stats, success, history and more. We're proud of our culture and are happy to share why - let's talk!
Required degrees must have been earned at institutions of Higher Education which are accredited by the Council for Higher Education Accreditation or equivalent.
Credit Acceptance is dedicated to providing a safe and inclusive working environment for all. As part of our Culture of Compliance, we are proud to be an Equal Opportunity Employer and value our culturally diverse workforce. All qualified applicants will receive consideration for employment regardless of the person's age, race, color, religion, sex, gender, sexual orientation, gender identity, national origin, veteran or disability status, criminal history, or any other legally protected characteristic.
California Residents: Please click here for the California Consumer Privacy Act (CCPA) notice regarding the personal information Credit Acceptance may collect from you.
Play the video below to learn more about our Company culture.
At Credit Acceptance, we are passionate about what we do. Our team members are intelligent, motivated, compassionate people who work hard and know how to have fun. We offer a strong work-life balance with many great benefits that start on day one. We focus first and foremost on striving to make our Company as valuable as possible, because we know it is the core of our success. Our team members are motivated by their desire to “Change Lives,” as well as by their fellow colleagues, Company leaders, competitive compensation, and career advancement opportunities.
Credit Acceptance has been named to Fortune magazine’s annual “100 Best Companies to Work For” list for 11 years, ranking #34 in 2025. We’ve also been named to IDG's Computerworld Best Places to Work in IT-Midsize category for the past six years. Based on 2025 survey data, 95% of our team members believe Credit Acceptance is a Great Place to Work (GPTW). Learn more about us at: https://www.greatplacetowork.com/certified-company/27