Senior Application Security Engineer (Remote)
Progressive LeasingAbout the role
Progressive Leasing is a leading provider of in-store and e-commerce lease-to-own solutions. As an almost 20+ year old FinTech company that has gone from start-up to industry leader, we know how to innovate, simplify, and value all people. We are a company founded on our grit and we are constantly looking to the future. As an ever-evolving group of entrepreneurs and technologists, we strive to do the right thing period in all aspects of our work. We are a subsidiary of PROG Holdings (NYSE: PRG), an exciting FinTech holding company, with three business segments including Progressive, Vive Financial, and Four, a Buy Now Pay Later (BNPL) platform.
We are currently hiring a Senior Application Security Engineer to help grow our company and ensure our mission is achieved!
This role is a work from home position and can be performed remotely anywhere in the continental US or in one of our corporate locations in Utah or Arizona.
Employee Value Proposition (EVP): PROG is dedicated to providing people with opportunity; opportunity for inclusive collaboration, opportunity for innovation, and opportunity for development.
WE ARE: Prog Tech embodies the modernity and transformational vision that is core to our business evolution. As passionate and hungry technical experts, we join together on the mission of progressing through technology. We believe in taking pride in our engineering, in the relentless pursuit of daily progress, and to bring others with you in your march to the future. We continuously experiment, fail fast, and constantly deliver
YOU ARE: The Senior Application Security Engineer plays a critical role in partnering closely with engineering and DevOps teams to ensure that security is built into our applications and infrastructure from start to finish. You will take ownership of building security into the CI/CD pipelines, provide expertise in threat modeling, and mentoring others to raise overall AppSec maturity.
YOUR DAY-TO-DAY:
Identify areas for improvement in our current CI/CD pipeline and design, implement, and maintain security enhancements.
Partner with engineering teams to ensure security controls and tooling are integrated into the SDLC.
Develop and lead a threat modeling program for new and existing applications.
Identify vulnerabilities across applications and APIs. Engage engineering teams for remediation.
Collaborate with the business and engineering teams to provide guidance on security best practices, prioritization of vulnerability remediation, etc.
Evaluate, implement, and manage security tools and technologies.
Mentor and coach engineers, DevOps, and other team members to build a strong AppSec culture.
Participate in AppSec team programs, such as Security Influencers (Champions) and office hours, to cultivate
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s