Jobs and Careers
CR

Senior Cloud Security Engineer

Credit Acceptance
Silver Triangle Building, United StatesRemotefull_timeVerifiedPosted 23 May 2024
💰 $195,797/yr($113,518/yr$195,797/yr)

About the role

Credit Acceptance is proud to be an award-winning company with local and national workplace recognition in multiple categories! Our world-class culture is shaped by dedicated Team Members who share a drive to succeed as professionals and together as a company. A great product, amazing people and our stable financial history have made us one of the largest used car finance companies nationally.

Our Engineering and Analytics Team Members utilize the latest technology to develop, monitor, and maintain complex practices that help optimize our success.  Our Team Members value being challenged, are encouraged to express their ideas, and have the flexibility to enjoy work life balance.  We build intrinsic value by partnering with all functions of our business to support their success and make strategic business decisions.  We focus on professional development and continuous improvement while enjoying a casual work environment and Great Place to Work culture!

We are looking for a highly motivated Cloud Security Engineer to join our Engineering Security function reporting to the Director of Engineering Security and Compliance. Our company is committed to building innovative technologies and future-proofing our business to stay ahead in the ever-changing digital landscape. We are seeking a passionate individual who is excited about protecting cutting-edge web applications built on public cloud such as AWS and Azure. The ideal candidate should possess strong cloud security skills, hybrid/multi-cloud network concepts, a deep understanding of secure software development life cycle methodologies, and a keen eye for detail. As a Cloud Security Engineer, you will be an essential part of the Engineering Security team, focused on ensuring the security of the Credit Acceptance web applications and cloud infrastructure through the continual improvement of security tooling, automation, and engagement with internal stakeholders. 

Outcomes and Activities: 

  • This position will work from home; occasional planned travel to an assigned Southfield, Michigan office location may be required.  However, this position is permitted to work at a Southfield, Michigan office location if requested by the team member ​
  • Design and Implement cloud security architecture using zero-trust principles
  • Automate security controls, data, and processes to provide better metrics and operational support using security-as-code
  • Configure network security including in a hybrid context with traditional network centric controls  
  • Design and Implement host-based security monitoring (E.g. AWS Inspector), network security tooling, or other infrastructure related security projects
  • Assess and support application migration efforts including but not limited to network connectivity architecture
  • Conduct Threat modeling to support business requirements
  • Define and implement IaC validation to prevent insecure configuration from being deployed
  • Configure access within the cloud environment using the defense-in-depth principle.  
  • Assess cloud systems and infrastructure to identify potential weaknesses or problems and upgrade software, VMs, containers to ensure optimal performance of cloud environment and security tools
  • Develop automated security compliance, remediate misconfigurations, vulnerabilities in the code/configurations
  • Lead cloud security issue remediation, troubleshooting and continuous improvement efforts including collaborating with stakeholders to improve overall application security posture
  • Support Cloud Security Maturity Assessment processes with  automated security reviews
  • Implement and configure security controls and policies, manage access to data, and monitor threats to ensure that apps, containers, infrastructure, and networks are protected
  • Take ownership of new initiatives, work with internal security teams, ESS, engineering, and product functions to deliver actionable intelligence or solutions that will lower risk 
  • Support our DevOps and infrastructure engineers to implement security best-practices and enable secure development and release processes
  • Perform architectural and design reviews through the security lens and provide timely, actionable requirements and recommendations 

 

Competencies: The following items detail how you will be successful in this role.  

  • Impact Analysis: Understand the rationale behind and how changes impact the enterprise and/or applications and across the technical ecosystem.  
  • Solution Design: Ability to translate high level requirements to create and implement designs that meet the needs of the customer, are technically sound, maintainable and cost effective. Ability to identify missing or ambiguous requirements. Ability to design at both high and low levels of abstraction, understand complex require

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Credit Acceptance

View company profile →