Senior Application Security Developer
About Acima
Acima Credit is based in Draper, Utah and is a young and dynamic leasing company that provides consumers financing options for life necessities otherwise not available to them. Acima blends the use of innovative online technology with a fast and easy application process for thousands of retailers nationwide. Acima is recognized as one of the fastest growing companies by the Mountain West Capital Network and the Utah Business Magazine and we need awesome people to continue to propel that growth.
Job Overview
As our Sr. Application Security Developer, you are expected to build strong relationships and become deeply embedded within the product management and software engineering teams. Working closely with these teams, you will drive the design and adoption of secure coding and SSDLC across teams and codebases.
You will be at the forefront of fostering a culture of bug and vulnerability remediation. You will need the ability to configure and deploy an appropriate static and dynamic code analysis tool to help developers quickly identify vulnerabilities. At the same time, you must demonstrate the ability to communicate well, so you can work with us to track and remediate the identified vulnerabilities.
Responsibilities
- Code and project security reviews
- Application penetration testing
- Implementation of application static analysis processes
- Deploy, configure, tune, and support an automated static code analysis tool
- Perform manual code reviews and work with developers to remediate security flaws
- Lead and champion the SSDLC across teams and programming languages
- Ensure code security integration into the current CI/CD pipeline
- Identify areas for automation and tooling to increase code security coverage
- Establish metrics and reporting to track the effectiveness of security processes
Benefits & Compensation
Acima understands that employment is the sum of many parts. Our compensation is very competitive. Pay Range starting at $135,000+ annually. Our total benefits round out what we feel is a complete package. Benefits include: paid time off, company paid holidays, supplemental insurance (long-term/short-term disability, life insurance, etc.), medical insurance, Health Savings Account (HSA) with a company match, dental and vision insurance, 401K with company match, employee assistance program and more.
- Strong experience in building security for web and mobile applications
- Strong experience in security development and design with microservice architectures
- In-depth knowledge of web and mobile security standards and best practices (OWASP, etc.)
- Experience with industry tools and technologies such as Burp, Metasploit, etc.
- Working knowledge of common languages such as Ruby, Python, Javascript, Java, etc.
- Excellent communication skills, good team player, self-motivated, and able to explain complex security topics in simple terms
- 5+ years of experience in a software development role such as Software Developer, Software Quality Assurance, or Security Engineer with a good understanding of application security
- Foundational knowledge of web application design best practices and secure software development
- Understanding of agile development practices and how to integrate security into those practices
- Security certifications such as CSSLP, GWEB, GWAPT, or other web application security certifications
- Knowledge of WCF, AJAX, HTML, ESB (Neuron a plus), SSIS/TSQL, jQuery
- Experience with SOA, web services, REST, SOAP, XSLT, XSD, and XML