This job has expired

This job posting is no longer active and is not accepting applications. Explore similar roles below!

Acima
Posted 2mo ago

Senior Security Engineer - Application & Cloud Security

Acima
Draper, Utah, United States
OnsiteFull Time
Responsibilities
  • securing applications
  • remediating vulnerabilities
  • integrating security
Requirements
  • 5+ years in application/cloud security or related engineering
  • Hands-on IaC, CI/CD
  • SAST/DAST/SCA
  • Terraform/CloudFormation/Kubernetes experience
  • Public cloud (AWS/Azure/GCP)
  • Strong coding
  • Threat hunting, and AI-assisted tooling experience
Technical tools mentioned
TerraformCloudFormationKubernetesHelmAWSAzureGCPSASTDASTSCAWAFGitHub CopilotClaudeChatGPT

Job description

Senior Security Engineer - Application & Cloud Security

(Draper Utah, In-Office) 

ABOUT UPBOUND 

Upbound Group, Inc. (effective February 27, 2023: NASDAQ: UPBD) is an omni-channel platform company committed to elevating financial opportunity for all through innovative, inclusive, and technology-driven financial solutions that address the evolving needs and aspirations of consumers. The Company’s customer-facing operating units include industry-leading brands such as Acima, Rent-A-Center, and Brigit that facilitate consumer transactions across a wide range of store-based and digital retail channels, including over 2,400 company branded retail units across the United States, Mexico and Puerto Rico. Upbound Group, Inc. is headquartered in Plano, Texas. 

ABOUT THE POSITION 

You will play a critical role in securing modern cloud-native applications, CI/CD pipelines, APIs, infrastructure, and development ecosystems across the enterprise. The ideal candidate is a cybersecurity-minded engineer who previously worked as a software developer, DevOps engineer, platform engineer, or infrastructure engineer and still possesses strong coding and system-level troubleshooting skills. This role requires someone who can read and understand source code, work closely with engineering teams, threat hunt across modern environments, and help build scalable security capabilities directly into the software development lifecycle. This position will work across Application Security, Cloud Security, and Engineering teams to help secure enterprise applications and cloud infrastructure, operating at scale. 

KEY RESPONSIBILITIES 

  • Work directly with software engineers, DevOps engineers, architects, and leadership to identify, prioritize, and remediate security vulnerabilities across applications and cloud environments. 

  • Perform hands-on application security reviews, source code analysis, threat modeling, and architecture reviews for modern applications and APIs. 

  • Build, integrate, automate, and operationalize security controls within modern CI/CD pipelines. 

  • Secure Infrastructure as Code (IaC) environments using Terraform, CloudFormation, Kubernetes, and related technologies. 

  • Develop and maintain automated security tooling and workflows across SAST, DAST, SCA, secrets scanning, container security, and cloud security platforms. 

  • Support incident response, threat hunting, forensic investigations, and remediation activities related to application and cloud environments. 

  • Identify and remediate security weaknesses involving APIs, authentication systems, secrets management, cloud infrastructure, containers, and microservices. 

  • Work closely with engineering teams to establish secure-by-default engineering practices and security guardrails. 

  • Assist with implementing and tuning WAF, API security, identity platforms, cloud security tooling, runtime protection, and logging/monitoring capabilities. 

  • Help operationalize modern security practices around: SSDLC, Software supply chain security, Cloud-native security, Threat detection and response 

  • Participate in security investigations involving fraud, insider threats, suspicious application activity, and cloud incidents. 

  • Provide technical leadership and mentorship across engineering and security teams. 

JOB REQUIREMENTS/QUALIFICATIONS 

  • 5+ years of experience in Application Security, DevSecOps, Cloud Security, Software Engineering, or related technical disciplines. 

  • Previous hands-on experience as a software developer, DevOps engineer, platform engineer, infrastructure engineer, or similar engineering role. 

  • Experience securing modern CI/CD environments and integrating security into engineering workflows. 

  • Strong experience with Infrastructure as Code (IaC), including Terraform, CloudFormation, Kubernetes, Helm, or similar technologies. 

  • Experience with public cloud platforms such as AWS, Azure, or GCP. 

  • Hands-on experience with security tooling such as: SAST, DAST, SCA, etc 

  • Understanding of OWASP Top 10, API security risks, cloud-native security threats, identity security, and modern attack techniques. 

  • Experience investigating and remediating vulnerabilities involving applications, APIs, authentication systems, cloud infrastructure, or software supply chain risks. 

  • Strong understanding of how to leverage AI tools and AI-assisted engineering workflows securely and effectively within day-to-day operations. 

  • Experience using modern AI-assisted development and security platforms such as GitHub Copilot, Claude, ChatGPT, or similar tools to improve engineering productivity, threat analysis, code review, vulnerability research, automation, and operational efficiency. 

  • Ability to evaluate, validate, and securely operationalize AI-generated output within enterprise engineering and cybersecurity environments. 

  • Understand the security implications, risks, and governance considerations associated with AI-assisted software development and modern AI workflows. 

  • Demonstrates a mindset of continuous learning and adaptation as AI rapidly transforms modern software engineering, DevOps, and cybersecurity operations. 

 

COMPENSATION/BENEFITS 

  • Competitive compensation  

  • Full health benefits-Medical/Dental/Vision  

  • 401(k) match, (5%/4%)  

  • DTO (discretionary time off)  

  • Health savings account (HSA) with company contribution  

  • College tuition reimbursement program (STEM degrees)  

  • Unlimited use of LinkedIn Learning  

  • On-site gym and showers 

  • Free car charging and covered parking 

  

SPONSORSHIP

Applicants must be authorized to work for ANY employer in the U.S. We are unable to sponsor or take over sponsorship of an employment visa at this time. 

Join us at the forefront of digital innovation, where your work will directly impact the future of financial accessibility and consumer experiences across retail, e‑commerce, and fintech. 

Upbound/Acima/Brigit are equal opportunity employers committed to ensuring that all employment decisions are made on a non-discriminatory basis, and without regard to actual or perceived race.   

About Acima

Provides virtual lease-to-own financing for retail consumers.

Similar jobs

Security Engineer roles near Draper, Utah
1w
Save
Mark Applied
Hide
Security Engineer
Salt Lake City, Utah, United States
HybridFull Time
Celtic Bank
Celtic Bank: Provides commercial lending and banking infrastructure for fintech companies.
3+ YOEBachelor's degree or equivalent experience; 3–5 years in information security or enterprise IT; Rapid7, CrowdStrike, SASE, CASB, SSPM, MFA, Dashlane, incident response, and financial security compliance experience.
Rapid7, CrowdStrike, Dashlane, Secure Access Service Edge (SASE), Cloud Access Security Broker (CASB), SaaS Security Posture Management (SSPM), Microsoft Excel
3w
Save
Mark Applied
Hide
Security Engineer
Salt Lake City, Utah, United States
RemoteFull Time
Check Point Software Technologies
Check Point Software TechnologiesNASDAQ: CHKP: Provides network, cloud, and mobile cybersecurity solutions.
5+ YOE5+ years engineering and pre-sales experience; strong analytical, communication, and presentation skills; ability to design end-to-end security solutions and conduct POCs; relevant certifications preferred.
1mo
Save
Mark Applied
Hide
Security Engineer
Hill AFB, Utah, United States
$100k-$203k/yr HybridFull Time
Accenture Federal Services
Accenture Federal ServicesNYSE: ACN: Provides technology and consulting services to U.S. federal agencies.
3+ YOEActive Secret clearance, 3+ years security engineering experience, Security+ (or equivalent), SIEM and automation experience, familiarity with RMF/JSIG and cloud security for AWS/Azure.
Splunk Enterprise, SIEM, Nessus, ACAS, Tenable Nessus Manager, Security Center, Evaluate-STIG, SCAP Compliance Checker, Microsoft Defender, Trellix, Ansible, Terraform, PowerShell, Bash, Python, AWS, Azure, Docker, Kubernetes, ECS, EKS, AKS, TCP/IP
1mo
Save
Mark Applied
Hide
Security Engineer
Kansas City or Atlanta or Clayton or New York or Los Angeles or Birmingham or Boston or Chattanooga or Charleston or Dallas or Denver or Edwardsville or Fort Lauderdale or Fort Worth or Houston or Jefferson City or Miami or Nashville or Park City or Philadelphia or Phoenix or Raleigh or Seattle or San Francisco or Salt Lake City or Wilmington or Washington
$120k-$150k/yr RemoteFull Time
Polsinelli
Polsinelli: Am Law 100 law firm providing comprehensive legal services.
2+ YOE2-4 years security engineering experience in on-premises environments, Bachelor's in CS/CE/IS or equivalent, experience with metrics/events/logging, detection engineering, scripting (Python, PowerShell), Microsoft Active Directory and Azure.
Splunk, Microsoft Active Directory, Azure, SIEM, Python, PowerShell, Microsoft Teams, Zoom, MITRE ATT&CK Framework, NIST Cyber Security Framework, CIS Controls
1mo
Save
Mark Applied
Hide
Senior Security Engineer
West Jordan, Utah, United States
OnsiteFull Time
Novva Data Centers
Novva Data Centers: Operates sustainable wholesale and multi-tenant colocation data center facilities.
7+ YOE7+ years cybersecurity experience with 5+ years security engineering; bachelor's in IT/cybersecurity (or equiv), Microsoft security tech experience, SIEM/EDR/IAM and vulnerability management experience.
Microsoft Defender XDR, Microsoft Entra ID, Privileged Identity Management (PIM), Conditional Access, Defender for Cloud, Defender for Endpoint, Email Security, SIEM, EDR, IAM, vulnerability management platforms, Microsoft 365, AWS, ServiceNow, PowerShell, Python, Infrastructure as Code, SIEM/SOAR platforms, Active Directory, Windows Server, Linux, Firewalls, DNS, VPN
1mo
Save
Mark Applied
Hide
Corporate Security Engineer
Salt Lake City or Seattle or San Francisco or New York City or London or Madrid or Singapore
$58k-$167k/yr OnsiteFull Time
Taxbit
Taxbit: Automated tax and accounting software for digital assets.
4+ YOEBachelor's in a technical field, 4+ years systems administration/security ops experience, hands-on Okta, Jamf, Intune, Google Workspace, SIEM, scripting (Bash/Python/PowerShell), and familiarity with ISO 27001/SOC 2/NIST frameworks and AI governance/operations.
Okta, Jamf Pro, Jamf Business Plan, Microsoft Intune, Google Workspace, SIEM, Bash, Python, PowerShell
3mo
Save
Mark Applied
Hide
Virtru Security Engineer
Fort Meade or Pensacola or Mechanicsburg or Columbus or San Antonio or Ford Island or Scott AFB or Tinker AFB or Hill AFB
$99k-$225k/yr OnsiteFull Time
Booz Allen Hamilton
Booz Allen HamiltonNYSE: BAH: Provides technology and management consulting services to diverse organizations.
3+ YOE3+ years designing and deploying data security solutions; experience with data security tools (e.g., Virtru); security architecture and cloud knowledge; Kubernetes and Docker; data tagging/classification; Zero Trust concepts; ability to travel up to 20%; Secret clearance; HS diploma or GED.
Terraform, Ansible, Kubernetes, Docker, CI/CD, Vulnerability Scanning, CNAP, SIEM, CSPM, CWPP, Go, Python, Node.js
3d
Save
Mark Applied
Hide
Senior Cloud Security Engineer
Midvale, Utah, United States
HybridFull Time
Zions Bancorporation
Zions BancorporationNASDAQ: ZION: Provides banking, lending, and financial services to customers.
8+ YOERequires 8-10+ years of cybersecurity experience, including 3-5+ years in cloud security, plus cloud platform expertise, security tool administration, stakeholder collaboration, and a relevant bachelor's degree or equivalent experience.
Broadcom CloudSOC, Symantec CASB, Palo Alto Prisma Cloud CSPM, AWS, Azure, IAM, SIEM, DLP, API
This job has expired