Upstart
Senior Application Security Engineer
Remote role where the employee must remain based in a particular country.
United States only
Employer listed it 2 days ago · Added 2 days ago
First listed 2 days ago.
Salary
$167k to $231k per year
Location
United States only
Timezone
US East
Contract
Full-time
Experience
Senior
Category
Software
Stated by the employer in the job description
Remote flexibility
Work from home
This is a remote role, but the employee must be based in United States. It is work from home rather than work from anywhere.
What the employer says
- Source listing states candidate location: "United States | Remote, Remote - United States"
- Job description states: "based in Canada"
What Nomaders makes of it
- Payroll and tax are likely handled in that country only
The quotes above are the employer's own words; the reading is ours. Always check the original listing and employment terms before working from another country.
About the role
About Upstart
At Upstart, we’re united by a mission that matters: to radically reduce the cost and complexity of borrowing for all Americans. Every day, we bring creativity, experimentation, and advanced AI to reshape access to credit, helping millions move forward financially with clarity and confidence.
As the leading AI lending marketplace, we partner with banks and credit unions to expand access to affordable credit through technology that’s both radically intelligent and deeply human. Our platform runs over one million predictions per borrower using more than 3,000 signals, powering smarter, fairer decisions for millions of customers. But the numbers only hint at the impact. Every idea, every voice, and every contribution moves us closer to a world where credit never stands between people and their financial progress.
We’re proudly digital-first, giving most Upstarters the flexibility to do their best work from wherever they thrive, alongside teammates across 80+ cities in the US and Canada. Digital-first doesn’t mean distant. We’re intentional about in-person connection through team onsites, planning sessions, and moments that spark creativity and trust. And whether you choose to work primarily from home or collaborate in-person from one of our offices in Columbus, Austin, the Bay Area, or New York City, you’ll have the support to work in the way that works best for you.
If you’re energized by tackling meaningful problems, excited to innovate with purpose, and motivated by work that truly matters, we’d love to hear from you.
The Team:
Upstart’s Application Security team enables product and engineering teams to build secure products without slowing innovation. We believe security should move at the speed of the business and that safety by design should be embedded throughout the software development lifecycle. Through engineering, automation, and close collaboration, we protect Upstart’s customer-facing products, internal applications, APIs, and AI-enabled systems while maintaining a positive developer experience.
As a Senior Application Security Engineer at Upstart, you will lead application security projects that reduce risk across our products and engineering ecosystem. You will partner with product, platform, data, infrastructure, and engineering teams to identify security risks, review designs, build preventative controls, and drive complex issues through remediation. This role is well suited for an experienced application security engineer who can lead substantial technical initiatives, navigate ambiguity, and deliver durable improvements that raise the security bar across the team and its partners.
How you’ll make an impact
Lead application security projects from planning through implementation, coordinating contributors and dependencies to deliver high-quality outcomes.
Conduct threat modeling and security architecture reviews for complex customer-facing applications, APIs, distributed services, and AI/ML systems.
Design and implement secure-by-default controls across the software development lifecycle, including secure coding standards, API protections, automated testing, CI/CD safeguards, and secrets management.
Partner with engineering teams to identify systemic vulnerabilities, evaluate practical remediation options, and ensure high-risk issues are resolved effectively.
Build services and automation that improve vulnerability detection, prioritization, validation, and prevention while reducing friction for developers.
Assess the security of AI-enabled products and developer workflows, including GenAI integrations, agentic systems, model inputs and outputs, sensitive-data handling, and access boundaries.
Provide technical leadership during high-severity application security incidents, helping determine root causes and drive durable follow-up improvements.
Improve team effectiveness by contributing to design and code reviews, documenting reusable patterns, mentoring engineers, and helping strengthen application security practices across Upstart.
Minimum Qualifications
5+ years of experience in security engineering, software engineering, or a related technical role, including 2+ years focused on application or product security.
Experience leading security projects involving multiple contributors or partner teams.
Experience conducting threat modeling and security architecture reviews for complex production applications.
Experience developing production software or security automation in Java, Python, Ruby, Go, or a similar programming language.
Experience designing or implementing application security controls across the software development lifecycle, including several of the following: API security, secure coding standards, SAST, DAST, SCA, CI/CD security, or secrets management.
Experience identifying, validating, prioritizing, and driving remediation of application vulnerabilities.
Requirements
- ·5+ years of experience in security engineering, software engineering, or a related technical role, including 2+ years focused on application or product security.
- ·Experience leading security projects involving multiple contributors or partner teams.
- ·Experience conducting threat modeling and security architecture reviews for complex production applications.
- ·Experience developing production software or security automation in Java, Python, Ruby, Go, or a similar programming language.
- ·Experience identifying, validating, prioritizing, and driving remediation of application vulnerabilities.
Benefits
- ·Employee Assistance Program (EAP) offering mental health support and life-centered resources
- ·Financial wellness resources, including access to financial planning tools and a financial concierge service (US Only)
- ·Annual wellness allowance to support your physical and emotional well-being and personal development, based on what matters most to you
- ·Annual productivity allowance to invest in relevant tools and resources you need to do your best work, no matter where you work from
- ·Connection and community through team events, all-company updates, and employee resource groups (ERGs)
How to apply
- 1Check the flexibility label above, work from home, matches where you plan to live and work.
- 2Tailor your CV to the role at Upstart, mentioning your remote working experience and working hours (US East).
- 3Apply directly on the employer's careers page using the button below. Nomaders never handles your application.
Found 3d ago. Last checked 23 Sept. Always confirm the details on the original posting, salary and location can change after publication.
Listing sourced from Company boards.
Similar roles
Other open software roles with comparable remote rules.
Free to apply, no account needed.
$167k to $231k per year · You'll be taken to the employer's careers page.