Base Salary
$167k - $231k/yr
Responsibilities
- Lead application security projects involving multiple contributors and partner teams.
- Conduct threat modeling and security architecture reviews for applications, APIs, distributed services, and AI/ML systems.
- Design and implement secure-by-default controls across the software development lifecycle, including API protections, automated testing, CI/CD safeguards, and secrets management.
- Identify, validate, prioritize, and drive remediation of application vulnerabilities.
- Build services and automation for vulnerability detection, prioritization, validation, and prevention.
- Assess security risks in GenAI integrations, agentic systems, model inputs and outputs, sensitive-data handling, and access boundaries.
- Provide technical leadership during high-severity application security incidents and drive corrective engineering work.
- Contribute to design and code reviews, document reusable patterns, mentor engineers, and improve application security practices.
Requirements
- 5+ years of experience in security engineering, software engineering, or a related technical role, including 2+ years focused on application or product security.
- Experience leading security projects involving multiple contributors or partner teams.
- Experience conducting threat modeling and security architecture reviews for complex production applications.
- Experience developing production software or security automation in Java, Python, Ruby, Go, or a similar programming language.
- Experience implementing application security controls such as API security, secure coding standards, SAST, DAST, SCA, CI/CD security, or secrets management.
- Experience securing cloud-native or distributed systems, including web applications, APIs, or microservices.
- Preferred experience building reusable security guardrails, platforms, or automation adopted by multiple engineering teams.
- Preferred experience securing frontend frameworks, REST or GraphQL APIs, microservices, and event-driven architectures.
- Preferred familiarity with AI/ML and GenAI security risks, risk metrics, application security mentoring, and regulated-environment partnerships.
- Security certifications such as CISSP, CSSLP, CCSP, or AWS Security Specialty are preferred, as is equivalent practical expertise.
Benefits
- Remote work available in the U.S. and Canada outside Quebec, with East/West Coast time-zone requirements.
- Most teams meet once or twice per quarter for 2–4 consecutive days of in-person collaboration.
- Base pay, bonus opportunities, annual equity grants, and an employee stock purchase plan are available.
- 401(k) or Group Retirement Savings Plan with company matching is provided.
- Medical, dental, vision, wellness resources, health savings account contributions, life insurance, and disability coverage are offered.
- Paid time off, sick leave, company holidays, and paid family and parental leave are provided.
- Family-centered benefits, an Employee Assistance Program, financial wellness resources, and annual wellness and productivity allowances are included.
- Team events, employee resource groups, and office perks such as catered lunches and stocked micro-kitchens are available.
About Upstart
Upstart (NASDAQ: UPST) is the leading AI lending marketplace, connecting millions of consumers to more than 100 banks and credit unions that leverage Upstart’s AI models and cloud applications to deliver superior credit products. With Upstart AI, lenders can approve more borrowers at lower rates while delivering the exceptional digital-first experience customers demand. More than 90% of loans are fully automated, with no human intervention by Upstart. Founded in 2012, Upstart’s platform includes personal loans, automotive retail and refinance loans, home equity lines of credit, and small-dollar “relief” loans. Upstart is based in San Mateo, California. Upstart Network, Inc. NMLS #936133 | All mortgage lending conducted by Upstart Mortgage, LLC. NMLS #2443873 nmlsconsumeraccess.org
