Responsibilities
- Own security tooling and vulnerability management across SAST, dependency and container scanning, secret detection, and penetration testing.
- Lead security design reviews, threat modeling, and targeted manual code reviews for authentication, authorization, payments, and customer data systems.
- Identify and prevent multi-tenant authorization vulnerabilities across quoting, booking, and trip workflows.
- Strengthen AWS security through IAM, account boundary design, secrets management, workload protection, and comprehensive logging.
- Build secure defaults, reusable libraries, automation, developer guardrails, and a security champions practice.
- Set application security standards, define secure shipping criteria, make security decisions in design and code review, and drive vulnerability remediation.
Requirements
- 5+ years of experience in software engineering or security, including 3+ years in application or product security.
- Strong Java and/or TypeScript software engineering skills, including experience building production-grade security tooling, automation, libraries, and developer-facing solutions.
- Deep application security expertise in threat modeling, secure system design, authentication, authorization, access control, injection, SSRF, and manual code review.
- Hands-on AWS and cloud-native security experience, including IAM, multi-account architecture, containerized workloads, CI/CD security, and vulnerability management.
- Familiarity with SOC 2, PCI DSS, and GDPR is a plus.
- Ability to set security standards, prioritize risk, and drive remediation across engineering teams without direct authority.
Benefits
- Hybrid schedule in Austin, Texas, with in-office work Monday, Wednesday, and Friday; the company otherwise operates remote-first.
- Medical, dental, and vision insurance, mental health support, virtual care, gym discounts, and family-building benefits; U.S. employees receive 100% premium coverage.
- U.S. paid time off includes 15 days initially, increasing to 20 days after two years, plus 8 paid holidays; international policies vary.
- Company-paid life, short-term disability, and long-term disability insurance where available.
- U.S. 401(k) plan or region-specific international savings programs, plus long-term financial planning support.
- Mac or PC with a monitor, keyboard, and mouse.
- U.S.-based employees may reside in approved states, and the company also hires in Canada while expanding globally.
Tech Stack
Categories
About CharterUP
CharterUP is transforming the $30 billion group transportation industry with cutting-edge technology and innovative SaaS software, delivering an industry-leading experience for both customers and operators. Trusted by most Fortune 500 companies, our platform connects users to thousands of charter bus and minibus operators nationwide. In just 60 seconds, customers can access real-time availability, transparent pricing, and detailed vehicle options—whether organizing a corporate event, a company shuttle, or a wedding. By streamlining what was once a fragmented and stressful process, CharterUP brings transparency, accountability, and efficiency to an industry overdue for innovation. With CharterUP, group transportation is no longer a hassle but an elevated, reliable experience. Join us as we lead the future of group travel.
