Upstart
Senior Application Security Engineer
United States · Remote
Get past the screening software and onto a recruiter's desk
hirly rewrites your resume for this job — matching the keywords and skills in the posting, moving your most relevant experience to the top, and writing a cover letter to fit. About 30 seconds.
- Keywords matched to this posting
- Fit score before you apply
- Cover letter included
Matched against 2.4M live jobs from 200,000+ employers in 200+ countries.
Tailor my resume for this job →Apply from your AI assistant
Connect hirly to Claude and ask it to apply to this job. hirly tailors your resume, fills the employer’s form and asks before sending. ChatGPT: manual setup today.
Some employer sites stop an application at a CAPTCHA or sign-in and hand it back with a link. Applying needs a paid plan. Works with any assistant that supports MCP.
hirly's read of this role
- Role family
- Engineering
- Seniority
- Senior
- Stated salary
- $166,900 – $230,900 per year
- Country
- US
- Work mode
- Remote-friendly
- First seen by hirly
- 6 Sept 2026
Derived automatically from the posting. Upload your resume above to see how the role scores against it.
the posting
About Upstart
At Upstart, we’re united by a mission that matters: to radically reduce the cost and complexity of borrowing for all Americans. Every day, we bring creativity, experimentation, and advanced AI to reshape access to credit, helping millions move forward financially with clarity and confidence.
As the leading AI lending marketplace, we partner with banks and credit unions to expand access to affordable credit through technology that’s both radically intelligent and deeply human. Our platform runs over one million predictions per borrower using more than 3,000 signals, powering smarter, fairer decisions for millions of customers. But the numbers only hint at the impact. Every idea, every voice, and every contribution moves us closer to a world where credit never stands between people and their financial progress.
We’re proudly digital-first, giving most Upstarters the flexibility to do their best work from wherever they thrive, alongside teammates across 80+ cities in the US and Canada. Digital-first doesn’t mean distant. We’re intentional about in-person connection through team onsites, planning sessions, and moments that spark creativity and trust. And whether you choose to work primarily from home or collaborate in-person from one of our offices in Columbus, Austin, the Bay Area, or New York City, you’ll have the support to work in the way that works best for you.
If you’re energized by tackling meaningful problems, excited to innovate with purpose, and motivated by work that truly matters, we’d love to hear from you.
The Team:
Upstart’s Application Security team enables product and engineering teams to build secure products without slowing innovation. We believe security should move at the speed of the business and that safety by design should be embedded throughout the software development lifecycle. Through engineering, automation, and close collaboration, we protect Upstart’s customer-facing products, internal applications, APIs, and AI-enabled systems while maintaining a positive developer experience.
As a Senior Application Security Engineer at Upstart, you will lead application security projects that reduce risk across our products and engineering ecosystem. You will partner with product, platform, data, infrastructure, and engineering teams to identify security risks, review designs, build preventative controls, and drive complex issues through remediation. This role is well suited for an experienced application security engineer who can lead substantial technical initiatives, navigate ambiguity, and deliver durable improvements that raise the security bar across the team and its partners.
How you’ll make an impact
Lead application security projects from planning through implementation, coordinating contributors and dependencies to deliver high-quality outcomes.
Conduct threat modeling and security architecture reviews for complex customer-facing applications, APIs, distributed services, and AI/ML systems.
Design and implement secure-by-default controls across the software development lifecycle, including secure coding standards, API protections, automated testing, CI/CD safeguards, and secrets management.
Partner with engineering teams to identify systemic vulnerabilities, evaluate practical remediation options, and ensure high-risk issues are resolved effectively.
Build services and automation that improve vulnerability detection, prioritization, validation, and prevention while reducing friction for developers.
Assess the security of AI-enabled products and developer workflows, including GenAI integrations, agentic systems, model inputs and outputs, sensitive-data handling, and access boundaries.
Provide technical leadership during high-severity application security incidents, helping determine root causes and drive durable follow-up improvements.
Improve team effectiveness by contributing to design and code reviews, documenting reusable patterns, mentoring engineers, and helping strengthen application security practices across Upstart.
Minimum Qualifications
5+ years of experience in security engineering, software engineering, or a related technical role, including 2+ years focused on application or product security.
Experience leading security projects involving multiple contributors or partner teams.
Experience conducting threat modeling and security architecture reviews for complex production applications.
Experience developing production software or security automation in Java, Python, Ruby, Go, or a similar programming language.
Experience designing or implementing application security controls across the software development lifecycle, including several of the following: API security, secure coding standards, SAST, DAST, SCA, CI/CD security, or secrets management.
Experience identifying, validating, prioritizing, and driving remediation of application vulnerabilities.
Experience securing cloud-native or distributed systems, including web applications, APIs, or microservices.
Experience investigating significant application security issues or incidents and translating findings into corrective engineering work.
Preferred Qualifications
Experience building reusable application security guardrails, platforms, or automation adopted by multiple engineering teams.
Experience securing modern frontend frameworks, REST or GraphQL APIs, microservices, and event-driven architectures.
Familiarity with security risks affecting AI/ML and GenAI-enabled systems, including prompt injection, insecure tool use, sensitive-data exposure, and model supply-chain risks.
Experience using risk metrics or program data to prioritize work and measure improvements in application security outcomes.
Experience mentoring security or software engineers and raising quality through design and code reviews.
Experience partnering with Legal, Risk, Compliance, or Audit teams in a regulated environment.
Security certifications such as CISSP, CSSLP, CCSP, AWS Security Specialty, or equivalent practical expertise.
Position location This role is available in the following locations: Remote
Time zone requirements The team operates on the East/West coast time zones.
Travel requirements As a digital first company, the majority of your work can be accomplished remotely. The majority of our employees can live and work anywhere in the U.S or Canada (outside of Quebec) but are expected to spend high quality time in-person collaborating via regular onsites and in-person meetings. The onsite cadence varies depending on the team and role; most teams meet once or twice per quarter for 2-4 consecutive days at a time.
#LI-REMOTE
#LI-MidSenior
At Upstart, your base pay is one part of your total compensation package. The anticipated base salary for this position is expected to be within the below range. Your actual base pay will depend on your geographic location–with our “digital first” philosophy, Upstart uses compensation regions that vary depending on location. Individual pay is also determined by job-related skills, experience, and relevant education or training. Your recruiter can share more about the specific salary range for your preferred location during the hiring process.
In addition, Upstart provides employees with target bonuses, equity compensation, and generous benefits packages (including medical, dental, vision, and 401k).
United States | Remote - Anticipated Base Salary Range
$166,900 — $230,900 USD
What you'll love
At Upstart, our benefits are designed to support your health, financial well-being, family, and personal growth. Here’s what you can expect:
Competitive compensation, including base pay, bonus opportunities, and annual equity grants that vest quarterly
Retirement benefits to help you plan for the future, including a 401(k) or Group Retirement Savings Plan with a company match of $2 for every $1 contributed, up to $15,000 annually (USD in the US,
Similar jobs
- Sr. Security Engineer, Proactive SecurityAmazon · Arlington, Virginia, USAFirst seen today
- Sr. Security Engineer, Proactive SecurityAmazon · Arlington, Virginia, USAFirst seen today
- Senior Security Engineer - Sec OpsRelx · 6 LocationsFirst seen today
- Senior Security Engineer - IAMNcsecu · Operations - Raleigh - Creedmoor RdFirst seen today
- Product Security Engineer IVCollegeboard · Remote - USAFirst seen todayremote
Browse similar roles
Want this one?
Upload your resume and hirly rewrites it for this job and writes the cover letter — in about thirty seconds, before you sign up.
Tailor my resume for this job