Principal Application Security Engineer

Upstart

San Mateo, US
Base: $190,600 - $263,900 usd; bonus/equity: targe...
**
Application security strategy
Threat modeling program
Secure coding practices
** Upstart is seeking a Principal Application Security Engineer to lead application security efforts, focusing on threat modeling and security architecture within their AI-driven lending marketplace. The ideal candidate will have extensive experience in security engineering, particularly in application security, and a strong ability to influence cross-functional teams. **

Job Summary

  • Define and drive Upstart’s application security strategy, aligning secure-by-design principles with business priorities, regulatory expectations, and our AI-driven product roadmap.
  • Establish and scale a robust threat modeling program for high-risk systems, including customer-facing applications, lending workflows, and ML/AI pipelines, translating findings into durable engineering standards and controls.
  • Elevate security maturity across the organization by mentoring engineers, influencing leadership through clear risk metrics, and fostering a culture where security enables innovation.

Matching Summary

Match Score: 75

** Upstart is seeking a Principal Application Security Engineer to lead application security efforts, focusing on threat modeling and security architecture within their AI-driven lending marketplace. The ideal candidate will have extensive experience in security engineering, particularly in application security, and a strong ability to influence cross-functional teams. **

Salary

Base: $190,600 - $263,900 USD; Bonus/Equity: target bonuses, equity compensation; Benefits: medical, dental, vision, 401k

Skills & Requirements

Must-have

  • Application security strategy
  • Threat modeling program
  • Secure coding practices
  • CI/CD security
  • Cloud-native systems security

Nice-to-have

  • Security enables innovation
  • Positive experience for Upstarters
  • AI/ML pipelines security

Key Requirements

  • 9+ years of experience in security engineering
  • 5 years focused on application security
  • Experience in Java, Python or Ruby development
  • Experience with advanced threat modeling techniques
  • 10+ years spanning multiple security domains
  • Security certifications

Work Rights

Not specified

Tailored Resume

Cover Letter