# Senior Application Security Engineer

**Company:** [Upstart](https://hotfix.jobs/companies/upstart)
**Location:** Remote
**Role:** Security Engineering
**Salary:** $167k – $231k/yr
**Experience:** 5+ years
**Skills:** Threat Modeling, Security Architecture, Api Security, SAST, DAST, Sca, Ci/Cd Security, Secrets Management, Python, Java, Go, Cloud Security, Microservices, Genai Security, Vulnerability Management
**Posted:** 2026-09-04

> Leads application security initiatives across products, APIs, distributed systems, and AI-enabled applications. The role requires at least five years of security or software engineering experience, strong threat-modeling and architecture skills, and the ability to build security automation and drive remediation.

## Job Description

## Responsibilities
- Lead application security projects from planning through implementation, coordinating contributors and dependencies.
- Conduct threat modeling and security architecture reviews for customer-facing applications, APIs, distributed services, and AI/ML systems.
- Design and implement secure-by-default software development lifecycle controls, including secure coding standards, API protections, automated testing, CI/CD safeguards, and secrets management.
- Partner with engineering teams to identify systemic vulnerabilities, evaluate remediation options, and drive resolution of high-risk issues.
- Build services and automation for vulnerability detection, prioritization, validation, and prevention.
- Assess AI-enabled products and developer workflows, including GenAI integrations, agentic systems, model inputs and outputs, sensitive-data handling, and access boundaries.
- Provide technical leadership during high-severity application security incidents and drive durable follow-up improvements.
- Contribute to design and code reviews, document reusable patterns, mentor engineers, and improve application security practices.

## Requirements
- 5+ years of experience in security engineering, software engineering, or a related technical role, including 2+ years focused on application or product security.
- Experience leading security projects involving multiple contributors or partner teams.
- Experience with threat modeling and security architecture reviews for complex production applications.
- Experience developing production software or security automation in Java, Python, Ruby, Go, or a similar language.
- Experience implementing application security controls across the software development lifecycle, including API security, secure coding standards, SAST, DAST, SCA, CI/CD security, or secrets management.
- Experience identifying, validating, prioritizing, and remediating application vulnerabilities.
- Experience securing cloud-native or distributed systems, including web applications, APIs, or microservices.
- Experience investigating significant application security issues or incidents and translating findings into corrective engineering work.

## Nice-to-haves
- Experience building reusable application security guardrails, platforms, or automation adopted by multiple engineering teams.
- Experience securing modern frontend frameworks, REST or GraphQL APIs, microservices, and event-driven architectures.
- Familiarity with AI/ML and GenAI security risks, including prompt injection, insecure tool use, sensitive-data exposure, and model supply-chain risks.
- Experience using risk metrics or program data to prioritize work and measure security outcomes.
- Experience mentoring security or software engineers and improving quality through design and code reviews.
- Experience partnering with Legal, Risk, Compliance, or Audit teams in a regulated environment.
- Security certifications such as CISSP, CSSLP, CCSP, or AWS Security Specialty, or equivalent practical expertise.

## Compensation
- Anticipated base salary: $166,900–$230,900 USD.
- Additional compensation may include target bonuses, equity compensation, and benefits.

## Similar jobs

- [Senior Manager, Product Security Engineering](https://hotfix.jobs/jobs/8fa92a96-1812-406c-8ae5-324c42e42eea) - GitLab - Remote - $168k – $245k/yr
- [Research Systems Analyst](https://hotfix.jobs/jobs/eddd16d1-e2f4-4e7b-95b1-e8312679a35a) - Censys - Remote - $170k – $220k/yr
- [Senior Software Engineer, Security](https://hotfix.jobs/jobs/4fb0f2e8-3bb9-4076-9b7a-739b1f661bee) - Flex - Remote - $170k – $230k/yr
- [Compliance Engineer - Public Sector](https://hotfix.jobs/jobs/1664a48a-e3c2-4c6a-91dd-ffcd986273e3) - Wiz - Remote - $174k – $238k/yr
- [Senior Security Engineer](https://hotfix.jobs/jobs/b4bd3a90-c9c6-4983-b371-da5d17567c3a) - Jasper - Remote - $174k – $205k/yr

**Apply:** https://hotfix.jobs/jobs/77d9af5b-0584-4512-b0a0-dde5773d5334
**Canonical:** https://hotfix.jobs/jobs/77d9af5b-0584-4512-b0a0-dde5773d5334