> Markdown version of [/jobs/ext/3399527-application-security-engineer](https://www.wearedevelopers.com/jobs/ext/3399527-application-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Application Security Engineer - **Company:** Upstart - **Location:** United States (Remote available) - **Experience:** Expert - **Salary:** $166,900.0 - $230,900.0 - **Contract:** Temporary contract - **Skills:** Java (Programming Language), Application Programming Interfaces (APIs), Artificial Intelligence, Amazon Web Services, Automation of Tests, Cloud Engineering, Cyber Security, Continuous Integration, Distributed Systems, Python (Programming Language), Key Management, Ruby, Secure Coding, Software Engineering, Software Technical Review, Web Applications, Web Application Frameworks, Data Processing, Software Security, Event Driven Architecture, Graphql, Machine Learning Operations, Security Orchestration, Automation & Response, Static Application Security Testing, Vulnerability Analysis, Golang, Programming Languages, Microservices, Dynamic Application Security Testing - **Published:** September 3, 2026 - **Apply:** https://startup.jobs/senior-application-security-engineer-upstart-9928002 ## About the Role If you're energized by tackling meaningful problems, excited to innovate with purpose, and motivated by work that truly matters, we'd love to hear from you., * 5+ years of experience in security engineering, software engineering, or a related technical role, including 2+ years focused on application or product security. * Experience leading security projects involving multiple contributors or partner teams. * Experience conducting threat modeling and security architecture reviews for complex production applications. * Experience developing production software or security automation in Java, Python, Ruby, Go, or a similar programming language. * Experience designing or implementing application security controls across the software development lifecycle, including several of the following: API security, secure coding standards, SAST, DAST, SCA, CI/CD security, or secrets management. * Experience identifying, validating, prioritizing, and driving remediation of application vulnerabilities. * Experience securing cloud-native or distributed systems, including web applications, APIs, or microservices. * Experience investigating significant application security issues or incidents and translating findings into corrective engineering work., * Experience building reusable application security guardrails, platforms, or automation adopted by multiple engineering teams. * Experience securing modern frontend frameworks, REST or GraphQL APIs, microservices, and event-driven architectures. * Familiarity with security risks affecting AI/ML and GenAI-enabled systems, including prompt injection, insecure tool use, sensitive-data exposure, and model supply-chain risks. * Experience using risk metrics or program data to prioritize work and measure improvements in application security outcomes. * Experience mentoring security or software engineers and raising quality through design and code reviews. * Experience partnering with Legal, Risk, Compliance, or Audit teams in a regulated environment. * Security certifications such as CISSP, CSSLP, CCSP, AWS Security Specialty, or equivalent practical expertise. ## Description Upstart's Application Security team enables product and engineering teams to build secure products without slowing innovation. We believe security should move at the speed of the business and that safety by design should be embedded throughout the software development lifecycle. Through engineering, automation, and close collaboration, we protect Upstart's customer-facing products, internal applications, APIs, and AI-enabled systems while maintaining a positive developer experience. As a Senior Application Security Engineer at Upstart, you will lead application security projects that reduce risk across our products and engineering ecosystem. You will partner with product, platform, data, infrastructure, and engineering teams to identify security risks, review designs, build preventative controls, and drive complex issues through remediation. This role is well suited for an experienced application security engineer who can lead substantial technical initiatives, navigate ambiguity, and deliver durable improvements that raise the security bar across the team and its partners. How you'll make an impact * Lead application security projects from planning through implementation, coordinating contributors and dependencies to deliver high-quality outcomes. * Conduct threat modeling and security architecture reviews for complex customer-facing applications, APIs, distributed services, and AI/ML systems. * Design and implement secure-by-default controls across the software development lifecycle, including secure coding standards, API protections, automated testing, CI/CD safeguards, and secrets management. * Partner with engineering teams to identify systemic vulnerabilities, evaluate practical remediation options, and ensure high-risk issues are resolved effectively. * Build services and automation that improve vulnerability detection, prioritization, validation, and prevention while reducing friction for developers. * Assess the security of AI-enabled products and developer workflows, including GenAI integrations, agentic systems, model inputs and outputs, sensitive-data handling, and access boundaries. * Provide technical leadership during high-severity application security incidents, helping determine root causes and drive durable follow-up improvements. * Improve team effectiveness by contributing to design and code reviews, documenting reusable patterns, mentoring engineers, and helping strengthen application security practices across Upstart. ## Related Videos - [Coffee with Developers: David Heinemeier Hansson](https://www.wearedevelopers.com/videos/875-coffee-with-developers-david-heinemeier-hansson) - [Go with the Flow: Stop the Leaks Before Your Memory's a Waterfall!](https://www.wearedevelopers.com/videos/100073-go-with-the-flow-stop-the-leaks-before-your-memory-s-a-waterfall) - [Putting the Graph In GraphQL With The Neo4j GraphQL Library](https://www.wearedevelopers.com/videos/257-putting-the-graph-in-graphql-with-the-neo4j-graphql-library) - [What The Hack is Web App Sec?](https://www.wearedevelopers.com/videos/1343-what-the-hack-is-web-app-sec) - [Coroutine explained yet again 60 years later](https://www.wearedevelopers.com/videos/690-coroutine-explained-yet-again-60-years-later) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers) - [Best Countries for Software Engineers](https://www.wearedevelopers.com/magazine/267-best-countries-for-software-engineers)