Principal Application Security Engineer

Upstart Upstart · Fintech · Remote · InfoSec

This role focuses on application security engineering within a fintech company that utilizes AI. The Principal Application Security Engineer will define and drive the application security strategy, conduct security architecture reviews, lead threat modeling for various systems including ML/AI pipelines, and design security guardrails across the SDLC. The role requires strong leadership and collaboration skills to influence secure system development and reduce systemic risk.

What you'd actually do

  1. Define and drive Upstart’s application security strategy, aligning secure-by-design principles with business priorities, regulatory expectations, and our AI-driven product roadmap.
  2. Lead cross-functional security architecture reviews for critical initiatives, influencing engineering, platform, data, and infrastructure decisions to reduce systemic risk early in the SDLC.
  3. Establish and scale a robust threat modeling program for high-risk systems, including customer-facing applications, lending workflows, and ML/AI pipelines, translating findings into durable engineering standards and controls.
  4. Design and standardize application security guardrails across the SDLC, including secure coding practices, automated testing (SAST/DAST/SCA), CI/CD protections, and secrets management.
  5. Partner with Infrastructure and Cloud teams to strengthen the security posture of cloud-native and distributed systems, ensuring defense-in-depth across application and infrastructure layers.

Skills

Required

  • security engineering
  • application security
  • security architecture reviews
  • threat modeling
  • Java
  • Python
  • Ruby
  • secure coding practices
  • API Security
  • SAST/DAST/SCA
  • CI/CD security
  • secrets management
  • influential leadership
  • stakeholder management
  • information security initiatives and programs management
  • building services for security operations
  • advanced threat modeling techniques
  • risk assessment

Nice to have

  • cloud-native environments
  • distributed systems
  • scaling application security programs
  • metrics definition
  • maturity models
  • risk-based prioritization frameworks
  • frontend frameworks
  • APIs (REST/GraphQL)
  • microservices architectures
  • Legal, Risk, Compliance, and Audit partnership
  • regulated environments
  • CISSP
  • CCSP
  • AWS Security Specialty

What the JD emphasized

  • lead cross-functional and cross-organizational discussions and outcomes
  • deeply understand the business verticals and product needs and influence them
  • well-rounded technologist and security practitioner
  • Define and drive Upstart’s application security strategy
  • aligning secure-by-design principles with business priorities, regulatory expectations, and our AI-driven product roadmap
  • Lead cross-functional security architecture reviews
  • influencing engineering, platform, data, and infrastructure decisions
  • reduce systemic risk early in the SDLC
  • Establish and scale a robust threat modeling program
  • high-risk systems
  • translating findings into durable engineering standards and controls
  • Design and standardize application security guardrails
  • secure coding practices
  • automated testing (SAST/DAST/SCA)
  • CI/CD protections
  • secrets management
  • Partner with Infrastructure and Cloud teams
  • strengthen the security posture of cloud-native and distributed systems
  • defense-in-depth across application and infrastructure layers
  • Identify and reduce internal and external attack surface
  • automation and platform-level solutions
  • prioritizing long-term risk reduction over point-in-time remediation
  • Serve as a senior technical authority during high-severity incidents
  • driving root cause analysis and durable architectural improvements
  • Elevate security maturity across the organization
  • mentoring engineers
  • influencing leadership through clear risk metrics
  • fostering a culture where security enables innovation
  • 9+ years of experience in security engineering
  • at least 5 years focused on application security
  • Demonstrated experience leading security architecture reviews and threat modeling for complex, customer-facing production systems
  • Experience in Java, Python or Ruby development
  • Experience designing and implementing application security controls across the SDLC
  • secure coding standards
  • API Security
  • SAST/DAST/SCA
  • CI/CD security
  • secrets management
  • Demonstrable track record as an influential leader
  • delivering security solutions with multiple stakeholder groups
  • Experience managing multiple and simultaneous, significant information security initiatives and programs
  • Experience developing code and building services to enhance unique security operational needs
  • Experience with advanced threat modeling techniques and risk assessment
  • Experience building or scaling an application security program
  • defining metrics
  • maturity models
  • risk-based prioritization frameworks
  • Experience partnering with Legal, Risk, Compliance, and Audit teams to operationalize security controls in regulated environments