Principal Security Engineer, Data Security

Upstart · Fintech · Remote · InfoSec

Upstart is an AI lending marketplace that uses technology to expand access to credit. The Principal Security Engineer, Data Security will lead the design and execution of the company's data security program, architecting and building software solutions for data protection and governance. This role requires a strong software engineering background, experience leading security programs, and the ability to influence stakeholders. The company emphasizes its AI capabilities and its mission to reduce the cost and complexity of borrowing.

What you'd actually do

  1. Lead the design and execution of Upstart’s data security program, from early foundations through mature, scalable systems
  2. Architect and build software solutions (APIs, services, and internal tools) that enable effective data protection and governance
  3. Partner closely with Engineering, Analytics, Product, Legal, Risk, HR, and other stakeholders to secure sensitive data across diverse domains
  4. Establish clear goals, success metrics, and accountability for data security initiatives
  5. Drive adoption of least-privilege access models and modern data protection patterns across the organization

Skills

Required

  • Bachelor’s degree in Computer Science, Engineering, or Mathematics, or a related field (or its equivalent) + 8 years of experience
  • Extensive experience across enterprise and operational security domains, with deep focus on Data Security and Identity & Access Management
  • Experience owning or leading a Data Security, DLP (Data Loss Prevention), or DSPM (Data Security Posture Management) initiatives
  • Proven experience leading security programs that span multiple teams and functions
  • Strong software engineering background, with the ability to design and build production-quality systems (e.g., APIs, services, or internal web applications)
  • Experience launching new security capabilities or programs from 0 to 1 in complex environments
  • Deep understanding of least-privilege principles and practical experience applying them at scale
  • Excellent communication skills, with the ability to influence senior technical and non-technical stakeholders
  • Ability to navigate ambiguity, make sound tradeoffs, and independently drive meaningful change

Nice to have

  • Familiarity with modern data protection tooling such as endpoint DLP, data classification, or posture management platforms
  • Experience working with diverse data domains (e.g., analytics, reporting, business operations, or people data)
  • Contributions to the security community through talks, publications, open-source projects, or other industry involvement
  • Familiarity with compliance frameworks such as SOC 1, SOC 2, and SOX
  • Interest in long-term growth as a senior individual contributor, with openness to future people leadership

What the JD emphasized

  • Extensive experience across enterprise and operational security domains, with deep focus on Data Security and Identity & Access Management
  • Experience owning or leading a Data Security, DLP (Data Loss Prevention), or DSPM (Data Security Posture Management) initiatives
  • Strong software engineering background
  • Experience launching new security capabilities or programs from 0 to 1 in complex environments
  • Deep understanding of least-privilege principles and practical experience applying them at scale