Senior Security Engineering Manager, Product Security

Upstart Upstart · Fintech · Remote · InfoSec

Lead a team responsible for scaling security engineering practices across application security, infrastructure security, offensive security, and product security at Upstart, an AI lending marketplace. The role involves defining roadmaps, managing engineers, partnering with cross-functional leaders, and strengthening secure-by-design practices across the SDLC and cloud infrastructure.

What you'd actually do

  1. Define and lead the Security Engineering roadmap across application security, infrastructure security, offensive security, and product security, aligning priorities with Upstart’s business objectives, engineering strategy, regulatory expectations, and risk posture.
  2. Manage, coach, and develop a team of security engineers, ensuring clear goals, measurable impact, sustainable execution, effective operating rhythms, and growth opportunities for each team member.
  3. Partner with Engineering, Product, Infrastructure, Data, Risk, Compliance, and Audit leaders to identify high-priority security risks, align on pragmatic mitigations, and embed security requirements early in planning, design, development, and operations.
  4. Scale secure-by-design practices across the SDLC, including threat modeling, security architecture reviews, secure coding practices, automated security testing, vulnerability management, API security, CI/CD protections, secrets management, and developer security enablement.
  5. Strengthen infrastructure and cloud security by partnering with Infrastructure and Platform teams on secure architecture, identity and access controls, Kubernetes and container security, cloud-native security controls, and defense-in-depth across application and infrastructure layers.

Skills

Required

  • Security engineering
  • Software engineering
  • Infrastructure engineering
  • Offensive security
  • Product security
  • Team management
  • Leadership
  • Roadmap definition
  • SDLC security
  • Threat modeling
  • Security architecture reviews
  • Secure coding practices
  • Automated security testing
  • Vulnerability management
  • API security
  • CI/CD security
  • Secrets management
  • Cloud security
  • Identity and access controls
  • Kubernetes security
  • Container security
  • Attack surface management
  • Penetration testing coordination
  • Bug bounty management
  • Security metrics and reporting
  • Incident response coordination
  • Risk management
  • Compliance

Nice to have

  • Experience in fintech security
  • Experience with AI/ML security concerns

What the JD emphasized

  • security engineering roadmap
  • application security
  • infrastructure security
  • offensive security
  • product security
  • secure-by-design practices
  • customer-facing products
  • cloud-native services
  • internal platforms
  • APIs
  • AI-driven product workflows
  • secure architecture
  • identity and access controls
  • Kubernetes and container security
  • cloud-native security controls
  • attack surface management
  • adversarial testing
  • security validation
  • penetration testing coordination
  • bug bounty intake
  • security requirements
  • customer-impacting risks
  • scalable controls
  • high-trust product experiences
  • Security Engineering metrics
  • operating models
  • reporting
  • risk posture
  • remediation progress
  • recurring patterns
  • program health
  • effectiveness of security investments
  • high-severity security issues
  • technical investigation
  • stakeholder communication
  • root cause analysis
  • remediation tracking
  • durable improvements
  • prevent repeat issues
  • security enables innovation
  • trusted partnerships
  • mentoring engineering leaders
  • practical controls
  • improve safety
  • 8+ years of experience in security engineering, software engineering, infrastructure engineering, offensive security, product security, or related technical security roles.
  • 3+ years of experience managing, leading, or formally developing security engineers or technical teams.
  • Experience leading security engineering programs in at least two of the following domains: application security, infras