You and the process

With a person
Anna, in-house recruiter
9 years hiring engineers
30 minutes with a real recruiter
They read your CV with you, on a call, and say where the offers are being lost.
Didn’t find what you were looking for? Tell us what to build
Be the first to open itNo views yet
Company hidden

Senior Application Security Engineer

  • Remote
  • 6+ years

Salary

$165,000 - 235,000/ year

AI summary

For members

The whole posting in a few lines. Sign up to read it here and on every role you open.

Sign Up to Read

Description

About the company

At the company, we’re united by a mission that matters: to radically reduce the cost and complexity of borrowing for all Americans. Every day, we bring creativity, experimentation, and advanced AI to reshape access to credit, helping millions move forward financially with clarity and confidence.

As the leading AI lending marketplace, we partner with banks and credit unions to expand access to affordable credit through technology that’s both radically intelligent and deeply human. Our platform runs over one million predictions per borrower using more than 3,000 signals, powering smarter, fairer decisions for millions of customers. But the numbers only hint at the impact. Every idea, every voice, and every contribution moves us closer to a world where credit never stands between people and their financial progress.

We’re proudly digital-first, giving most Upstarters the flexibility to do their best work from wherever they thrive, alongside teammates across 80+ cities in the US and Canada. Digital-first doesn’t mean distant. We’re intentional about in-person connection through team onsites, planning sessions, and moments that spark creativity and trust. And whether you choose to work primarily from home or collaborate in-person from one of our offices in Columbus, Austin, the Bay Area, or New York City, you’ll have the support to work in the way that works best for you.

If you’re energized by tackling meaningful problems, excited to innovate with purpose, and motivated by work that truly matters, we’d love to hear from you.

The Team:

The company’s Application Security team enables product and engineering teams to build secure products without slowing innovation. We believe security should move at the speed of the business and that safety by design should be embedded throughout the software development lifecycle. Through engineering, automation, and close collaboration, we protect the company’s customer-facing products, internal applications, APIs, and AI-enabled systems while maintaining a positive developer experience.

As a Senior Application Security Engineer at the company, you will lead application security projects that reduce risk across our products and engineering ecosystem. You will partner with product, platform, data, infrastructure, and engineering teams to identify security risks, review designs, build preventative controls, and drive complex issues through remediation. This role is well suited for an experienced application security engineer who can lead substantial technical initiatives, navigate ambiguity, and deliver durable improvements that raise the security bar across the team and its partners.

How you’ll make an impact

Lead application security projects from planning through implementation, coordinating contributors and dependencies to deliver high-quality outcomes.

Conduct threat modeling and security architecture reviews for complex customer-facing applications, APIs, distributed services, and AI/ML systems.

Design and implement secure-by-default controls across the software development lifecycle, including secure coding standards, API protections, automated testing, CI/CD safeguards, and secrets management.

Partner with engineering teams to identify systemic vulnerabilities, evaluate practical remediation options, and ensure high-risk issues are resolved effectively.

Build services and automation that improve vulnerability detection, prioritization, validation, and prevention while reducing friction for developers.

Assess the security of AI-enabled products and developer workflows, including GenAI integrations, agentic systems, model inputs and outputs, sensitive-data handling, and access boundaries.

Provide technical leadership during high-severity application security incidents, helping determine root causes and drive durable follow-up improvements.

Improve team effectiveness by contributing to design and code reviews, documenting reusable patterns, mentoring engineers, and helping strengthen application security practices across the company.

Minimum Qualifications

5+ years of experience in security engineering, software engineering, or a related technical role, including 2+ years focused on application or product security.

Experience leading security projects involving multiple contributors or partner teams.

Experience conducting threat modeling and security architecture reviews for complex production applications.

Experience developing production software or security automation in Java, Python, Ruby, Go, or a similar programming language.

Experience designing or implementing application security controls across the software development lifecycle, including several of the following: API security, secure coding standards, SAST, DAST, SCA, CI/CD security, or secrets management.

Experience identifying, validating, prioritizing, and driving remediation of application vulnerabilities.

Experience securing cloud-native or distributed systems, including web applications, APIs, or microservices.

Experience investigating significant application security issues or incidents and translating findings into corrective engineering work.

Preferred Qualifications

Experience building reusable application security guardrails, platforms, or automation adopted by multiple engineering teams.

Experience securing modern frontend frameworks, REST or GraphQL APIs, microservices, and event-driven architectures.

Familiarity with security risks affecting AI/ML and GenAI-enabled systems, including prompt injection, insecure tool use, sensitive-data exposure, and model supply-chain risks.

Experience using risk metrics or program data to prioritize work and measure improvements in application security outcomes.

Experience mentoring security or software engineers and raising quality through design and code reviews.

Experience partnering with Legal, Risk, Compliance, or Audit teams in a regulated environment.

Security certifications such as CISSP, CSSLP, CCSP, AWS Security Specialty, or equivalent practical expertise.

Position location This role is available in the following locations: Remote

Time zone requirements The team operates on the East/West coast time zones.

Travel requirements As a digital first company, the majority of your work can be accomplished remotely. The majority of our employees can live and work anywhere in the U.S or Canada (outside of Quebec) but are expected to spend high quality time in-person collaborating via regular onsites and in-person meetings. The onsite cadence varies depending on the team and role; most teams meet once or twice per quarter for 2-4 consecutive days at a time.

LI-REMOTE

LI-MidSenior

At the company, your base pay is one part of your total compensation package. The anticipated base salary for this position is expected to be within the below range. Your actual base pay will depend on your geographic location–with our “digital first” philosophy, the company uses compensation regions that vary depending on location. Individual pay is also determined by job-related skills, experience, and relevant education or training. Your recruiter can share more about the specific salary range for your preferred location during the hiring process.

In addition, the company provides employees with target bonuses, equity compensation, and generous benefits packages (including medical, dental, vision, and 401k).

$166,900 - $230,900 USD

What you'll love

At the company, our benefits are designed to support your health, financial well-being, family, and personal growth. Here’s what you can expect:

Competitive compensation, including base pay, bonus opportunities, and annual equity grants that vest quarterly

Retirement benefits to help you plan for the future, including a 401(k) or Group Retirement Savings Plan with a company match of $2 for every $1 contributed, up to $15,000 annually (USD in the US, CAD in Canada)

Employee Stock Purchase Plan (ESPP) with discounted stock purchase options for eligible employees (US only)

Comprehensive health coverage designed to support you and your family, including medical, dental, vision, and wellness resources for US and supplemental health coverage for Canada.

Health Savings Account contributions from the company for eligible plans (US only)

Income protection benefits, including life insurance and disability coverage for added financial security

Paid time off, sick leave, and company holidays, in line with local requirements

Paid family and parental leave to support caregiving and major life moments (duration varies by country)

Family-centered benefits to support fertility, parenthood, and caregiving needs

Employee Assistance Program (EAP) offering mental health support and life-centered resources

Financial wellness resources, including access to financial planning tools and a financial concierge service (US Only)

Annual wellness allowance to support your physical and emotional well-being and personal development, based on what matters most to you

Annual productivity allowance to invest in relevant tools and resources you need to do your best work, no matter where you work from

Connection and community through team events, all-company updates, and employee resource groups (ERGs)

Onsite perks, including catered lunches and fully stocked micro-kitchens when working from one of our offices in the Bay Area, Austin, Columbus, and New York City

For roles based in Canada, please note that we are not currently able to hire in Quebec.

The company is a proud Equal Opportunity Employer. Just as we are dedicated to improving access to affordable credit for all, we are committed to inclusive and fair hiring practices.

Where you’d work

Fully remote

You can work from

  • United States

About the company

Company hidden

  • Industry: FinTech

Your chances

Still hiring, moderately crowded, and a person reads your message.

  • 19 checks run
  • 7 good signs
  • 2 red flags

Still hiring?

13 checks

Actively hiring

In its favour5

  • Still on the company's own careers site, checked 4 h agoModerate evidence
  • The company opened 6 roles and closed 7 in the last 2 weeks: hiring is movingModerate evidence
  • Specific about the basics: pay, place, level, stack and contract all statedSlight evidence
2 moreFewer
  • States its salarySlight evidence
  • A hiring contact is attached to itSlight evidence

Against it1

  • Posted 4 weeks agoSlight evidence

How crowded?

6 checks

Moderate

In its favour2

  • You can message the hiring contact and skip the queueModerate evidence
  • Senior level: far fewer people qualifySlight evidence

Against it1

  • Open for 4 weeks: applications have had time to pile upModerate evidence
12 roles like this are in their Early WindowFound before the big job boards, while the crowd hasn’t arrived

Fits Me

How well does this role fit you?

Answer a few questions or drop your CV, and every role gets a fit score with the reasons, this one first.

  • Your field
  • Level
  • Stack
  • Work model
  • Salary floor
  • Must-haves
Details13 facts · Role, Location, Compensation, Employment, Company
Tech stack
  • Python
  • Go
  • AWS
  • CI/CD
Seniority
Senior
Type
Full-time
Equity
Equity offered
Industry
FinTech
Specialty
Security
Show 7 more factsShow less

Role

Category
DevOps & Infrastructure
Specialty
Security
Seniority
Senior
Experience
5+ years
Tech stack
  • Python
  • Go
  • AWS
  • CI/CD

Location

Work model
Remote
Region
United States
Remote from
  • United States

Compensation

Salary
$165,000 - 235,000 / year
Pay period
Annual
Equity
Equity offered

Employment

Type
Full-time

Company

Industry
FinTech

Something wrong with this vacancy?

Similar vacancies

  • Early Window: Be the first to open itNo views yetCloses in
    Company hidden

    Security Engineer, New Grad

    Salary by agreement

    • Office · Dublin
    • Junior
  • Early Window: Be the first to open itNo views yetCloses in
    Company hidden

    Senior Security Operations Analyst

    Salary by agreement

    • Hybrid · Wellington, Auckland
    • Senior
  • Early Window: Be the first to open itNo views yetCloses in
    Company hidden

    Platform Security Engineer

    £90,000 - 160,000 / year

    • Hybrid · London
    • Mid-Level
  • Early Window: Be the first to open itNo views yetCloses in
    Company hidden

    Security Engineer

    $275,000 - 345,000 / year

    • Office · London

Share this vacancy

What's wrong with it?

The employer never sees who reported.

Reason