Senior Application Security Engineer

Upstart

Confirmed live yesterday High trust
Remote

Quick summary

Work type
Remote
Location
Canada
Salary
$166,900–$230,900 / yr
Posted
6 days ago
Freshness
Confirmed live yesterday
Closes
Dec 8, 2026

Market check

Salary context

Above market

How this pay compares to similar roles

Similar $179k
This role $199k
$118k most similar roles pay here $243k

This role pays more than 70% of similar roles. Most pay $145,700–$212,625 — the shaded band above. At the midpoint, this role pays about $199k versus about $179k for comparable roles.

Based on 240 similar postings.

Employer

About Upstart

Upstart is an AI lending platform that partners with banks and credit unions to expand access to affordable credit using non-traditional variables.

Upstart currently has 73 open roles on FindRole.

Listed pay typically runs $166,900–$230,450 across 72 roles with salary data.

Most-posted roles

View all roles at Upstart

At a glance

TL;DR · Senior Application Security Engineer

As a Senior Application Security Engineer on the Application Security team, you will lead critical projects to reduce risk across the product and engineering ecosystem. You will partner with various teams to conduct threat modeling and security architecture reviews for complex customer-facing applications, APIs, distributed services, and AI/ML systems. Your daily work involves designing secure-by-default controls, building automation for vulnerability detection, and managing secrets and CI/CD safeguards. To succeed, you must be proficient in Java, Python, Ruby, or Go while implementing SAST, DAST, and SCA tools. You will also address specific risks involving GenAI integrations, such as prompt injection and sensitive data handling. This role focuses on securing the company's AI-enabled systems and infrastructure to ensure that security is embedded throughout the software development lifecycle without hindering innovation.

What you'll do

  • Lead application security projects from initial planning through implementation and coordination of various contributors.
  • Conduct threat modeling and security architecture reviews for customer-facing applications, APIs, and AI/ML systems.
  • Design and implement secure-by-default controls including coding standards, API protections, and CI/CD safeguards.
  • Build automation tools to improve vulnerability detection, prioritization, and validation while reducing developer friction.
  • Assess the security of AI-enabled products, focusing on GenAI integrations and sensitive data handling.
  • Provide technical leadership during high-severity incidents to determine root causes and drive lasting improvements.
  • Mentor engineers and contribute to design and code reviews to strengthen overall security practices.

What we're looking for

  • Must have 5+ years of experience in security engineering, software engineering, or a related technical role.
  • Must have at least 2 years of experience focused on application or product security.
  • Experience leading security projects involving multiple contributors or partner teams is required.
  • Experience conducting threat modeling and security architecture reviews for complex production applications is required.
  • Experience developing production software or security automation in Java, Python, Ruby, Go, or similar languages is required.
  • Experience implementing application security controls such as API security, SAST, DAST, SCA, CI/CD security, or secrets management is required.
  • Experience identifying, validating, prioritizing, and driving remediation of application vulnerabilities is required.
  • Experience securing cloud-native systems, including web applications, APIs, or microservices, is required.

More like this

Similar roles

Application Security Engineer

Opendoor

Toronto, Canada 85 days ago
Go Python TypeScript Ruby Terraform AWS GCP Azure Kubernetes GraphQL Apollo GitHub Advanced Security CodeQL Semgrep HackerOne Burp Suite Cloudflare WAF Claude OpenAI REST gRPC Threat Modeling
5+ yrs exp Hybrid

Application Security Engineer

State Street

Quincy, MA +4 13 days ago $120,000$202,500
AppSec DevSecOps SAST DAST SCA CI/CD Python Java .Net Node.js AWS Azure Kubernetes Terraform Ansible Infrastructure as Code Agile SDLC API Security Container Scanning
6+ yrs exp

Junior Application Security Engineer

AbbVie

Chicago, IL 9 days ago $84,500$162,000
Application Security SAST DAST IAST SCA ASPM CI/CD DevSecOps Java Node.js Python Snyk Endor Labs CSPM OWASP Top 10 CWE Containerization
5+ yrs exp

Application Security Engineer

AbbVie

Chicago, IL 9 days ago $84,500$162,000
Application Security SAST DAST IAST SCA ASPM CI/CD DevSecOps Java Node.js Python Snyk Endor Labs CSPM OWASP Top 10 CWE Containerization
5+ yrs exp

Senior Application Security Engineer

Brex

Remote 56 days ago $192,000$240,000
Application Security Penetration Testing SAST DAST Python Kotlin gRPC GraphQL Kubernetes AWS Threat Modeling Incident Response Scripting Distributed Systems
5+ yrs exp Remote

Senior Application Security Engineer

AbbVie

Chicago, IL 41 days ago $109,500$208,500
SAST DAST IAST SCA ASPM CI/CD DevSecOps Java Node.js Python AWS Azure Terraform CloudFormation OWASP Top 10 CWE CSPM Snyk Endor Labs
7+ yrs exp