Principal Application Security Engineer at Upstart

**Who this is for** This role is for a seasoned Principal Application Security Engineer passionate about progressive security approaches. You will lead cross-fu

Work type: remote

Location: United States | Remote

Salary: $190,600 – $263,900/yr

Type: Full-time

Summary

**Who this is for** This role is for a seasoned Principal Application Security Engineer passionate about progressive security approaches. You will lead cross-functional discussions and outcomes related to threat modeling, application, and infrastructure security, influencing teams to build highly secure systems. **Key highlights** You will directly shape the strategic security posture and roadmap for Upstart, acting as a senior technical authority. This involves defining and driving the application security strategy, leading security architecture reviews, and scaling a robust threat modeling program. **You might be a good fit if you...** - Have experience defining and driving application security strategies and roadmaps. - Can lead security architecture reviews for critical initiatives and influence engineering decisions. - Are skilled in establishing and scaling threat modeling programs. - Possess expertise in designing and standardizing application security guardrails across the SDLC.

Job Description

About Upstart

At Upstart, we’re united by a mission that matters: to radically reduce the cost and complexity of borrowing for all Americans. Every day, we bring creativity, experimentation, and advanced AI to reshape access to credit, helping millions move forward financially with clarity and confidence.

As the leading AI lending marketplace, we partner with banks and credit unions to expand access to affordable credit through technology that’s both radically intelligent and deeply human. Our platform runs over one million predictions per borrower using more than 1,800 signals, powering smarter, fairer decisions for millions of customers. But the numbers only hint at the impact. Every idea, every voice, and every contribution moves us closer to a world where credit never stands between people and their financial progress.

We’re proudly digital-first, giving most Upstarters the flexibility to do their best work from wherever they thrive, alongside teammates across 80+ cities in the US and Canada. Digital-first doesn’t mean distant. We’re intentional about in-person connection through team onsites, planning sessions, and moments that spark creativity and trust. And whether you choose to work primarily from home or collaborate in-person from one of our offices in Columbus, Austin, the Bay Area, or New York City (opening Summer 2026), you’ll have the support to work in the way that works best for you.

If you’re energized by tackling meaningful problems, excited to innovate with purpose, and motivated by work that truly matters, we’d love to hear from you.

The Team:

Upstart’s Application Security team ispassionate in bringing progressive approaches in securing our products. We believe that security should empower innovation, move at the speed of business, and have safety by design as core principles. Our team’s mission is to ensure the safety of our core product platforms, enterprise, and manage threats to Upstart. We approach our efforts through automation, strong collaboration with our partner teams, and maintaining a positive experience for Upstarters..

As the Principal Application Security Engineer at Upstart, you will be expected to lead cross-functional and cross-organizational discussions and outcomes around threat modeling, application and infrastructure security.You will be expected to deeply understand the business verticals and product needs and influence them to build highly secure systems and platforms. You will have a direct hand in shaping the strategic security posture and roadmap for Upstart and should be a well-rounded technologist and security practitioner.

How you’ll make an impact:









What we’re looking for:Minimum requirements:









Preferred qualifications:






Position Location -This role is available in the following locations: San Mateo, Columbus, Austin, Remote

Time Zone Requirements - This team operates on the East/West Coast time zones.

Travel Requirements - This team has regular on-site collaboration sessions. These occur 3-4 days per Quarter at one of our office locations or some other off-site location determined by your team/manager. If you need to travel to make these meetups, Upstart will cover all travel related expenses.

#LI-REMOTE

#LI-MidSenior

At Upstart, your base pay is one part of your total compensation package. The anticipated base salary for this position is expected to be within the below range. Your actual base pay will depend on your geographic location–with our “digital first” philosophy, Upstart uses compensation regions that vary depending on location. Individual pay is also determined by job-related skills, experience, and relevant education or training. Your recruiter can share more about the specific salary range for your preferred location during the hiring process.

In addition, Upstart provides employees with target bonuses, equity compensation, and generous benefits packages (including medical, dental, vision, and 401k).

United States | Remote - Anticipated Base Salary Range
$190,600—$263,900 USD

What you'll love

At Upstart, our benefits are designed to support your health, financial well-being, family, and personal growth. Here’s what you can expect:
















Upstart is a proud Equal Opportunity Employer. Just as we are dedicated to improving access to affordable credit for all, we are committed to inclusive and fair hiring practices.

If you require reasonable accommodation in completing an application, interviewing, completing any pre-employment testing, or otherwise participating in the employee selection process, please email[candidate_accommodations@upstart.com](mailto:candidate_accommodations@upstart.com)

[https://www.upstart.com/candidate_privacy_policy](https://www.upstart.com/candidate_privacy_policy)

View this job on nocollar jobs