10 Sep
|
Jobcubby
|
Quebec City
10 Sep
Jobcubby
Quebec City
Every day, we bring creativity, experimentation, and advanced AI to reshape access to credit, helping millions move forward financially with clarity and confidence. As the leading AI lending marketplace, we partner with banks and credit unions to expand access to affordable credit through technology that’s both radically intelligent and deeply human. Our platform runs over one million predictions per borrower using more than 3,000 signals, powering smarter, fairer decisions for millions of customers.
We’re proudly digital-first, giving most Upstarters the flexibility to do their best work from wherever they thrive, alongside teammates across 80+ cities in the US and Canada. Digital-first doesn’t mean distant. And whether you choose to work primarily from home or collaborate in-person from one of our offices in Columbus, Austin, the Bay Area, or New York City (opening Summer 2026), you’ll have the support to work in the way that works best for you.
Upstart’s Application Security team enables product and engineering teams to build secure products without slowing innovation. We believe security should move at the speed of the business and that safety by design should be embedded throughout the software development lifecycle. Through engineering, automation, and close collaboration, we protect Upstart’s customer-facing products, internal applications, APIs, and AI-enabled systems while maintaining a positive developer experience.
As a Senior Application Security Engineer at Upstart, you will lead application security projects that reduce risk across our products and engineering ecosystem. You will partner with product, platform, data, infrastructure, and engineering teams to identify security risks, review designs, build preventative controls, and drive complex issues through remediation. This role is well suited for an experienced application security engineer who can lead substantial technical initiatives, navigate ambiguity, and deliver durable improvements that raise the security bar across the team and its partners.
Lead application security projects from planning through implementation, coordinating contributors and dependencies to deliver high-quality outcomes. Conduct threat modeling and security architecture reviews for complex customer-facing applications, APIs, distributed services, and AI/ML systems. Design and implement secure-by-default controls across the software development lifecycle,
including secure coding standards, API protections, automated testing, CI/CD safeguards, and secrets management.
Partner with engineering teams to identify systemic vulnerabilities, evaluate practical remediation options, and ensure high-risk issues are resolved effectively. Assess the security of AI-enabled products and developer workflows, including GenAI integrations, agentic systems, model inputs and outputs, sensitive-data handling, and access boundaries. Provide technical leadership during high-severity application security incidents, helping determine root causes and drive durable follow-up improvements.
Improve team effectiveness by contributing to design and code reviews, documenting reusable patterns, mentoring engineers, and helping strengthen application security practices across Upstart. 5+ years of experience in security engineering, software engineering, or a related technical role, including 2+ years focused on application or product security. ~ Experience leading security projects involving multiple contributors or partner teams. ~ Experience conducting threat modeling and security architecture reviews for complex production applications. ~ Experience developing production software or security automation in Java, Python, Ruby, Go, or a similar programming language. ~ Experience designing or implementing application security controls across the software development lifecycle, including several of the following: API security, secure coding standards, SAST, DAST, SCA, CI/CD security, or secrets management. ~ Experience securing cloud-native or distributed systems, including web applications, APIs, or microservices. ~ Experience investigating significant application security issues or incidents and translating findings into corrective engineering work.
Experience building reusable application security guardrails, platforms, or automation adopted by multiple engineering teams.
Experience securing contemporary frontend frameworks, REST or GraphQL APIs, microservices, and event-driven architectures.
Familiarity with security risks affecting AI/ML and GenAI-enabled systems, including prompt injection, insecure tool use, sensitive-data exposure, and model supply‑chain risks.
Experience using risk metrics or program data to prioritize work and measure improvements in application security outcomes.
Experience mentoring security or software engineers and raising quality through design and code reviews.
Experience partnering with Legal, Risk, Compliance, or Audit teams in a regulated environment. Security certifications such as CISSP, CSSLP, CCSP, AWS Security Specialty, or equivalent practical expertise.
Remote
Travel requirements As a digital first company, the majority of your work can be accomplished remotely. S or Canada (outside of Quebec) but are expected to spend high quality time in-person collaborating via regular onsites and in-person meetings.
United
States | Remote - Anticipated Base Salary Range United States | Remote - Anticipated Base Salary Range $Competitive compensation, including base pay, bonus opportunities, and annual equity grants that vest quarterly Retirement benefits to help you plan for the future, including a 401(k) or Group Retirement Savings Plan with a company match of $2 for every $1 contributed, up to $15,000 annually (USD in the US, CAD in Canada) Comprehensive health coverage designed to support you and your family, including medical, dental, vision, and wellness resources for US and supplemental health coverage for Canada.
Health Savings
Account contributions from Upstart for eligible plans (US only) Income protection benefits, including life insurance and disability coverage for added financial security Paid time off, sick leave, and company holidays, in line with local requirements Paid family and parental leave to support caregiving and major life moments (duration varies by country) Employee Assistance Program (EAP) offering mental health support and life-centered resources Annual wellness allowance to support your physical and emotional well-being and personal development, based on what matters most to you Connection and community through team events, all-company updates, and employee resource groups (ERGs) Onsite perks, including catered lunches and fully stocked micro-kitchens when working from one of our offices in the Bay Area, Austin, Columbus, and New York City (opening Summer 2026!)
📌 Virtual Senior Application Security Engineer (Quebec City)
🏢 Jobcubby
📍 Quebec City