
Opportunity at
UpsideStaff Application Security Engineer
Upside operates a commerce platform that connects consumers with brick-and-mortar businesses to provide cashback value and profitable customer acquisition. Billions of dollars in transactions flow through…
Career Tools
About This Role
Upside operates a commerce platform that connects consumers with brick-and-mortar businesses to provide cashback value and profitable customer acquisition. Billions of dollars in transactions flow through the system annually. The company is currently seeking a Staff Application Security Engineer to take charge of the application security program and scale secure software delivery across web, mobile, and cloud environments. This position reports directly to the Product Security Manager and involves close…
Job Description
Upside operates a commerce platform that connects consumers with brick-and-mortar businesses to provide cashback value and profitable customer acquisition. Billions of dollars in transactions flow through the system annually. The company is currently seeking a Staff Application Security Engineer to take charge of the application security program and scale secure software delivery across web, mobile, and cloud environments.
This position reports directly to the Product Security Manager and involves close collaboration with Engineering and Cloud Security groups. The person in this role will lead threat modeling, manage vulnerabilities, build developer-focused guardrails, and secure agentic artificial intelligence workflows. It is an ideal fit for professionals with a strong background in product engineering who focus on practical risk reduction and automation.
The employer maintains an on-site working environment and offers a comprehensive benefits package, including health coverage starting on the first day, equity options, flexible time off, and retirement planning. Equal opportunity employment practices are followed, ensuring that all applicants are evaluated without regard to protected characteristics.
Responsibilities
- Manage the application security program, security standards, vulnerability management pipeline, and engineering guardrails
- Triage and tune findings from code reviews, scanning, and penetration testing while partnering with engineering groups to verify fixes
- Conduct application security reviews and threat models for backend, web, and mobile systems
- Review and threat model agentic AI workflows while defining security controls for tool usage, data access, and execution
- Develop automation tools to triage and prioritize findings with service context to generate actionable remediation guidance
- Build repository baselines, GitHub required checks, secure-by-default AWS patterns, templates, and a security champions program
Requirements
- Have at least six years of professional experience in application security, product security, or secure software engineering with relevant security ownership
- Demonstrate strong Python code review capabilities, including the ability to inspect and explain AWS Lambda functions
- Show a proven history of implementing security improvements that tangibly lower risk across teams
- Possess experience with threat modeling and secure design reviews prior to shipping
- Use artificial intelligence regularly in practical security workflows
- Bring working knowledge of AWS security principles and GitHub Actions CI/CD security
Core Skills
Benefits
- Medical, dental, and vision insurance starting on day one
- Equity in the form of Incentive Stock Options
- Participation in a 401(k) retirement program
- Paid parental leave and family planning programs
- Wellness and physical fitness memberships
- Mental and emotional health support services
- Unlimited paid time off, 10 paid federal holidays, and an annual week-long winter break
- Lunch reimbursement for employees working on-site
- Access to Employee Resource Groups
- Stipend for learning and development
Frequently Asked Questions
Answers are based only on the employer’s listing; where it doesn’t say, neither do we.
What is the salary for the Staff Application Security Engineer role?
The salary ranges from USD 235,000 to 245,000 per year.
Is this position remote?
No, the job posting specifies an on-site work environment.
What is the employment type?
The position is full-time.
Where is the position located?
The exact location is not stated in the job posting.
Sample Interview Questions
AI-generated questions tailored to this specific role — a preview of the full practice set.


