Back to positions

[Remote] Senior Security Engineering Manager, Product Security

Remote role Full-time Open position

Note: The job is a remote job and is open to candidates in USA. Upstart is a leading AI lending marketplace dedicated to reducing the cost and complexity of borrowing for all Americans. As the Senior Security Engineering Manager for Product Security, you will lead a team focused on scaling security engineering practices and improving the security posture of Upstart's products and infrastructure through collaboration with various stakeholders.

Responsibilities

  • Define and lead the Security Engineering roadmap across application security, infrastructure security, offensive security, and product security, aligning priorities with Upstart’s business objectives, engineering strategy, regulatory expectations, and risk posture
  • Manage, coach, and develop a team of security engineers, ensuring clear goals, measurable impact, sustainable execution, effective operating rhythms, and growth opportunities for each team member
  • Partner with Engineering, Product, Infrastructure, Data, Risk, Compliance, and Audit leaders to identify high-priority security risks, align on pragmatic mitigations, and embed security requirements early in planning, design, development, and operations
  • Scale secure-by-design practices across the SDLC, including threat modeling, security architecture reviews, secure coding practices, automated security testing, vulnerability management, API security, CI/CD protections, secrets management, and developer security enablement
  • Strengthen infrastructure and cloud security by partnering with Infrastructure and Platform teams on secure architecture, identity and access controls, Kubernetes and container security, cloud-native security controls, and defense-in-depth across application and infrastructure layers
  • Build and mature offensive security capabilities, including attack surface management, adversarial testing, security validation, penetration testing coordination, bug bounty intake, and prioritization of findings into durable engineering improvements
  • Improve product security outcomes by partnering with Product and Engineering teams to identify abuse cases, security requirements, customer-impacting risks, and scalable controls for high-trust product experiences
  • Drive consistent execution across cross-functional initiatives by setting priorities, clarifying ownership, communicating tradeoffs, and ensuring high-impact security work is delivered with quality and urgency
  • Establish and improve Security Engineering metrics, operating models, and reporting so leaders can understand risk posture, remediation progress, recurring patterns, program health, and the effectiveness of security investments
  • Support response to high-severity security issues by coordinating technical investigation, stakeholder communication, root cause analysis, remediation tracking, and durable improvements that prevent repeat issues
  • Foster a culture where security enables innovation by building trusted partnerships, mentoring engineering leaders, and helping teams adopt practical controls that improve safety without unnecessary friction

Skills

  • 8+ years of experience in security engineering, software engineering, infrastructure engineering, offensive security, product security, or related technical security roles
  • 3+ years of experience managing, leading, or formally developing security engineers or technical teams
  • Experience leading security engineering programs in at least two of the following domains: application security, infrastructure security, offensive security, product security, cloud security, or secure SDLC
  • Experience partnering with Engineering, Product, Infrastructure, Risk, Compliance, or Audit stakeholders to deliver cross-functional security initiatives
  • Experience with modern application and infrastructure architectures, including APIs, web applications, cloud-native services, CI/CD pipelines, identity and access controls, and common vulnerability classes
  • Experience defining roadmaps, priorities, metrics, and operating processes for security programs with cross-functional dependencies
  • Experience building or scaling a security engineering function, including team operating models, roadmap planning, prioritization frameworks, metrics, and executive-level reporting
  • Experience managing security work in a regulated environment, financial technology company, or organization with high security, privacy, or compliance requirements
  • Knowledge of AWS, Kubernetes, containers, CI/CD security, infrastructure-as-code security, identity and access management, vulnerability management, API security, and modern application security testing practices
  • Experience implementing or scaling security tooling such as SAST, DAST, SCA, IaC scanning, secrets detection, attack surface management, bug bounty intake, penetration testing workflows, vulnerability management platforms, or developer security guardrails
  • Familiarity with security considerations for AI/ML systems, data-intensive applications, lending or financial technology platforms, or other high-trust customer-facing products
  • Ability to communicate technical risk, tradeoffs, and recommendations clearly to technical, non-technical, and senior leadership audiences
  • Experience partnering with Engineering, Product, Infrastructure, Legal, Risk, Compliance, and Audit teams to deliver security outcomes without creating unnecessary friction
  • Security certifications such as CISSP, CSSLP, CCSP, AWS Security Specialty, GIAC, OSCP, or equivalent practical expertise

Benefits

  • Target bonuses
  • Equity compensation
  • Generous benefits packages (including medical, dental, vision, and 401k)
  • Competitive compensation, including base pay, bonus opportunities, and annual equity grants that vest quarterly
  • Retirement benefits to help you plan for the future, including a 401(k) or Group Retirement Savings Plan with a company match of $2 for every $1 contributed, up to $15,000 annually (USD in the US, CAD in Canada)
  • Employee Stock Purchase Plan (ESPP) with discounted stock purchase options for eligible employees (US only)
  • Comprehensive health coverage designed to support you and your family, including medical, dental, vision, and wellness resources for US and supplemental health coverage for Canada.
  • Health Savings Account contributions from Upstart for eligible plans (US only)
  • Income protection benefits, including life insurance and disability coverage for added financial security
  • Paid time off, sick leave, and company holidays, in line with local requirements
  • Paid family and parental leave to support caregiving and major life moments (duration varies by country)
  • Family-centered benefits to support fertility, parenthood, and caregiving needs
  • Employee Assistance Program (EAP) offering mental health support and life-centered resources
  • Financial wellness resources, including access to financial planning tools and a financial concierge service (US Only)
  • Annual wellness allowance to support your physical and emotional well-being and personal development, based on what matters most to you
  • Annual productivity allowance to invest in relevant tools and resources you need to do your best work, no matter where you work from
  • Connection and community through team events, all-company updates, and employee resource groups (ERGs)
  • Onsite perks, including catered lunches and fully stocked micro-kitchens when working from one of our offices in the Bay Area, Austin, Columbus, and New York City (opening Summer 2026!)

Company Overview

  • Upstart is a leading AI lending marketplace partnering with banks and credit unions to expand access to affordable credit. It was founded in 2012, and is headquartered in San Mateo, California, USA, with a workforce of 1001-5000 employees. Its website is https://upstart.com/about.
  • Apply To This Job

    Further positions

    [Remote] AI Automation Engineer

    Remote role Full-time

    [Remote] Healthcare Admin Assistant - AI Projects (Remote)

    Remote role Full-time

    [Remote] Concierge Customer Service Representative II

    Remote role Full-time

    [Remote] Manager, Field Marketing

    Remote role Full-time

    [Remote] Senior Account Executive

    Remote role Full-time

    [Remote] Senior Financial Analyst

    Remote role Full-time

    [Remote] National Account Manager

    Remote role Full-time

    [Remote] UN Women: International Consultant - Governance, Peace and Security (Intersectional Approaches), Home-based

    Remote role Full-time

    [Remote] Lead UX Designer

    Remote role Full-time

    [Remote] Cloud Platform Engineer - Control Plane

    Remote role Full-time

    Experienced Customer Success Manager – Real Estate and Construction Industry Expertise

    Remote role Full-time

    PR Manager

    Remote role Full-time

    Experienced Customer Service Representative – Delivering Exceptional Travel Experiences for arenaflex

    Remote role Full-time

    Tech Lead, Web Core Product & Chrome Extension - Glasgow, United Kingdom

    Remote role Full-time

    Online | Hotel Reservations | Customer Service

    Remote role Full-time

    Crisis Support Specialist - Sat-Tues, 10p-8a

    Remote role Full-time

    Principal Presales Engineer, Product Specialist – CDP, Martech, AI

    Remote role Full-time

    EM110 VA2: Foundations of Teaching (Fall 2026) - Internal Posting for CTF Members Only

    Remote role Full-time

    Data QA Associate

    Remote role Full-time

    K-6 Online ESL Teacher - Part-Time Independent Contractor with VIPKID

    Remote role Full-time