CareerRiver

Senior Security Engineering Manager, Product Security

Upstart Holdings, Inc. · Remote

📍 United States | Remote💰 $190,600via greenhousePosted 2026-05-20
Apply on company site ↗
CareerRiver pulls this listing straight from the employer's hiring system — no recruiter middleman, no reposts. Applying takes you directly to Upstart Holdings, Inc..
About Upstart At Upstart, we’re united by a mission that matters: to radically reduce the cost and complexity of borrowing for all Americans. Every day, we bring creativity, experimentation, and advanced AI to reshape access to credit, helping millions move forward financially with clarity and confidence. As the leading AI lending marketplace, we partner with banks and credit unions to expand access to affordable credit through technology that’s both radically intelligent and deeply human. Our platform runs over one million predictions per borrower using more than 1,800 signals, powering smarter, fairer decisions for millions of customers. But the numbers only hint at the impact. Every idea, every voice, and every contribution moves us closer to a world where credit never stands between people and their financial progress. We’re proudly digital-first, giving most Upstarters the flexibility to do their best work from wherever they thrive, alongside teammates across 80+ cities in the US and Canada. Digital-first doesn’t mean distant. We’re intentional about in-person connection through team onsites, planning sessions, and moments that spark creativity and trust. And whether you choose to work primarily from home or collaborate in-person from one of our offices in Columbus, Austin, the Bay Area, or New York City (opening Summer 2026), you’ll have the support to work in the way that works best for you. If you’re energized by tackling meaningful problems, excited to innovate with purpose, and motivated by work that truly matters, we’d love to hear from you. The Team:  Upstart’s Security Engineering team is passionate about bringing progressive approaches to securing our products, infrastructure, platforms, and enterprise systems. We believe security should empower innovation, move at the speed of business, and embed safety by design into how Upstart builds and operates. Our team’s mission is to protect Upstart’s core product platforms, cloud infrastructure, enterprise systems, customers, and data by partnering deeply with Engineering, Product, Infrastructure, Risk, Compliance, and Security teams to reduce security risk through automation, collaboration, offensive security, and durable security practices. As the Senior Security Manager for Product Security Engineering at Upstart, you will lead a team responsible for scaling security engineering practices across application security, infrastructure security, offensive security, and product security. You will set priorities, develop team members, and partner with senior engineering and business leaders to shape Upstart’s security engineering strategy, strengthen secure-by-design practices, reduce systemic risk, and improve the security posture of customer-facing products, cloud-native services, internal platforms, APIs, and AI-driven product workflows. How you’ll make an impact Define and lead the Security Engineering roadmap across application security, infrastructure security, offensive security, and product security, aligning priorities with Upstart’s business objectives, engineering strategy, regulatory expectations, and risk posture. Manage, coach, and develop a team of security engineers, ensuring clear goals, measurable impact, sustainable execution, effective operating rhythms, and growth opportunities for each team member. Partner with Engineering, Product, Infrastructure, Data, Risk, Compliance, and Audit leaders to identify high-priority security risks, align on pragmatic mitigations, and embed security requirements early in planning, design, development, and operations. Scale secure-by-design practices across the SDLC, including threat modeling, security architecture reviews, secure coding practices, automated security testing, vulnerability management, API security, CI/CD protections, secrets management, and developer security enablement. Strengthen infrastructure and cloud security by partnering with Infrastructure and Platform teams on secure architecture, identity and access controls, Kubernetes and container security, cloud-native security controls, and defense-in-depth across application and infrastructure layers. Build and mature offensive security capabilities, including attack surface management, adversarial testing, security validation, penetration testing coordination, bug bounty intake, and prioritization of findings into durable engineering improvements. Improve product security outcomes by partnering with Product and Engineering teams to identify abuse cases, security requirements, customer-impacting risks, and scalable controls for high-trust product experiences. Drive consistent execution across cross-functional initiatives by setting priorities, clarifying ownership, communicating tradeoffs, and ensuring high-impact security work is delivered with quality and urgency. Establish and improve Security Engineering metrics, operating models, and reporting so leaders can understand risk posture, remediation progress, recurring patterns, program health, and the effectiveness of security investments. Support response to high-severity security issues by coordinating technical investigation, stakeholder communication, root cause analysis, remediation tracking, and durable improvements that prevent repeat issues. Foster a culture where security enables innovation by building trusted partnerships, mentoring engineering leaders, and helping teams adopt practical controls that improve safety without unnecessary friction. What we’re looking for:  Minimum requirements: 8+ years of experience in security engineering, software engineering, infrastructure engineering, offensive security, product security, or related technical security roles. 3+ years of experience managing, leading, or formally developing security engineers or technical teams. Experience leading security engineering programs in at least two of the following domains: application security, infrastructure security, offens

More Remote jobs

Remote jobs · Browse all locations