[![Image]() Meet Jobicy Copilot — free AI autofill for job applications + remote job alerts ›](#)   [All remote jobs](https://jobicy.com/jobs.md)Open role[![Upside logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/06/06e64944-221.png)](https://jobicy.com/company/upside.md)Remote opportunity at[Upside](https://jobicy.com/company/upside.md)

# Staff Application Security Engineer

Review the role, location requirements, compensation details, and application process before deciding whether this opportunity fits your next career move.

[Apply for this job](#job-application)[View company](https://jobicy.com/company/upside.md)Share6 Sep 2026Published36Listing views3Application actions6 Oct 2026Apply before  Opportunity details

## About this role.

AI SummaryUpside is hiring a Staff Application Security Engineer to own and scale its application security program across mobile, web, backend, cloud, and AI systems. The role emphasizes vulnerability management, threat modeling, secure design reviews, remediation leadership, and developer-friendly security guardrails. The engineer will work closely with Cloud Security and product engineering, with particular focus on AWS, GitHub Actions, Python, Terraform, and agentic AI workflow security. This is a senior individual-contributor role requiring demonstrated ability to drive verified risk reduction across teams without direct authority.

## Role DNA

A quick view of the complexity, pace, ownership and collaboration implied by the job description.

### Job Complexity

5/5EasyHard

### Pace & Pressure

4/5RelaxedFast-paced

### Autonomy Level

5/5GuidedFull ownership

### Communication Load

5/5IndependentCollaborative

AI insightThis staff-level role requires deep hands-on application security expertise alongside program ownership, secure architecture judgment, and AI security knowledge. Success depends on influencing multiple engineering teams and turning findings into durable, verified remediation outcomes.

## Salary analysis

Estimated compensation compared with the broader US market for similar roles.

Estimated job medianHighly competitive$240,000US market range$190k–$270k0$297k

AI insightThe disclosed annual base salary range is $235,000 to $245,000 USD, with a midpoint of $240,000. This is competitive for a Staff Application Security Engineer in major U.S. technology markets; a typical U.S. market range is estimated at $190,000 to $270,000 annually, varying by location, company stage, scope, and equity package.

## Core skills

Skills and capabilities most closely associated with this opportunity.

[Application Security](https://jobicy.com/jobs?search_keywords=Application%20Security.md)[Product Security](https://jobicy.com/jobs?search_keywords=Product%20Security.md)[Threat Modeling](https://jobicy.com/jobs?search_keywords=Threat%20Modeling.md)[Vulnerability Management](https://jobicy.com/jobs?search_keywords=Vulnerability%20Management.md)[Secure Code Review](https://jobicy.com/jobs?search_keywords=Secure%20Code%20Review.md)[Python](https://jobicy.com/jobs?search_keywords=Python.md)[AWS Security](https://jobicy.com/jobs?search_keywords=AWS%20Security.md)[GitHub Actions](https://jobicy.com/jobs?search_keywords=GitHub%20Actions.md)[CI/CD Security](https://jobicy.com/jobs?search_keywords=CICD%20Security.md)[AI Security](https://jobicy.com/jobs?search_keywords=AI%20Security.md)

Sample interview questionsDescribe an application-security improvement you drove from finding through verified remediation.I would explain the original risk, how I prioritized it using exploitability and business context, the engineering partners involved, and the control or code change that resolved it. I would also describe how I verified the fix and added a preventive guardrail, such as a CI check, secure template, or detection rule.

How would you threat model an agentic AI workflow that can use tools and access internal data?

I would map the model, prompts, tools, identities, data sources, and execution paths, then identify threats such as prompt injection, unauthorized data access, excessive tool permissions, unsafe actions, and data exfiltration. Controls would include scoped and short-lived credentials, allowlisted tools and actions, strong authorization checks outside the model, input/output validation, audit logging, approval gates for sensitive actions, and adversarial testing.

How do you make vulnerability management effective rather than simply generating scanner findings?

I prioritize findings using asset criticality, exposure, exploitability, data sensitivity, and compensating controls rather than severity alone. I tune noisy rules, assign clear owners and deadlines, provide actionable remediation guidance, track verified closure, and use recurring trends to create systemic engineering guardrails.

What would you review when assessing an AWS Lambda and API Gateway design?

I would assess authentication and authorization boundaries, IAM least privilege, secrets storage and rotation, input validation, logging, encryption, network exposure, error handling, dependency risk, and data access paths. I would also review API Gateway authorization, rate limiting, request validation, and whether the Lambda role can be narrowed to only the required actions and resources.

How would you build a security champions program that engineering teams actually adopt?

I would start with willing technical leaders, provide concise role-specific training and reusable review tools, and make the program useful by offering direct access to security expertise and reducing delivery friction. I would define lightweight expectations, recognize meaningful contributions, measure outcomes such as earlier risk discovery and remediation time, and continuously adapt based on champion feedback.

Meet Upside:

We created Upside to transform brick-and-mortar commerce. Our technology uses the sophistication of online retail—profit measurement, attribution, and incrementality—to provide users with more value on their everyday purchases and brick-and-mortar businesses with new, profitable customers. We’ve helped millions of users earn 2 to 3 times more cashback than any other product, and hundreds of thousands of brick-and-mortar businesses earn measurable profit. Billions of dollars in commerce run through the Upside platform every year, and that value goes directly back to our retailer partners, the consumers they serve, and important sustainability initiatives.

The Impact You’ll Make

You’ll report to the Product Security Manager and work closely with our Cloud Security and Engineering teams to scale secure software delivery across Upside. This role owns our application security program, reducing real risk across mobile, web, and cloud systems by driving remediation, building engineering guardrards, and creating security guidance that developers actually use.

You’ll also work both sides of the AI problem: we use AI to do security work, and we secure the AI systems we’re building. If you came into security from a product engineering background, we’d especially love to hear from you.

*

Own Upside’s application security program, the standards, the vulnerability management pipeline, and the guardrails that stop entire classes of defects from coming back

*

Drive vulnerability management outcomes by triaging and tuning findings from scanning, code review, and our annual penetration test, then partnering with engineering teams to get fixes shipped and verified

*

Lead application security reviews and threat models for high-impact work across mobile, web, and backend systems, and document risk decisions with clear mitigation plans

*

Review and threat model agentic AI workflows, and define security controls for tool use, data access, and action execution

*

Build and improve the automation that triages findings, prioritizes them with service context, and produces remediation guidance engineers can act on

*

Build guardrails that scale beyond our team; repository baselines, required checks in GitHub, secure-by-default patterns for AWS workloads, reusable templates, and a security champions program

What You’ll Bring

*

6+ years in application or product security or equivalent depth in secure software engineering with meaningful application security ownership

*

Strong Python code review skills, you can open a Lambda, understand what it does, and explain to the engineer who wrote it exactly what’s wrong and why

*

A track record of shipping security improvements that reduced real risk, not just running scanners or writing policy, you can point to fixes that landed, were verified, and to remediation you drove across teams you didn’t own

*

Experience with threat modeling and secure design review, engaging with designs before they ship, not only with code after the fact

*

Practical, everyday use of AI in your security work; this is about how you already work, not a tool you’ve tried once

*

Working knowledge of our stack: AWS security (Lambda, API Gateway, IAM least privilege, secrets handling) and CI/CD security in GitHub Actions, depth in the underlying mechanics matters more here than years in any one platform

Tools We Use

*

GitHub: Actions, Advanced Security, Copilot

*

Python, Terraform

*

AWS: Lambda, API Gateway, IAM, DynamoDB, S3, SNS, SQS, VPCs

*

Snowflake, SQL, dbt, Dagster

*

Claude, Claude Code, Amazon Bedrock

Benefits:

*

Medical, dental, and vision coverage starting on Day 1

*

Equity (ISOs)

*

401(k) program

*

Family planning programs + paid parental leave

*

Physical fitness and wellness memberships

*

Emotional and mental health support programs

*

Unlimited PTO + 10 paid federal holidays + our annual, week-long Winter Break

*

Flexible work environment

*

Lunch reimbursement for in-office employees

*

Employee Resource Groups

*

Learning and Development stipend

*

Transparent culture

*

Amazing mission!

Diversity and Inclusion:

Diversity drives innovation, and our differences make us stronger. We‘re passionate about building a workplace that represents a variety of backgrounds, skills, and perspectives, and we do not discriminate based on race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status. Everyone is welcome here!

If there’s anything we can do to support a disability or special need during your application or interview process, please email accommodations@upside.com.

This email is for accessibility accommodations only, it should not be used to submit job applications.

Notice To Recruiters And Placement Agencies:

This is an in-house search with a dedicated recruiter. Please do not submit resumes to any person or email address at Upside. Upside is not liable for, and will not pay, placement fees for candidates submitted by any party or agency other than its approved recruitment partners.

Show more

[Apply now >](https://jobicy.com/jobs/152657-staff-application-security-engineer.md)

*

![Upload CV](data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHdpZHRoPSI2NSIgaGVpZ2h0PSI2NSIgZmlsbD0ibm9uZSIgeG1sbnM6dj0iaHR0cHM6Ly92ZWN0YS5pby9uYW5vIj48ZyBjbGlwLXBhdGg9InVybCgjQSkiPjxwYXRoIGQ9Ik0wIDBINjVWNjVIMFYwWiIgZmlsbD0iIzAyOWFlYiIvPjxnIGZpbGw9IiNmZmYiIHN0cm9rZT0iI2ZmZiIgc3Ryb2tlLXdpZHRoPSIyIj48cGF0aCBkPSJNMzMuMDQ5IDE1LjQ1NGExLjQzIDEuNDMgMCAwIDAtMi4wOTcgMGwtNy41NzkgOC4xNDdhMS4zOCAxLjM4IDAgMCAwIC4wOSAxLjk3MyAxLjQ0IDEuNDQgMCAwIDAgMi4wMDgtLjA4OGw1LjEwOS01LjQ5MnYyMC42MWExLjQxIDEuNDEgMCAwIDAgMS40MjEgMS4zOTdjLjc4NSAwIDEuNDIxLS42MjUgMS40MjEtMS4zOTd2LTIwLjYxbDUuMTA5IDUuNDkyYTEuNDQgMS40NCAwIDAgMCAyLjAwOC4wODggMS4zOCAxLjM4IDAgMCAwIC4wOS0xLjk3M2wtNy41NzktOC4xNDZ6TTE2Ljc2OSAzOC40YzAtLjc3My0uNjItMS40LTEuMzg1LTEuNFMxNCAzNy42MjcgMTQgMzguNHYuMTAybC4yMTUgNi4yMjljLjIyMyAxLjY4LjcwMSAzLjA5NSAxLjgxMyA0LjIxOHMyLjUxIDEuNjA3IDQuMTcyIDEuODMzYzEuNi4yMTggMy42MzYuMjE4IDYuMTYuMjE4aDExLjI4bDYuMTYtLjIxOGMxLjY2Mi0uMjI2IDMuMDYxLS43MDkgNC4xNzItMS44MzNzMS41ODktMi41MzggMS44MTMtNC4yMThDNTAgNDMuMTEzIDUwIDQxLjA1NSA1MCAzOC41MDNWMzguNGMwLS43NzMtLjYyLTEuNC0xLjM4NS0xLjRzLTEuMzg1LjYyNy0xLjM4NSAxLjRsLS4xOSA1Ljk1OGMtLjE4MiAxLjM3LS41MTUgMi4wOTUtMS4wMjYgMi42MTJzLTEuMjI4Ljg1My0yLjU4MyAxLjAzOGMtMS4zOTUuMTktMy4yNDMuMTkzLTUuODkzLjE5M0gyNi40NjJjLTIuNjUgMC00LjQ5OC0uMDAzLTUuODkzLS4xOTMtMS4zNTUtLjE4NC0yLjA3Mi0uNTIxLTIuNTgzLTEuMDM4cy0uODQ0LTEuMjQyLTEuMDI2LTIuNjEyYy0uMTg3LTEuNDEtLjE5MS0zLjI3OS0uMTkxLTUuOTU4eiIvPjwvZz48L2c+PGRlZnM+PGNsaXBQYXRoIGlkPSJBIj48cGF0aCBmaWxsPSIjZmZmIiBkPSJNMCAwaDY1djY1SDB6Ii8+PC9jbGlwUGF0aD48L2RlZnM+PC9zdmc+)

### Upload your resume now

To unlock remote work opportunities and be discovered by global employers.

This job listing has been manually reviewed by the Jobicy Trust & Safety Team for compliance with our posting guidelines, including verification of the company's legitimacy, accuracy of job details, clarity of remote work policy, and absence of misleading or fraudulent content.

Next step

## Apply now.

Follow the employer’s application method and review Jobicy’s safety guidance before sharing personal information.

Keep exploring

## Related remote jobs.

Matched by job category10 related opportunities[Cybersecurity](https://jobicy.com/categories/cybersecurity.md) [Browse all jobs](https://jobicy.com/jobs.md)
*
![Tenable logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/06/01879e02-221.jpg)
Tenable  Sep 6

### [Senior Security Consultant](https://jobicy.com/jobs/152673-senior-security-consultant.md)

Who is Tenable? Tenable® is the Exposure Management company. Over 40,000 organizations around the globe rely on Tenable to understand and reduce cyber risk. Our global employees support 65 percent…

*
![Tenable logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/06/01879e02-221.jpg)
Tenable  Sep 6

### [Security Sales Engineer – SLED/Public Sector](https://jobicy.com/jobs/152668-security-sales-engineer-sled-public-sector.md)

Who is Tenable? Tenable® is the Exposure Management company. Over 40,000 organizations around the globe rely on Tenable to understand and reduce cyber risk. Our global employees support 65 percent…

*
![Tenable logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/06/01879e02-221.jpg)
Tenable  Sep 6

### [Principal Solutions Architect (AWS Technical Alliances)](https://jobicy.com/jobs/152664-principal-solutions-architect-aws-technical-alliances.md)

Who is Tenable? Tenable® is the Exposure Management company. Over 40,000 organizations around the globe rely on Tenable to understand and reduce cyber risk. Our global employees support 65 percent…

*
![Smartsheet logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/06/8b6103bd-221.jpg)
Smartsheet  Sep 6

### [Senior Security Engineer I, Customer Trust EMEA (Remote Eligible in the UK)](https://jobicy.com/jobs/150221-senior-security-engineer-i-customer-trust-emea-remote-eligible-in-the-uk.md)

For over 20 years, Smartsheet has empowered teams to manage work seamlessly and scale solutions smarter. Now, in our most ambitious chapter yet, we are uniting human teams with AI…

*
![HackerOne logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/06/8937d355-221.png)
HackerOne  Sep 4

### [Senior Director, Community](https://jobicy.com/jobs/152527-senior-director-community.md)

HackerOne is a global leader in Continuous Threat Exposure Management (CTEM). The HackerOne Platform unites agentic AI solutions with the ingenuity of the world’s largest community of security researchers to…

*
![HackerOne logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/06/8937d355-221.png)
HackerOne  Sep 4

### [Product Security Analyst](https://jobicy.com/jobs/152523-product-security-analyst.md)

HackerOne is a global leader in Continuous Threat Exposure Management (CTEM). The HackerOne Platform unites agentic AI solutions with the ingenuity of the world’s largest community of security researchers to…

*
![HackerOne logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/06/8937d355-221.png)
HackerOne  Sep 4

### [Senior Security Engineer, Detection and Response](https://jobicy.com/jobs/152514-senior-security-engineer-detection-and-response.md)

HackerOne is a global leader in Continuous Threat Exposure Management (CTEM). The HackerOne Platform unites agentic AI solutions with the ingenuity of the world’s largest community of security researchers to…

*
![CertiK logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2021/03/Jobicy-210308091023-955845.jpg)
CertiK  Sep 3

### [Blockchain Security Expert – AI Track](https://jobicy.com/jobs/152451-blockchain-security-expert-ai-track.md)

About the Company CertiK is the largest blockchain security auditor and provides a comprehensive suite of tools to secure the industry at scale. To date, CertiK has worked with over…

*
![CertiK logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2021/03/Jobicy-210308091023-955845.jpg)
CertiK  Sep 3

### [Blockchain Security Engineer – Senior Level (Solidity / Rust / Golang )](https://jobicy.com/jobs/152447-blockchain-security-engineer-senior-level-solidity-rust-golang.md)

About the Role: We are seeking a Senior Blockchain Security Engineer with a strong security mindset and deep technical expertise across smart contracts, blockchain nodes, and decentralized infrastructure. You will…

*
![Keyfactor, Inc. logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/06/ba8ae349-221.png)
Keyfactor, Inc.  Sep 1

### [Information Security Engineer](https://jobicy.com/jobs/152303-information-security-engineer.md)

About Keyfactor Our mission is to securely connect the world: humans, machines, and AI. Keyfactor is the leader in trust infrastructure for AI and machines, helping the world’s largest enterprises…