Senior Application Security Engineer (Remote)

| Remote
Sorry, this job was removed at 3:30 p.m. (CST) on Thursday, October 13, 2022
Find out who’s hiring remotely Nationwide
See all Remote jobs Nationwide
Easy Apply
By clicking Apply Now you agree to share your profile information with the hiring company.

Upgrade is a fintech unicorn founded in 2017. We are the fastest-growing company in the Americas (Financial Times). In the last five years, over 15 million people have applied for an Upgrade card or loan, and we have delivered over $10 billion in affordable and responsible credit. Our innovative Upgrade Card is the fastest growing credit card in America (Nilson Report). Combining the flexibility of a credit card with the low cost of an installment loan helps us redefine banking.


Upgrade has been named a “Best Place to Work in the Bay Area” three years in a row, one of the “Top Companies to work for in Arizona”, “Best Engineering Team" and we have received awards for being a best company for Diversity, Women, Culture, and Veterans.

 

We are looking for new team members who get excited about designing and delivering new and better products to join a team of 1300 talented and passionate professionals. Come join us if you like to tackle big problems and make a meaningful difference in people's lives.


About our Team:


As a core Application Security Engineer at Upgrade, you’ll have direct access and work directly with our Head of Infosec to scale our static and dynamic code analysis, handle manual and automated pen-testing, threat modeling, and lead the overall improvement of our appsec posture. You’ll collaborate alongside DevOps, QA, and Engineering to improve the security of applications architected 100% on the cloud (AWS) in a fully microservices-based environment.


This is a remote position based in the United States. At this time we are unable to consider international applicants for this role.

What You'll Do:

  • Evaluate our security technology, methodology, and tools to better the software development life cycle.
  • Help train developers, and QA personnel to the appropriate level of software security knowledge to perform their responsibilities.
  • Improve and support application security tool services including static analysis, dynamic testing, software composition analysis tools.
  • Support incident response and architecture review processes whenever application security expertise is needed.
  • Manage routine penetration testing services, including both expert consulting and managed services.
  • Provide manual penetration testing and standards gap analysis services to internal business and technology partners.
  • Support, improve, and maintain secure development standards and application security framework projects.
  • Support Vendor Management activities to ensure third party software and development meet security standards.
  • Integrate threat modeling practices into the product development life cycle.
  • Provide security requirements for test driven design to assess control effectiveness.
  • Produce metrics reporting the state of application security programs and performance of development teams against requirements.

What We Look For:

  • 5+ years of relevant work experience.
  • Experience with agile development processes and have experience integrating secure development practices into the model.
  • Experience writing and testing web applications, mobile applications and microservices.
  • Familiarity with graphQL architecture and security best practices.
  • Basic understanding of authentication and authorization schemes including OAuth.
  • Familiarity with a variety of development and testing tools.
  • Experience working with one or more SAST, DAST and IAST tools.
  • Ability to explain vulnerabilities and weaknesses, and discuss effective defensive techniques.
  • Experience with cyber security attacks and mitigation methods (red/blue team experience).
  • Experience working with web applications and browser security; security assessments and penetration testing; identity and access control; applied cryptography and security protocols; security information and event monitoring and intrusion detection.
  • Expertise in employing analytics and threat intelligence techniques, Incident response process; Software security.
  • Basic familiarity with python for security tool automation would be a plus.
  • Experience in IT supply-chain risk management and assurance, as well as cloud security operations.

What We Offer You:

  • Competitive salary and stock option plan. 
  • 100% paid coverage of medical, dental and vision insurance. 
  • 401(k) company match program.
  • Unlimited vacation. 
  • Learning stipend for personal growth and development. 
  • Paid parental leave.
  • Health and wellness initiatives.


Read Full Job Description
Easy Apply
By clicking Apply Now you agree to share your profile information with the hiring company.

Technology we use

  • Engineering
  • Product
  • Sales & Marketing
  • People Operations
    • Apache GroovyLanguages
    • GolangLanguages
    • JavaLanguages
    • PythonLanguages
    • ScalaLanguages
    • SqlLanguages
    • ReactLibraries
    • ReduxLibraries
    • DockerFrameworks
    • GraphQLFrameworks
    • KafkaFrameworks
    • KubernetesFrameworks
    • Node.jsFrameworks
    • OAuthFrameworks
    • SpringFrameworks
    • TerraformFrameworks
    • AWS RedshiftDatabases
    • DynamoDBDatabases
    • ElasticsearchDatabases
    • PostgreSQLDatabases
    • AWS (Amazon Web Services)Services
    • TableauAnalytics
    • FigmaDesign
    • IllustratorDesign
    • InVisionDesign
    • PhotoshopDesign
    • UserlyticsDesign
    • ConfluenceManagement
    • Google DriveManagement
    • Google DocsManagement
    • Google SlidesManagement
    • JIRAManagement
    • HubSpotCRM
    • ZoomInfoLead Gen
    • Google HangoutsCollaboration
    • SlackCollaboration

An Insider's view of Upgrade, Inc.

How do you collaborate with other teams in the company?

I'm surrounded by so many smart, humble and passionate people, where I can learn and grow from everyday. With culture where everyone’s voice is valued and heard, this makes for a very collaborative and thriving workplace where you can grow. It is very empowering and it truly feels like we can achieve anything we, as a team, set our minds toward.

Nelson Lobo

Software Engineer

What are some things you learned at the company?

Since I started at Upgrade, I have been exposed to new technologies for test automation, infrastructure and code coverage, to name a few. I had some challenges in making our test framework more efficient and faster. This is another aspect of Upgrade that I love: there are always different projects to work on which means new learning opportunities.

Seti Momayez

QA Developer

What are Upgrade, Inc. Perks + Benefits

Culture
Volunteer in local community
Partners with nonprofits
Open door policy
Team based strategic planning
Open office floor plan
Employee resource groups
Employee-led culture committees
Hybrid work model
In-person all-hands meetings
Flexible work schedule
Remote work program
Diversity
Dedicated diversity and inclusion staff
Diversity employee resource groups
Health Insurance & Wellness Benefits
Disability insurance
Dental insurance
Vision insurance
Health insurance
Life insurance
Wellness programs
Mental health benefits
Abortion travel benefits
Financial & Retirement
401(K)
401(K) matching
Upgrade offers up to 4% match after 90 days of employment.
Company equity
Charitable contribution matching
Child Care & Parental Leave Benefits
Generous parental leave
Family medical leave
Vacation & Time Off Benefits
Generous PTO
Paid holidays
Paid sick days
Flexible time off
Bereavement leave benefits
Hardship benefits
Office Perks
Company-sponsored outings
Free snacks and drinks
Some meals provided
Company-sponsored happy hours
Relocation assistance
Fitness stipend
Professional Development Benefits
Job training & conferences
Lunch and learns
Promote from within
Mentorship program
Continuing education stipend

More Jobs at Upgrade, Inc.

Easy Apply
By clicking Apply Now you agree to share your profile information with the hiring company.
Learn more about Upgrade, Inc.Find similar jobs like this