Staff Application Security Engineer

UpsideWashington, DC
$214,000 - $245,000Hybrid

About The Position

Upside is seeking a Staff Application Security Engineer to report to the Product Security Manager. This role will work closely with Cloud Security and Engineering teams to scale secure software delivery across Upside. The position owns the application security program, focusing on reducing real risk across mobile, web, and cloud systems by driving remediation, building engineering guardrails, and creating security guidance for developers. The role also involves working with AI for security tasks and securing AI systems being built. A background in product engineering is a plus.

Requirements

  • 6+ years in application or product security or equivalent depth in secure software engineering with meaningful application security ownership.
  • Strong Python code review skills, with the ability to understand Lambda functions and explain issues to engineers.
  • A track record of shipping security improvements that reduced real risk, demonstrating successful remediation across teams.
  • Experience with threat modeling and secure design review, engaging with designs before shipping.
  • Practical, everyday use of AI in security work.
  • Working knowledge of AWS security (Lambda, API Gateway, IAM least privilege, secrets handling) and CI/CD security in GitHub Actions.

Nice To Haves

  • Came into security from a product engineering background.

Responsibilities

  • Own Upside's application security program, including standards, vulnerability management pipeline, and guardrails to prevent recurring defects.
  • Drive vulnerability management outcomes by triaging and tuning findings from scanning, code review, and penetration tests, and partnering with engineering teams for fix verification.
  • Lead application security reviews and threat models for high-impact mobile, web, and backend systems, documenting risk decisions and mitigation plans.
  • Review and threat model agentic AI workflows, defining security controls for tool use, data access, and action execution.
  • Extend AI automation for handling finding volume, including triage, prioritization with service context, and remediation guidance.
  • Build scalable guardrails such as repository baselines, required checks in GitHub, secure-by-default patterns for AWS workloads, reusable templates, and a security champions program.

Benefits

  • Medical, dental, and vision coverage starting on Day 1
  • Equity (ISOs)
  • 401(k) program
  • Family planning programs + paid parental leave
  • Physical fitness and wellness memberships
  • Emotional and mental health support programs
  • Unlimited PTO + 10 paid federal holidays + our annual, week-long Winter Break
  • Flexible work environment
  • Lunch reimbursement for in-office employees
  • Employee Resource Groups
  • Learning and Development stipend
  • Transparent culture
  • Amazing mission!
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service