USWFHUpsideSep 06, 2026
UP

Staff Application Security Engineer

at Upside

Apply directly for Staff Application Security Engineer at Upside. Verified 100% work-from-home position. View requirements, benefits, salary & direct application link.

Level: Staff
✨ Apply Now ↗Opens employer's official career page

Job Overview

Published

Sep 06, 2026

Expires

Sep 21, 2026

Source

Upside

Region

US

Type

Remote / Work From Home

Category

WFH

Seniority

Staff

Job Description

Meet Upside

We created Upside to transform brick-and-mortar commerce.

Our technology uses the sophistication of online retail—profit measurement, attribution, and incrementality—to provide users with more value on their everyday purchases and brick-and-mortar businesses with new, profitable customers.

We’ve helped millions of users earn 2 to 3 times more cashback than any other product, and hundreds of thousands of brick-and-mortar businesses earn measurable profit.

Billions of dollars in commerce run through the Upside platform every year, and that value goes directly back to our retailer partners, the consumers they serve, and important sustainability initiatives.

The Impact You'll Make You'll report to the Product Security Manager and work closely with our Cloud Security and Engineering teams to scale secure software delivery across Upside.

This role owns our application security program, reducing real risk across mobile, web, and cloud systems by driving remediation, building engineering guardrards, and creating security guidance that developers actually use.

You'll also work both sides of the AI problem: we use AI to do security work, and we secure the AI systems we're building.

If you came into security from a product engineering background, we'd especially love to hear from you.

Own Upside's application security program, the standards, the vulnerability management pipeline, and the guardrails that stop entire classes of defects from coming back Drive vulnerability management outcomes by triaging and tuning findings from scanning, code review, and our annual penetration test, then partnering with engineering teams to get fixes shipped and verified Lead application security reviews and threat models for high-impact work across mobile, web, and backend systems, and document risk decisions with clear mitigation plans Review and threat model agentic AI workflows, and define security controls for tool use, data access, and action execution Build and improve the automation that triages findings, prioritizes them with service context, and produces remediation guidance engineers can act on Build guardrails that scale beyond our team; repository baselines, required checks in GitHub, secure-by-default patterns for AWS workloads, reusable templates, and a security champions program What You'll Bring 6+ years in application or product security or equivalent depth in secure software engineering with meaningful application security ownership Strong Python code review skills, you can open a Lambda, understand what it does, and explain to the engineer who wrote it exactly what's wrong and why A track record of shipping security improvements that reduced real risk, not just running scanners or writing policy, you can point to fixes that landed, were verified, and to remediation you drove across teams you didn't own Experience with threat modeling and secure design review, engaging with designs before they ship, not only with code after the fact Practical, everyday use of AI in your security work; this is about how you already work, not a tool you've tried once Working knowledge of our stack:

AWS security (Lambda, API Gateway, IAM least privilege, secrets handling) and CI/CD security in GitHub Actions, depth in the underlying mechanics matters more here than years in any one platform Tools We Use GitHub:

Actions, Advanced Security, Copilot Python, Terraform AWS

Lambda, API Gateway, IAM, DynamoDB, S3, SNS, SQS, VPCs Snowflake, SQL, dbt, Dagster Claude, Claude Code, Amazon Bedrock Benefits:

Medical, dental, and vision coverage starting on Day 1 Equity (ISOs) 401(k) program Family planning programs + paid parental leave Physical fitness and wellness memberships Emotional and mental health support programs Unlimited PTO + 10 paid federal holidays + our annual, week-long Winter Break Flexible work environment Lunch reimbursement for in-office employees Employee Resource Groups Learning and Development stipend Transparent culture Amazing mission! Diversity and Inclusion:

Diversity drives innovation, and our differences make us stronger.

We‘re passionate about building a workplace that represents a variety of backgrounds, skills, and perspectives, and we do not discriminate based on race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status.

Everyone is welcome here! If there's anything we can do to support a disability or special need during your application or interview process, please email accommodations@upside.com.

This email is for accessibility accommodations only, it should not be used to submit job applications.

Notice To Recruiters And Placement Agencies

This is an in-house search with a dedicated recruiter.

Please do not submit resumes to any person or email address at Upside.

Upside is not liable for, and will not pay, placement fees for candidates submitted by any party or agency other than its approved recruitment partners.

Remote Work Guidelines & Career Insights

Practical advice for succeeding as a remote professional in this role.

Asynchronous Productivity

High-performing remote teams prioritize asynchronous communication. Document your progress clearly in tickets, maintain organized project repositories, and communicate status updates proactively without waiting for real-time meetings.

🛡️

Home Office & Security

Ensure a private, quiet workstation with a reliable high-speed broadband connection (min 50 Mbps). Maintain compliance with employer cybersecurity policies by utilizing secure password managers, 2FA authentication, and authorized VPN services.

🎯

Resume & Application Tips

Tailor your CV specifically to the requirements of Staff Application Security Engineer. Highlight quantifiable achievements from past roles (e.g. revenue growth, efficiency improvements, or software shipped) and showcase proven experience collaborating with remote teams.

💬

Virtual Interview Prep

Test your video and audio hardware before virtual calls. Prepare concise STAR-format stories demonstrating how you manage time independently, handle conflicting priorities across different time zones, and solve complex problems autonomously.

Frequently Asked Questions

Key answers about the application process, remote setup, and compensation for Staff Application Security Engineer.

Is the Staff Application Security Engineer role 100% remote?+

Yes, this is a fully remote work-from-home position with Upside. You can collaborate asynchronously, manage project deliverables, and participate in virtual team meetings from your home office without daily commuting.

What qualifications and experience are needed for Staff Application Security Engineer?+

Applicants are typically evaluated on relevant industry background, core capabilities, and self-management. Key requirements include strong English communication skills, independent problem-solving abilities, and familiarity with modern remote collaboration platforms like Slack, Zoom, and project management tools.

Who is eligible to apply for this job?+

This remote opening welcomes applications from US and eligible remote regions. Candidates must ensure they meet the work authorization, residency, or independent contractor criteria required by Upside.

What is the salary and benefits package for Staff Application Security Engineer?+

The expected compensation for this role is competitive compensation aligned with global remote market standards. In addition to base compensation, remote positions often provide flexible working hours, home office equipment stipends, and professional growth opportunities.

How do I apply and what should I prepare for the interview?+

Click the "Apply Now" button on this page to visit Upside's official application portal. Tailor your resume to highlight relevant achievements, and prepare to discuss your experience working productively in an asynchronous remote environment.

Related Skills & Keywords

#staff#application#security#engineer#work from home#remote jobs

Similar Remote Jobs

Save this remote job alert.

Store your email with the current page context so you can keep track of similar remote opportunities and reuse this search later.

Search alerts are stored with your current page context so you can track similar jobs over time.

🚀

Ready to Apply?

Click the button below to apply on the employer's official website. Always verify job details before submitting personal information.

Staff Application Security Engineer
Upside • Verified Remote
Apply Now