Upstart
Senior Offensive Security Engineer
Job Summary
The Sr Offensive Security Engineer at Upstart is responsible for establishing and executing the company's Offensive Security program. The role involves identifying vulnerabilities in Upstart's controls and systems, collaborating with detection, cloud, and application security teams, and conducting purple teaming exercises. Candidates should have extensive security experience, especially in offensive security, and be capable of building tools to simulate attacker behavior. The position offers remote work options and a comprehensive benefits package.
Required Skills
Benefits
Job Description
About Upstart
Upstart is the leading AI lending marketplace partnering with banks and credit unions to expand access to affordable credit. By leveraging Upstart's AI marketplace, Upstart-powered banks and credit unions can have higher approval rates and lower loss rates across races, ages, and genders, while simultaneously delivering the exceptional digital-first lending experience their customers demand. More than 80% of borrowers are approved instantly, with zero documentation to upload.
Upstart is a digital-first company, which means that most Upstarters live and work anywhere in the United States. However, we also have offices in San Mateo, California; Columbus, Ohio; and Austin, Texas.
Most Upstarters join us because they connect with our mission of enabling access to effortless credit based on true risk. If you are energized by the impact you can make at Upstart, we’d love to hear from you!
The Team:
Upstart’s Security team is passionate in bringing progressive approaches in securing our products. We believe that security should empower innovation, move at the speed of business, and have safety by design as core principles. Our team’s mission is to ensure the safety of our core product platforms, enterprise, and manage threats to Upstart. We approach our efforts through automation, strong collaboration with our partner teams, and maintaining a positive experience for Upstarters.
As the Sr Offensive Security Engineer at Upstart, you will be responsible for building the Offensive Security program at Upstart and executing on its objectives. This will include finding weaknesses in Upstart's controls and helping drive remediation of those weaknesses. You will partner frequently with your peers in Detection Engineering, Cloud Security, Application Security, and Enterprise Security to ensure the controls we build are effective, and help determine the priority of future controls.
How you’ll make an impact:
- Validate assumptions and discover weaknesses in Upstart's controls and systems
- Partnering within security on control design, providing feedback from an attacker's perspective
- Run purple teaming exercises with our Detection and Response team to ensure detections would be effective in an attacker scenario
- Stack rank systems to be tested and coordinate external resources and testing firms to perform testing across our systems
- Program management for the Offensive Security program - defining goals, KPIs, and driving it towards success.
What we’re looking for:
Minimum Qualifications:
- 5+ years in Security, at least 2 of which are in Offensive Security
- Experience scoping and coordinating offense security testing exercises
- Experience in an Okta + MacOS environment
- Experience with K8s and modern cloud stacks
- Ability to build tools to recreate attacker behavior (python preferred)
Preferred Qualifications:
- Internal Red team experience
- AWS & EKS experience
- Experience with testing CI/CD pipelines
- Detection Engineering experience (for purple team collaboration)
- System Administration experience (cloud native systems)
Position Location - This role is available in the following locations: Remote, San Mateo, Columbus, Austin
Time Zone Requirements - This team operates across all U.S. time zones.
Travel requirements - As a digital first company, the majority of your work can be accomplished remotely. The majority of our employees can live and work anywhere in the U.S but are encouraged to to still spend high quality time in-person collaborating via regular onsites. The in-person sessions’ cadence varies depending on the team and role; most teams meet once or twice per quarter for 2-4 consecutive days at a time.
What you'll love:
- Competitive Compensation (base + bonus & equity)
- Comprehensive medical, dental, and vision coverage with Health Savings Account contributions from Upstart
- 401(k) with 100% company match up to $4,500 and immediate vesting and after-tax savings
- Employee Stock Purchase Plan (ESPP)
- Life and disability insurance
- Generous holiday, vacation, sick and safety leave
- Supportive parental, family care, and military leave programs
- Annual wellness, technology & ergonomic reimbursement programs
- Social activities including team events and onsites, all-company updates, employee resource groups (ERGs), and other interest groups such as book clubs, fitness, investing, and volunteering
- Catered lunches + snacks & drinks when working in offices
At Upstart, your base pay is one part of your total compensation package. The anticipated base salary for this position is expected to be within the below range. Your actual base pay will depend on your geographic location–with our “digital first” philosophy, Upstart uses compensation regions that vary depending on location. Individual pay is also determined by job-related skills, experience, and relevant education or training. Your recruiter can share more about the specific salary range for your preferred location during the hiring process.
In addition, Upstart provides employees with target bonuses, equity compensation, and generous benefits packages (including medical, dental, vision, and 401k).
Upstart is a proud Equal Opportunity Employer. We are dedicated to ensuring that underrepresented classes receive better access to affordable credit, and are just as committed to embracing diversity and inclusion in our hiring practices. We celebrate all cultures, backgrounds, perspectives, and experiences, and know that we can only become better together.
If you require reasonable accommodation in completing an application, interviewing, completing any pre-employment testing, or otherwise participating in the employee selection process, please email [email protected]
Upstart
A lending platform using AI to provide personal loans and credit solutions with a focus on fair and fast approvals.
See more jobsSafe Remote Job Search Tips
Verify Employer Thoroughly
Research the company's identity thoroughly before applying. Check for a professional website with contacts, active social media, and LinkedIn profiles. Verify details across platforms and look for reviews on Glassdoor or Trustpilot to confirm legitimacy.
Never Pay to Get a Job
Legitimate employers never require payment for applications, training, background checks, or equipment. Always reject upfront payment requests or demands for bank details, even if they claim it's for purchasing necessary work gear on your behalf.
Safeguard Your Personal Information
Protect sensitive data like SSN, bank details, or ID copies. Share this only after accepting a formal, written job offer. Ensure it's submitted via a secure company system or portal, never through insecure channels like standard email attachments.
Scrutinize Communication & Interviews
Watch for communication red flags: poor grammar, generic emails (@gmail), vague details, or undue pressure. Be highly suspicious of interviews held only via text or chat apps; legitimate companies typically use video or phone calls.
Beware of Unrealistic Offers
If an offer's salary or benefits seem unrealistically high for the work involved, be cautious. Research standard pay for similar roles. Offers that appear 'too good to be true' are often scams designed to lure you into providing information or payment.
Insist on a Formal Contract
Always secure and review a formal, written job offer or employment contract before starting work or sharing final personal details. Ensure it clearly defines your role, compensation, key terms, and conditions to avoid misunderstandings or scams.