Upstart logo
Upstart

Our mission is to enable effortless credit based on true risk.

Principal Security Engineer, Data Security

Security EngineerSecurity EngineerFull TimeRemoteSeniorTeam 1,001-5,000H1B SponsorCompany SiteLinkedIn

Location

United States

Posted

54 days ago

Salary

$190.6K - $263.9K / year

Seniority

Senior

Job Description

Principal Security Engineer, Data Security

Upstart

About Upstart At Upstart, we’re united by a mission that matters: to radically reduce the cost and complexity of borrowing for all Americans. Every day, we bring creativity, experimentation, and advanced AI to reshape access to credit, helping millions move forward financially with clarity and confidence. As the leading AI lending marketplace, we partner with banks and credit unions to expand access to affordable credit through technology that’s both radically intelligent and deeply human. Our platform runs over one million predictions per borrower using more than 1,800 signals, powering smarter, fairer decisions for millions of customers. But the numbers only hint at the impact. Every idea, every voice, and every contribution moves us closer to a world where credit never stands between people and their financial progress. We’re proudly digital-first, giving most Upstarters the flexibility to do their best work from wherever they thrive, alongside teammates across 80+ cities in the US and Canada. Digital-first doesn’t mean distant. We’re intentional about in-person connection through team onsites, planning sessions, and moments that spark creativity and trust. And whether you choose to work primarily from home or collaborate in-person from one of our offices in Columbus, Austin, the Bay Area, or New York City (opening Summer 2026), you’ll have the support to work in the way that works best for you. If you’re energized by tackling meaningful problems, excited to innovate with purpose, and motivated by work that truly matters, we’d love to hear from you. The Team Upstart’s Information Security team is dedicated to advancing security practices that enhance the safety of our products, customers, and partners. We believe security should empower innovation, move at the speed of the business, and be built in from the ground up. Our mission is to protect Upstart’s products and enterprise while enabling teams to move quickly and safely through strong collaboration, automation, and thoughtful security design. As a Principal Security Engineer focused on Data Security, you will play a critical role in defining, building, and leading Upstart’s data security program. This is a highly impactful role that combines deep hands-on technical execution with program leadership. You will design and implement scalable data security capabilities, influence cross-functional partners across the company, and help establish long-term strategy and accountability for how data is protected at Upstart. This role is ideal for a senior security practitioner who enjoys operating at the intersection of coding, architecture, and cross-functional leadership, and who has experience taking complex security programs from concept to reality. Position Location - This role is available in the following locations: Remote (US), San Mateo, Columbus, Austin Time Zone Requirements - This team operates on the East/West Coast time zones. Travel Requirements - As a digital first company, the majority of your work can be accomplished remotely. The majority of our employees can live and work anywhere in the U.S but are encouraged to to still spend high quality time in-person collaborating via regular onsites. The in-person sessions’ cadence varies depending on the team and role; most teams meet once or twice per quarter for 2-4 consecutive days at a time. How you’ll make an impact: - Lead the design and execution of Upstart’s data security program, from early foundations through mature, scalable systems - Architect and build software solutions (APIs, services, and internal tools) that enable effective data protection and governance - Partner closely with Engineering, Analytics, Product, Legal, Risk, HR, and other stakeholders to secure sensitive data across diverse domains - Establish clear goals, success metrics, and accountability for data security initiatives - Drive adoption of least-privilege access models and modern data protection patterns across the organization - Mentor engineers and security practitioners, fostering strong technical standards and a culture of ownership - Continuously improve systems by learning from real-world signals such as false positives, operational feedback, and evolving threats What we’re looking for: - Minimum requirements: - Bachelor’s degree in Computer Science, Engineering, or Mathematics, or a related field (or its equivalent) + 8 years of experience - Extensive experience across enterprise and operational security domains, with deep focus on Data Security and Identity & Access Management - Experience owning or leading a Data Security, DLP (Data Loss Prevention), or DSPM (Data Security Posture Management) initiatives - Proven experience leading security programs that span multiple teams and functions - Strong software engineering background, with the ability to design and build production-quality systems (e.g., APIs, services, or internal web applications) - Experience launching new security capabilities or programs from 0 to 1 in complex environments - Deep understanding of least-privilege principles and practical experience applying them at scale - Excellent communication skills, with the ability to influence senior technical and non-technical stakeholders - Ability to navigate ambiguity, make sound tradeoffs, and independently drive meaningful change - Preferred qualifications: - Familiarity with modern data protection tooling such as endpoint DLP, data classification, or posture management platforms - Experience working with diverse data domains (e.g., analytics, reporting, business operations, or people data) - Contributions to the security community through talks, publications, open-source projects, or other industry involvement - Familiarity with compliance frameworks such as SOC 1, SOC 2, and SOX - Interest in long-term growth as a senior individual contributor, with openness to future people leadership paths At Upstart, your base pay is one part of your total compensation package. The anticipated base salary for this position is expected to be within the below range. Your actual base pay will depend on your geographic location–with our “digital first” philosophy, Upstart uses compensation regions that vary depending on location. Individual pay is also determined by job-related skills, experience, and relevant education or training. Your recruiter can share more about the specific salary range for your preferred location during the hiring process. In addition, Upstart provides employees with target bonuses, equity compensation, and generous benefits packages (including medical, dental, vision, and 401k). United States | Remote - Anticipated Base Salary Range $190,600—$263,900 USD What you'll love At Upstart, our benefits are designed to support your health, financial well-being, family, and personal growth. Here’s what you can expect: - Competitive compensation, including base pay, bonus opportunities, and annual equity grants that vest quarterly - Generous 401(k) plan with Upstart matching $2 for every $1 contributed, up to $15,000 per year - Employee Stock Purchase Plan (ESPP) with discounted stock purchase options for eligible employees - Affordable medical, dental, and vision coverage, with multiple plan options - Upstart covers 90% to 100% of the cost depending on the plans you choose - Health Savings Account contributions from Upstart for eligible plans - Income protection benefits, including company-paid Basic Life, AD&D, and Short- and Long-Term Disability coverage, with options to purchase supplemental coverage - Paid time off, sick and safe time, and company holidays - Paid family and parental leave to support caregiving and major life moments - Family-centered benefits through Carrot and Cleo, supporting fertility, parenthood, and caregiving - Employee Assistance Program (EAP) offering mental health support and life-centered resources - Financial wellness resources, including access to financial planning tools and a financial concierge service - Annual wellness allowance to support your physical and emotional well-being and personal development, based on what matters most to you - Annual productivity allowance to invest in relevant tools and resources you need to do your best work, no matter where you work from - Connection and community through team events and onsites, all-company updates, and employee resource groups (ERGs) - Onsite perks, including catered lunches and fully stocked micro-kitchens when working from one of our four offices, located in the Bay Area, Austin, Columbus, and New York City (opening Summer 2026!). Upstart is a proud Equal Opportunity Employer. Just as we are dedicated to improving access to affordable credit for all, we are committed to inclusive and fair hiring practices. If you require reasonable accommodation in completing an application, interviewing, completing any pre-employment testing, or otherwise participating in the employee selection process, please email candidate_accommodations@upstart.com https://www.upstart.com/candidate_privacy_policy

Benefits

  • 401(K), 401(K) matching, Adoption Assistance, Company equity, Company-sponsored outings, Company sponsored family events, Continuing education stipend, Dental insurance, Disability insurance, Employee stock purchase plan, Family medical leave, Fitness stipend, Flexible Spending Account (FSA), Flexible work schedule, Free daily meals, Generous parental leave, Generous PTO, Company-sponsored happy hours, Health insurance, Highly diverse management team, Job training & conferences, Open door policy, Life insurance, Mentorship program, Online course subscriptions available, Open office floor plan, Paid holidays, Paid sick days, Onsite office parking, Performance bonus, Promote from within, Recreational clubs, Lunch and learns, Relocation assistance, Remote work program, Return-to-work program post parental leave, Free snacks and drinks, Team based strategic planning, OKR operational model, Mandated unconscious bias training, Unlimited vacation policy, Vision insurance, Wellness programs, Mental health benefits, Home-office stipend for remote employees, Diversity employee resource groups, Hiring practices that promote diversity, Fertility benefits, Employee resource groups, Employee-led culture committees, Hybrid work model, In-person all-hands meetings, Pay transparency, Mother's room, Virtual coaching services, Flexible time off, Bereavement leave benefits

Related Categories

Related Job Pages

More Security Engineer Jobs

Immersive Labs logo

Senior Cloud Security Engineer

Immersive Labs

The leader in people-centric cyber resilience.

Full TimeRemoteTeam 201-500Since 2017H1B No Sponsor

• Utilising knowledge of cloud technology to plan, write and improve cloud security labs, challenges and online learning content on the Immersive platform. • Produce multi-format content utilising various teaching methods; practical exercises, questions & gamification • Test Cloud Security labs to ensure they function as expected • Work with the Engineering and Content teams on new projects/products and how best to deploy them

United Kingdom
Job Closed
DigitalOcean logo

Staff Product Security Engineer

DigitalOcean

The cloud ☁️ of choice for developers, startups, and growing digital businesses around the world.

Full TimeRemoteTeam 1,001-5,000Since 2011H1B Sponsor

• Threat model application designs and solutions and provide security risk assessments. • Collaborate with product managers, designers, and engineers to threat model and architect secure and resilient systems. • Design and build internal tooling for engineering teams. • Write robust, resilient, and maintainable software primarily in Go and Python. • Champion an internal security culture, mentor teams in security best practices, and oversee vulnerability management program.

Texas
$170K - $200K / year
Job Closed
Logically logo

Network Security Engineer I

Logically

Intelligence for high-stakes environments, where timing, perception, and context all matter.

Full TimeRemoteTeam 51-200Since 2017H1B No Sponsor

• Provide best in class customer service to Logically’s customer base • Adhere to company values while following best practices and operational procedures • Ensure compliance with company policies, procedures, and all contractual and regulatory requirements • Manage the status of open tickets/projects and complete technical and operational tasks to address project deliverables efficiently and accurately • Implement secure networks on case-by-case bases dependent upon circumstantial business and technology requirements • Responsible for implementing appropriate IT security procedures, configuring security software, and implementing security administration functions across multiple platforms • Responsible for performing product deployments and assessments as well as making recommendations to enhance and expand the cybersecurity portfolio of customers • Collaborate with the team to ensure customer service level agreements (SLA) are met • Provide network and firewall support to customers • Provide support, engineering, configuration, and troubleshooting for network security infrastructure • Perform network troubleshooting, network traffic analysis and debugging, security incident response; implement VPN encryption • Develop and maintain network security documentation • Apply risk management framework to assess cybersecurity risks of network appliances and provide strategic recommendations to bolster security and reduce attack surface while maintaining required operational capabilities • Participate in on-call support rotation

Ohio
$270K / year
Job Closed

Application Security Architect

RGA - Reinsurance Group of America

Reinsurance Group of America (RGA), founded in 1973 and headquartered in Chesterfield, Missouri, is a global provider of health and life insurance. RGA has prov

• Partner with engineering teams to build secure software • Help developers write secure code and resolve false positives • Conduct Secure by Design reviews for applications • Lead threat modeling workshops and document risk mitigations • Advise on security of CI/CD practices and third-party dependencies • Collaborate to integrate security controls into workflows • Provide security architecture guidance for AI/ML applications

Minnesota
$150.8K - $224.6K / year
Job Closed