Himalayas logo
UpgradeUP

Senior Application Security Developer

Upgrade, Inc. is an American neobank founded in 2016 that offers credit and banking products to consumers, including fixed-rate credit cards, personal loans, rewards checking accounts, and credit monitoring tools.

Upgrade

Employee count: 1001-5000

Salary: 150k-250k CAD

Canada only

Upgrade is a fintech company that provides affordable and responsible credit, mobile banking, and payment products to everyday consumers. We were the fastest growing company in the Americas last year according to the Financial Times and Upgrade Card was the fastest growing credit card in America two years in a row. We have delivered over $33 billion in affordable and responsible credit to our 5.5M customers. The company is backed by some of the most prominent technology investors and was recently valued at $6.3B.

We have built an energizing, collaborative and inclusive culture where team members help each other, learn and innovate to move the company and its customers in the right direction, and own the outcome of their efforts.

Upgrade has been named a “Best Place to Work in the Bay Area” three years in a row, “Top Companies to work for in Arizona” and one of the "Best Engineering Department" awarded annually by Comparably. We've also received recognition for being a best company for Diversity, Women, Culture, and Veterans.

We are looking for new team members who get excited about designing and delivering new and better products to join a team of 1850 talented and dedicated professionals. Come work with us if you like to tackle big problems and make a meaningful difference in people's lives.


About the Role:

As a Senior Application Security Developer, you’ll help scale our static and dynamic code analysis, handle manual and automated pen-testing, threat modeling, and lead the overall improvement of our AppSec posture. You’ll collaborate alongside DevOps, QA, and Engineering to improve the security of applications architected on the cloud (AWS) in a microservices-based environment.


What You’ll Do:

  • Evaluate our security technology, methodology, and tools to better the software development life cycle
  • Help train developers, and QA personnel to the appropriate level of software security knowledge to perform their responsibilities
  • Improve and support application security tool services including static analysis, dynamic testing, software composition analysis tools
  • Support incident response and architecture review processes whenever application security expertise is needed
  • Manage routine penetration testing services, including both expert consulting and managed services
  • Provide manual penetration testing and standards gap analysis services to internal business and technology partners
  • Support, improve, and maintain secure development standards and application security framework projects
  • Support Vendor Management activities to ensure third party software and development meet security standards
  • Integrate threat modeling practices into the product development life cycle
  • Provide security requirements for test driven design to assess control effectiveness
  • Produce metrics reporting the state of application security programs and performance of development teams against requirements

What We Look For:

  • 5+ years of relevant work experience.
  • Experience with agile development processes and have experience integrating secure development practices into the model
  • Experience writing and testing web applications, mobile applications and microservices
  • Familiarity with GraphQL architecture and security best practices
  • Basic understanding of authentication and authorization schemes including OAuth
  • Familiarity with a variety of development and testing tools
  • Experience working with one or more SAST, DAST and IAST tools
  • Ability to explain vulnerabilities and weaknesses, and discuss effective defensive techniques
  • Experience with cyber security attacks and mitigation methods (red/blue team experience)
  • Experience working with web applications and browser security; security assessments and penetration testing; identity and access control; applied cryptography and security protocols; security information and event monitoring and intrusion detection
  • Expertise in employing analytics and threat intelligence techniques, Incident response process; Software security
  • Experience in IT supply-chain risk management and assurance, as well as cloud security operations

Nice to Have:

  • Basic familiarity with Python for security tool automation would be a plus.


What We Offer You:

  • Competitive salary and stock option plan
  • 100% paid coverage of medical, dental and vision insurance
  • Flexible PTO
  • Competitive 401(k) and RRSP program
  • Opportunities for professional growth and development
  • Paid parental leave
  • Health wellness initiatives

The compensation range of this position in Canada is $150,000 - $250,000 CAD annually plus equity and benefits. Within this range, an individual's base pay will be dependent on a variety of factors, including without limitation, job-related knowledge, skills, education, and experience.

#BI-Remote

We are an equal opportunity employer and value diversity at our company. We do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status.

Upgrade does not accept unsolicited resumes from staffing agencies, search firms, or any third parties. Any resume submitted to any employee of Upgrade without a prior written agreement in place will be considered the property of Upgrade, and Upgrade will not be obligated to pay any referral or placement fee. Agencies must obtain advance written approval from Upgrade's Talent Acquisition department to submit resumes and only in conjunction with a valid, fully executed agreement.

About the job

Apply before

Posted on

Job type

Full Time

Experience level

Senior

Salary

Salary: 150k-250k CAD

Location requirements

Hiring timezones

Canada +/- 0 hours

About Upgrade

Learn more about Upgrade and their company culture.

View company profile

Upgrade's journey began in August 2016, spearheaded by Renaud Laplanche, the visionary founder and former CEO of LendingClub, alongside a team of his former colleagues. The company officially launched its loan offerings in April 2017, quickly securing a significant $60 million in a Series A funding round. This initial success set the stage for a period of rapid innovation and growth. By April 2018, Upgrade unveiled a personal credit line, a novel hybrid product combining the features of a credit card and a personal loan, at the LendIt Conference in San Francisco. This was followed by the launch of the Upgrade Card in October 2019, a product designed to merge the broad acceptance of credit cards with the predictable payment structure of installment loans.

The company's innovative approach to consumer finance continued to attract significant investment and recognition. In June 2020, Upgrade achieved a $1 billion valuation following a Series D equity round led by Santander Group. The momentum continued, and by August 2021, a Series E funding round led by Koch Disruptive Technologies pushed its valuation to $3.3 billion. Just a month later, in September 2021, the Nilson Report distinguished Upgrade Card as the fastest-growing credit card in the United States. This rapid ascent was further underscored in November 2021 when Upgrade's valuation soared to $6.28 billion after a $280 million Series F funding round co-led by Coatue Management and DST Global. Expanding its offerings, Upgrade acquired the travel-focused Buy Now, Pay Later (BNPL) provider Uplift in July 2023 for $100 million, integrating travel financing into its diverse portfolio. Uplift was subsequently rebranded to Flex Pay in December 2024, signaling a new phase of growth and expanded opportunities for customers across the U.S. and Canada. Throughout its journey, Upgrade has remained committed to providing affordable and responsible credit, mobile banking, and payment products, helping millions of families manage their finances more effectively.

Claim this profileUpgrade logoUP

Upgrade

View company profile

Similar remote jobs

Here are other jobs you might want to apply for.

View all remote jobs

10 remote jobs at Upgrade

Explore the variety of open remote roles at Upgrade, offering flexible work options across multiple disciplines and skill levels.

View all jobs at Upgrade

Remote companies like Upgrade

Find your next opportunity by exploring profiles of companies that are similar to Upgrade. Compare culture, benefits, and job openings on Himalayas.

View all companies

Find your dream job

Sign up now and join over 100,000 remote workers who receive personalized job alerts, curated job matches, and more for free!

Sign up
Himalayas profile for an example user named Frankie Sullivan
Upgrade hiring Senior Application Security Developer • Remote (Work from Home) | Himalayas