Senior Application Security Engineer

Charterup · Austin, Texas · Engineering

Posted 2026-09-03

Apply for this role →

About the Role

CharterUP is seeking a Senior Application Security Engineer to raise the bar on how we build and ship secure software. This is a dedicated security role on the Platform Engineering team. Our applications handle customer PII, passenger manifests, trip and location data, and payment flows, and they enforce authorization boundaries between thousands of parties in a two-sided marketplace. You'll be the technical leader on application security here, setting our standards, defining what "secure enough to ship" means, owning security decisions in design and code review, and driving vulnerabilities through remediation. Expect to split your time roughly evenly between building security tooling and automation and conducting threat modeling, design reviews, and targeted code reviews.

Title: Senior Application Security Engineer

Reports to: Engineering Manager

Location: Austin, TX (Hybrid: Monday, Wednesday, Friday in-office)

What You’ll Do

Own security tooling and vulnerability management across SAST, dependency and container scanning, secret detection, and penetration testing, including triage, routing, and remediation SLAs

Lead security design reviews, threat modeling, and targeted manual code reviews for high-risk systems, including authentication, authorization, payments, and customer data

Identify and prevent multi-tenant authorization vulnerabilities across quoting, booking, and trip workflows through scalable patterns and automated testing

Strengthen AWS security through IAM and account boundary design, secrets management, workload protection, and comprehensive logging

Scale security across engineering by building secure defaults, reusable libraries, automation, and developer guardrails, and establishing a security champions practice

What You’ll Bring

5+ years of experience in software engineering or security, including 3+ years in application or product security

Strong software engineering skills in Java and/or TypeScript, with experience building production-grade security tooling, automation, libraries, and developer-facing solutions

Deep expertise in application security, including threat modeling, secure system design, authentication, authorization, access control, injection, SSRF, and manual code review; familiarity with security and compliance standards, including SOC 2, PCI DSS, and GDPR is a plus.

Hands-on experience with AWS and cloud-native security, including IAM, multi-account architecture, containerized workloads, CI/CD security, and vulnerability management

Strong technical judgment and influence, with the ability to set security standards, prioritize risk, and drive remediation across engineering teams without direct authority

Recruiting Process

Step 1 - Video call: Talent Acquisition interview

Step 2 - Video call: Technical interview

Step 3 - Video call: Team interviews

Step 4 - Offer & reference check

Welcome aboard!

Salary

$150,000—$180,000 USD

Apply for this role →

← Back to all jobs