Senior Application Security Engineer
About the Role
CharterUP is seeking a Senior Application Security Engineer to raise the bar on how we build and ship secure software. This is a dedicated security role on the Platform Engineering team. Our applications handle customer PII, passenger manifests, trip and location data, and payment flows, and they enforce authorization boundaries between thousands of parties in a two-sided marketplace. You'll be the technical leader on application security here, setting our standards, defining what "secure enough to ship" means, owning security decisions in design and code review, and driving vulnerabilities through remediation. Expect to split your time roughly evenly between building security tooling and automation and conducting threat modeling, design reviews, and targeted code reviews.
Title: Senior Application Security Engineer
Reports to: Engineering Manager
Location: Austin, TX (Hybrid: Monday, Wednesday, Friday in-office)
What You’ll Do
Own security tooling and vulnerability management across SAST, dependency and container scanning, secret detection, and penetration testing, including triage, routing, and remediation SLAs
Lead security design reviews, threat modeling, and targeted manual code reviews for high-risk systems, including authentication, authorization, payments, and customer data
Identify and prevent multi-tenant authorization vulnerabilities across quoting, booking, and trip workflows through scalable patterns and automated testing
Strengthen AWS security through IAM and account boundary design, secrets management, workload protection, and comprehensive logging
Scale security across engineering by building secure defaults, reusable libraries, automation, and developer guardrails, and establishing a security champions practice
What You’ll Bring
5+ years of experience in software engineering or security, including 3+ years in application or product security
Strong software engineering skills in Java and/or TypeScript, with experience building production-grade security tooling, automation, libraries, and developer-facing solutions
Deep expertise in application security, including threat modeling, secure system design, authentication, authorization, access control, injection, SSRF, and manual code review; familiarity with security and compliance standards, including SOC 2, PCI DSS, and GDPR is a plus.
Hands-on experience with AWS and cloud-native security, including IAM, multi-account architecture, containerized workloads, CI/CD security, and vulnerability management
Strong technical judgment and influence, with the ability to set security standards, prioritize risk, and drive remediation across engineering teams without direct authority
Recruiting Process
Step 1 - Video call: Talent Acquisition interview
Step 2 - Video call: Technical interview
Step 3 - Video call: Team interviews
Step 4 - Offer & reference check
Welcome aboard!
Salary
$150,000—$180,000 USD