Base Career helps you apply smarter for this job.
Key skills for this role
CharterUP is seeking a Senior Application Security Engineer to raise the bar on how we build and ship secure software. This is a dedicated security role on the Platform Engineering team. Our applications handle customer PII, passenger manifests, trip and location data, and payment flows, and they enforce authorization boundaries between thousands of parties in a two-sided marketplace. You'll be the technical leader on application security here, setting our standards, defining what "secure enough to ship" means, owning security decisions in design and code review, and driving vulnerabilities through remediation. Expect to split your time roughly evenly between building security tooling and automation and conducting threat modeling, design reviews, and targeted code reviews.
Innovative Impact: Be part of the team that's revolutionizing group travel, setting new standards in an industry overdue for change.
Growth Opportunities: As a hyper growth company and one of the fastest-growing companies recognized by Inc., there’s no better time to join our dynamic, growth-stage organization.
Driven Team: Collaborate with some of the most driven minds in tech, all while working in a remote-first environment with a tech hub in Austin, TX.
Funding and Stability: Our $60 million Series A funding was just the start—we’re poised for even greater expansion, and you can be part of this exciting journey. CharterUp has achieved this growth profitability and efficiently, ensuring long-term stability.
CharterUP is seeking a Senior Application Security Engineer to raise the bar on how we build and ship secure software. This is a dedicated security role on the Platform Engineering team. Our applications handle customer PII, passenger manifests, trip and location data, and payment flows, and they enforce authorization boundaries between thousands of parties in a two-sided marketplace. You'll be the technical leader on application security here, setting our standards, defining what "secure enough to ship" means, owning security decisions in design and code review, and driving vulnerabilities through remediation. Expect to split your time roughly evenly between building security tooling and automation and conducting threat modeling, design reviews, and targeted code reviews.
Skip the repetitive application forms
Install the Base Career Chrome Extension and autofill job applications across major job boards with your profile.
Trusted by over 500,000 job seekers on Base Career
More from this employer
Austin, USA
Austin, USA
Austin, USA
Austin, USA
, USA
Austin, USA
, USA
, USA
Own security tooling and vulnerability management across SAST, dependency and container scanning, secret detection, and penetration testing, including triage, routing, and remediation SLAs
Lead security design reviews, threat modeling, and targeted manual code reviews for high-risk systems, including authentication, authorization, payments, and customer data
Identify and prevent multi-tenant authorization vulnerabilities across quoting, booking, and trip workflows through scalable patterns and automated testing
Strengthen AWS security through IAM and account boundary design, secrets management, workload protection, and comprehensive logging
Scale security across engineering by building secure defaults, reusable libraries, automation, and developer guardrails, and establishing a security champions practice
5+ years of experience in software engineering or security, including 3+ years in application or product security
Strong software engineering skills in Java and/or TypeScript, with experience building production-grade security tooling, automation, libraries, and developer-facing solutions
Deep expertise in application security, including threat modeling, secure system design, authentication, authorization, access control, injection, SSRF, and manual code review; familiarity with security and compliance standards, including SOC 2, PCI DSS, and GDPR is a plus.
Hands-on experience with AWS and cloud-native security, including IAM, multi-account architecture, containerized workloads, CI/CD security, and vulnerability management
Strong technical judgment and influence, with the ability to set security standards, prioritize risk, and drive remediation across engineering teams without direct authority
Step 1 - Video call: Talent Acquisition interview
Step 2 - Video call: Technical interview
Step 3 - Video call: Team interviews
Step 4 - Offer & reference check
Welcome aboard!
AI-powered charter bus marketplace serving corporations, schools, governments, events, and group transportation programs.
Visit company websiteJobs and hiring trendsFull-time
Senior · 5+ years experience
Hybrid
Apply faster on company sites with our extension.