Principal DevSecOps Engineer


Upgrade Inc. logo
Upgrade Inc.
Apply now Apply later

Posted 3 weeks ago

Upgrade aims to deliver frictionless mobile banking and exceptional value to mainstream consumers. Founded in 2017, Upgrade has already originated over $3 billion in consumer credit.
Upgrade products are designed to create a new banking experience that seeks to eliminate fees on everyday transactions and offer access to more affordable and responsible credit through cards and loans. In 3 short years 10 million people have already applied for an Upgrade Card or loan.
Upgrade has been named a “Best Place to Work in the Bay Area” by the San Francisco Business Times and Silicon Valley Business Journal, and received “Best Company for Women” and “Best Company for Diversity” awards from Comparably.
We are looking for new team members who are excited about creating, designing and implementing new and better solutions to join a team of 300 talented and passionate professionals. Come join us if you like to tackle big problems and make a meaningful difference in people's lives.


  • Lead the security strategy governing the applications and cloud-based platform infrastructure.
  • Collaborate with other infrastructure, DevOps, InfoSec and application engineers to understand the product, technology and business needs. 
  • Define and own guidance, alerts and security as code deployments to provide protection from malicious traffic, vulnerabilities and other attack vectors.
  • Oversee building and maintaining an AWS cloud infrastructure architecture aligning security, compliance, performance and resilience. 
  • Own the management and remediation of identified security flaws within our development platforms.
  • Build and maintain monitoring, auditing, and reporting frameworks that produce artifacts that support security and compliance needs.
  • Architect procedures to automate security tasks which seamlessly integrate into code builds and deployments.
  • Build security utilities and tools for internal use that enable the DevSecOps team to operate at high speed and wide scale.
  • Develop security and compliance capabilities in support of DevOps processes.
  • Create and maintain documentation for security systems.
  • Participate in an on-call rotation for 24x7 support of security operations. 
  • Research security industry trends and best practices to share with the organization through presentations and training sessions.  

You are:

  • Highly motivated and self driven.
  • Enjoy collaborating and working in small teams and cross teams. 
  • Technically strong and hands-on.
  • Good at multitasking and thrive in fast-paced environments.
  • Methodical, thorough, and solution oriented.
  • Enjoy learning new technologies and applying that to solving problems.
  • Excellent written and verbal communication skills.


  • At least 5+ years of relevant experience in modern DevSecOps space.
  • Expert level understanding of security best practices for client-server product architectures for cloud-based deployments.
  • In-depth knowledge of AWS services and hands-on experience.
  • Experience in performing security vulnerability assessments, good familiarity with PCI and SOX.
  • Knowledge of SSO methodologies (SAML, LDAPS, AD).
  • Experience in DevOps environments and maintaining security in CI/CD processes.
  • Experience in HashiCorp Vault.
  • Experience with Kubernetes and containerized applications.
  • Experience developing infrastructure as code (Terraform, Ansible).
  • Experience designing processes around DevSecOps tools.
  • Experience with cloud-based security management/IDS/IPS/SIEM tools (WAF, Inspector, GuardDuty, Twistlock, Splunk, Dome9, AlienVault, AlertLogic, Fortinet, Threat Stack, Sumologic, Imperva etc).
  • Knowledge of network based, system level, and application layer attacks and mitigation methods.
  • Experience extracting security data from SIEM solutions, audit logs.
  • Strong programming/scripting knowledge - Go, Python, Bash, etc.

Strong Plus:

  • Experience in OOP, TDD, design patterns, data structures and software security.
  • Experience with other IaaT platforms.
  • One or more recognized security and cloud specific certifications (e.g. CCSP, SSCP, CISSP, CCSK, GWAP, AWS Solutions Architect).


  • Downtown office location near Square Victoria.
  • Comprehensive benefits package including medical, dental, & vision.
  • Unlimited vacation policy.
  • Catered lunch every Thursday.
  • Kitchen stocked with beverages, snacks & treats. 
  • In office game rooms (ping pong, foosball, pool).
  • Monthly social gatherings.
We are an equal opportunity employer and value diversity at our company. We do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status.
Job tags: Architecture Auditing AWS Banking CISSP DevOps Go IDS IPS PCI Python SIEM Splunk SSCP Strategy Vulnerabilities