Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy
Jobs / Job page
Sr. Application Security Engineer image - Rise Careers
Job details

Sr. Application Security Engineer

We are seeking a Sr. Application Security Engineer to join our security team. In this role, you will be a critical partner to engineering, product, and DevOps teams, helping to identify, assess, and mitigate security risks across the software development lifecycle (SDLC). You will drive security by design, shape our product security standards, and ensure vulnerabilities are identified, tracked, and resolved efficiently.


This is a hands-on technical role where you will lead secure architecture/design reviews, code reviews, and penetration testing while collaborating closely with teams to embed security in every phase of product development.


Problems You Will Solve
  • Partner with engineering and product teams to define and implement security requirements for applications, APIs, and microservices during design and architecture reviews.
  • Conduct in-house penetration testing, secure code reviews, and threat modeling for high-impact features and critical products.
  • Lead application vulnerability management, including triaging and driving the remediation of security findings from SAST, DAST, SCA, and penetration tests.
  • Consult and advise cross-functional teams (engineering, DevOps, product) on secure coding practices, security architecture, and remediation strategies.
  • Establish and maintain application security standards, guidelines, and best practices, aligned with OWASP, NIST, ISO, and industry frameworks.
  • Ensure vulnerabilities are classified, prioritized, and remediated according to vulnerability management policies and regulatory requirements.
  • Work closely with DevSecOps teams to ensure SAST/DAST/IAST/SCA tools are integrated into CI/CD pipelines and functioning effectively.
  • Track and manage security issues to resolution, providing metrics, reports, and dashboards for leadership visibility.
  • Stay up-to-date with emerging security threats, vulnerabilities, tools, and methodologies to continuously improve Prosper’s security posture.


All About You
  • Bachelor’s degree in Computer Science, Information Security, or related field, with 8+ years of relevant experience (or Master’s degree with 6+ years).
  • Strong hands-on experience in application security, secure coding, and penetration testing.
  • Development background with expertise in Java/Python, SQL, JavaScript, HTML and experience reviewing modern application architectures.
  • Experience working with modern web application frameworks (e.g., Spring Boot, .NET, J2EE, Rails, REST, SOAP).
  • In-depth understanding of web and API security vulnerabilities (e.g., OWASP Top 10, API Top 10, CWE).
  • Familiarity with authentication and authorization protocols (e.g., OAuth2, OIDC, SAML).
  • Knowledge of application security testing tools (SAST, DAST, SCA, IAST) and methodologies.
  • Proven experience working with DevOps/DevSecOps pipelines, integrating security tools and automation.
  • Strong understanding of vulnerability management processes and regulatory frameworks (e.g., PCI DSS, GDPR, SOC 2).
  • Bonus: Knowledge of cloud security (AWS, GCP, Azure) and container security (Docker, Kubernetes).
  • Security experience in Agile, CI/CD, and fast-paced product development environments.
  • Preferred: Industry certifications such as OSCP, CSSLP, GWAPT, CEH, GPEN, CISSP.
  • Preferred: Familiarity with mobile application security testing and API security testing tools (e.g., Burp Suite, Postman, ZAP, Insomnia).
  • Preferred: Knowledge of network security, infrastructure security, and microservices architecture.
  • Preferred: Experience driving secure SDLC initiatives and developer security education.


What We Offer
  • The opportunity to collaborate with a team of creative, fun, and driven colleagues on products that have an immediate and significant impact on people's lives
  • The opportunity to work in a fast-paced environment with experienced industry leaders
  • Flexible time off, comprehensive health coverage, competitive salary, paid parental leave
  • Wellness benefits including access to mental health resources, virtual HIIT and yoga workouts
  • A bevy of other perks including Udemy access, childcare assistance, pet insurance discounts, legal assistance, and additional discounts


$189,000 - $211,000 a year
Compensation details: The salary for this position is $189,000 - $211,000 annually, plus bonus and generous benefits. In determining your salary, we will consider your location, experience, and other job-related factors.

#LI-AW1

#IND1




About Our Technology Team

We are growing our Technology team to support our various financial products. The ideal candidate is passionate about learning the Fintech domain and delivering cutting-edge, high-quality solutions to solve business problems. We utilize a progressive, test-driven, Agile development methodology that places a high premium on communication, teamwork, sound design and clean implementation. 


About Us

Founded in 2005 as the first peer-to-peer marketplace lending platform in the U.S., Prosper was built on a simple idea: connect people who want to borrow money with those who want to invest. Since inception, Prosper has helped more than 2 million people gain access to affordable credit with over $27 billion in loans originated through its platform. Our mission is to help our customers advance their financial well-being through a variety of products including personal loans, credit, home equity lines of credit (HELOC), and our newest product, HELoan. Our diverse culture rewards accountability and cross functional teamwork because we believe this encourages innovative thinking and helps us deliver on our mission.  

 

We’re on a mission to hire the very best, and we are committed to creating exceptional employee experiences where everyone is respected and has access to equal opportunity. We realize that new ideas can come from everywhere. It is important to us that every hire connects with our vision, mission, and core values. Join a leading fintech company that’s democratizing finance for all!  


Our Values

Diversity expands opportunities

Collaboration creates better solutions

Curiosity fuels our innovation

Integrity defines all our relationships

Excellence leads to longevity 

Simplicity guides our user experience 

Accountability at all levels drives results


www.prosper.com

Our Story & Team  //   Our Blog 


Applicants have rights under Federal Employment Laws.

Family & Medical Leave Act (FMLA)

Equal Employment Opportunity (EEO)

Employee Polygraph Protection Act (EPPA)  


California applicants: please click here to view our California Consumer Privacy Act (“CCPA”) Notice for Applicants, which describes your rights under the CCPA: https://www.prosper.com/plp/legal/privacy-notice-for-applicants/


At Prosper, we're looking for people with passion, integrity, and a hunger to learn. We encourage you to apply even if your experience doesn't precisely match the job description. Your unique skill set and diverse perspective will stand out and set you apart from other candidates. Prosper thrives with people who think outside of the box and aren't afraid to challenge the status quo. We invite you to join us on our mission to advance financial well-being.


Prosper is committed to an inclusive and diverse workplace. All aspects of employment including the decision to hire, promote, discipline, or discharge, will be based on merit, competence, performance, and business needs. We do not discriminate on the basis of race, color, religion, marital status, age, national origin, ancestry, physical or mental disability, medical​​​ condition, pregnancy, genetic information, gender, sexual orientation, gender identity or expression, veteran status, or any other status protected under federal, state, or local law, including the San Francisco Fair Chance Ordinance. Prosper will consider for employment qualified applicants who are non-US citizens and will provide green card sponsorship.

Average salary estimate

$200000 / YEARLY (est.)
min
max
$189000K
$211000K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

What You Should Know About Sr. Application Security Engineer, Prosper

At Prosper, we’re on the lookout for a Sr. Application Security Engineer to join our dynamic security team! In this crucial role, you’ll become an indispensable partner to our engineering, product, and DevOps teams, helping them identify, assess, and mitigate security risks throughout the software development lifecycle (SDLC). You’ll have the opportunity to drive security by design, shaping our product security standards and ensuring any vulnerabilities are efficiently tracked and resolved. What’s even more exciting is that this hands-on technical position involves leading secure architecture and design reviews, performing code reviews, and conducting penetration testing while collaborating closely with our teams to embed security in every phase of product development. You will be responsible for defining and implementing security requirements for applications, conducting in-house penetration tests, and leading application vulnerability management. With a focus on maintaining application security standards aligned with industry frameworks, your expertise will directly impact our ability to innovate securely. Your strong background in application security, secure coding, and development experience will be key, as you help to ensure our systems are robust against emerging threats. If you’re looking to make a significant impact within a fast-paced Fintech environment, this position promises to be both challenging and rewarding. Embrace the chance to work alongside driven professionals while enjoying perks such as flexible time off, comprehensive health coverage, and opportunities for professional growth.

Frequently Asked Questions (FAQs) for Sr. Application Security Engineer Role at Prosper
What are the key responsibilities of a Sr. Application Security Engineer at Prosper?

As a Sr. Application Security Engineer at Prosper, your key responsibilities will include collaborating with engineering and product teams to define security requirements for applications, conducting penetration testing, leading secure architecture reviews, and managing vulnerabilities. You’ll ensure that security practices are integrated into every stage of product development while driving the remediation of security findings from various testing methodologies.

Join Rise to see the full answer
What qualifications are required for the Sr. Application Security Engineer position at Prosper?

To qualify for the Sr. Application Security Engineer position at Prosper, candidates should have a Bachelor’s degree in Computer Science, Information Security, or a related field with at least 8 years of relevant experience (or a Master’s degree with 6+ years). Essential skills include strong hands-on experience in application security, secure coding, and penetration testing, along with proficiency in languages like Java or Python. Industry certifications such as OSCP, CSSLP, or CISSP are preferred.

Join Rise to see the full answer
How does Prosper promote security in its development processes for the Sr. Application Security Engineer role?

At Prosper, the Sr. Application Security Engineer promotes security in development processes by partnering with cross-functional teams to establish security requirements, implementing security measures during architecture reviews, and leveraging security tools integrated into CI/CD pipelines. The role emphasizes continuous improvement and collaboration to ensure all applications are developed with security best practices in mind.

Join Rise to see the full answer
What tools and methodologies should a Sr. Application Security Engineer at Prosper be familiar with?

A Sr. Application Security Engineer at Prosper should be familiar with a variety of application security testing tools including SAST, DAST, and IAST, as well as methodologies pertaining to secure coding practices and vulnerability management processes. Understanding industry frameworks like OWASP, PCI DSS, and cloud security tools will also be highly beneficial.

Join Rise to see the full answer
What is the work environment like for a Sr. Application Security Engineer at Prosper?

The work environment for a Sr. Application Security Engineer at Prosper is fast-paced and collaborative, designed to encourage creativity and innovation. You’ll work alongside passionate professionals who value integrity and teamwork, supported by a culture that promotes continuous learning and professional growth while offering comprehensive wellness benefits and flexible work arrangements.

Join Rise to see the full answer
Common Interview Questions for Sr. Application Security Engineer
Can you explain the role of a Sr. Application Security Engineer in the SDLC?

In the SDLC, the Sr. Application Security Engineer’s role is to integrate security practices throughout each phase, ensuring that security considerations are addressed during requirements gathering, design, development, testing, and deployment. You should emphasize the importance of proactive risk management and collaboration with all stakeholders to foster a secure development environment.

Join Rise to see the full answer
How do you stay updated on emerging security threats and vulnerabilities?

To stay updated on emerging threats, I regularly follow industry news, subscribe to security blogs, participate in webinars, and engage with communities that focus on application security. It’s essential to be proactive and continuously educate myself on the latest security issues and defense mechanisms.

Join Rise to see the full answer
What experience do you have with penetration testing and vulnerability management?

In my previous role, I conducted numerous penetration tests to identify vulnerabilities within applications and APIs. I’ve managed vulnerability triage processes, collaborated with development teams to remediate findings, and provided training on secure coding practices to ensure ongoing awareness.

Join Rise to see the full answer
Describe your experience with secure coding practices.

I have extensive experience with secure coding practices, especially in languages like Java and Python. I’ve implemented guidelines based on OWASP principles and provided coaching to developers on identifying and mitigating common vulnerabilities. My goal has always been to embed security into the development culture.

Join Rise to see the full answer
How do you assess the security posture of a new software application?

Assessing the security posture of a new application involves reviewing its architecture, conducting threat modeling sessions, and implementing security tests at various stages. This assessment helps identify potential vulnerabilities and allows for proactive adjustments before deployment.

Join Rise to see the full answer
What are the most critical web application vulnerabilities to be aware of?

The most critical web application vulnerabilities include those listed in the OWASP Top 10, such as SQL injection, cross-site scripting, insecure deserialization, and insufficient logging. It’s vital to understand these vulnerabilities and the strategies for mitigating them to protect applications effectively.

Join Rise to see the full answer
Can you discuss your experience working within agile methodologies?

I’m well-versed in agile methodologies and have seen firsthand how agile practices can enhance security. By integrating security into sprint planning and incorporating security reviews in agile ceremonies, we ensure that security considerations are addressed without slowing down progress.

Join Rise to see the full answer
How do you approach security architecture reviews?

In security architecture reviews, I focus on understanding the application’s design and its data flow. I evaluate whether appropriate security controls are in place, identify points of vulnerability, and advise teams on implementing security measures that align with best practices and compliance requirements.

Join Rise to see the full answer
What strategies do you use for effective communication with development teams?

Effective communication with development teams involves building strong relationships, being transparent about security goals, and presenting security findings in a constructive manner. I emphasize collaboration, offer support, and help bridge the gap between security and development to create a shared sense of responsibility.

Join Rise to see the full answer
Why do you want to work as a Sr. Application Security Engineer at Prosper?

I’m excited about the opportunity to work at Prosper because I admire your commitment to utilizing technology to provide innovative financial solutions. The emphasis on teamwork, accountability, and continuous improvement aligns perfectly with my professional values and goals, making this role a great fit for me.

Join Rise to see the full answer
Similar Jobs
Photo of the Rise User
Posted 7 days ago
Photo of the Rise User
Posted 17 hours ago
Inclusive & Diverse
Empathetic
Collaboration over Competition
Growth & Learning
Transparent & Candid
Medical Insurance
Dental Insurance
Mental Health Resources
Life insurance
Disability Insurance
Child Care stipend
Employee Resource Groups
Learning & Development

Join American Express as a Manager in Information Security to work on technology risk governance and contribute to a safe and compliant operation.

Photo of the Rise User
Posted 7 days ago
Photo of the Rise User

Join SWBC as a Data Center Operator and gain valuable IT experience while providing vital support operations.

Photo of the Rise User

Join the New York City Department of Correction as an Application Support Specialist, focusing on user support and software enhancement.

Photo of the Rise User
Citi Remote Schaumburg, Illinois, United States
Posted 12 days ago
Inclusive & Diverse
Rise from Within
Mission Driven
Diversity of Opinions
Work/Life Harmony

Prosper Marketplace, Inc. was founded in 2005 and is headquartered in San Francisco. The lending platform is owned by Prosper Funding LLC, a subsidiary of Prosper Marketplace, Inc. Loans originated through the Prosper marketplace are made by WebBa...

22 jobs
MATCH
VIEW MATCH
FUNDING
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
EMPLOYMENT TYPE
Full-time, remote
DATE POSTED
March 31, 2025

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!
LATEST ACTIVITY
Photo of the Rise User
Someone from OH, Dublin just viewed Associate, Legal Ops - United States (Remote) at EvenUp
Photo of the Rise User
37 people applied to Security Analyst Jr at DEUNA
Photo of the Rise User
43 people applied to Cyber Crime Analyst at TEKsystems
Photo of the Rise User
Someone from OH, Cleveland just viewed Senior Governance Risk and Compliance Analyst at Dave
T
Someone from OH, New Albany just viewed Product Manager - Media & Entertainment at Truelogic
Photo of the Rise User
Someone from OH, Cincinnati just viewed Chief Financial Officer (Single Family Office) at Confidential
Photo of the Rise User
Someone from OH, New Albany just viewed Earned Media Specialist at L2TMedia
Photo of the Rise User
Someone from OH, New Albany just viewed Field Marketing Manager at Houzz
Photo of the Rise User
Someone from OH, New Albany just viewed Fields and Events Marketing Manager at FullStory
Photo of the Rise User
Someone from OH, Cincinnati just viewed Full-Time Google Ad Manager - US Only, No Agencies at Upwork
Photo of the Rise User
Someone from OH, New Albany just viewed Field Marketing Manager at Front
S
7 people applied to SOC Intern at SHEIN
Photo of the Rise User
22 people applied to Cybersecurity Intern at Dewberry
Photo of the Rise User
Someone from OH, Cincinnati just viewed Quality Inspector - Mechanical - Level 1 at SQA Services
Photo of the Rise User
Someone from OH, East Palestine just viewed Business Development Representative - (Remote - US) at Jobgether
Photo of the Rise User
Someone from OH, Columbus just viewed Amazon customer service at Amazon
Photo of the Rise User
Someone from OH, Hilliard just viewed UX Researcher (Contract Position) at RR Donnelley
Photo of the Rise User
Someone from OH, Hilliard just viewed Minor Team Member (14-15) at Chick-fil-A
Photo of the Rise User
Someone from OH, Hilliard just viewed Lead UX Product Designer -Stores(Remote Or Hybrid) at Target
F
Someone from OH, Cincinnati just viewed Payroll Tax Consultant at Fourth Enterprises, LLC
Photo of the Rise User
Someone from OH, Columbus just viewed Aquatics Director at British Swim School