Coupa employees grouped together on the left and sitting on the right.
Coupa Logo

Coupa

Lead Application Security Engineer - 11006

Reposted 9 Hours Ago
Remote
Hiring Remotely in US
142K-185K Annually
Senior level
Remote
Hiring Remotely in US
142K-185K Annually
Senior level
As a Lead Application Security Engineer, you will drive security architecture, perform design reviews, and mentor teams while enhancing Coupa's security features and compliance.
The summary above was generated by AI
Coupa makes margins multiply through its community-generated AI and industry-leading total spend management platform for businesses large and small. Coupa AI is informed by trillions of dollars of direct and indirect spend data across a global network of 10M+ buyers and suppliers. We empower you with the ability to predict, prescribe, and automate smarter, more profitable business decisions to improve operating margins.

Why join Coupa?

🔹 Pioneering Technology: At Coupa, we're at the forefront of innovation, leveraging the latest technology to empower our customers with greater efficiency and visibility in their spend.
🔹 Collaborative Culture: We value collaboration and teamwork, and our culture is driven by transparency, openness, and a shared commitment to excellence.
🔹 Global Impact: Join a company where your work has a global, measurable impact on our clients, the business, and each other. 

Learn more on Life at Coupa blog and hear from our employees about their experiences working at Coupa. 

The Impact of a Lead Application Security Engineer at Coupa:

We are looking for an extremely talented Lead Application Security Engineer to join our Application Security Team. You will be part of a global agile group that is responsible for building the best-in-class SaaS platform, deployment infrastructure, and services. The position will require a candidate to drive security architecture, perform design and threat modeling reviews, and design, develop, maintain, and scale Coupa’s security features and application security tooling. This role is critical in ensuring the security of our cutting-edge, highly scalable platform, including the review and guidance for new technological domains such as Artificial Intelligence (AI) and Machine Learning (ML) systems.

What You'll Do:

  • Expand the application security landscape at Coupa
  • Being a hands-on developer is a key responsibility in this role, with strong proficiency in secure coding practices
  • Strong software development skills in languages such as Java, .Net, and Python
  • Ability to perform code reviews and mentor junior team members
  • Passion for building security-focused features that perform at scale
  • Track vulnerability reports and contribute security fixes
  • Design and implement application changes to meet security compliance requirements
  • Lead and execute Security Architecture Reviews, Threat Modeling, and Design Reviews for new and existing platform components to proactively identify and mitigate security risks.
  • Conduct Security Reviews for AI/ML models and systems, addressing unique risks associated with data integrity, model poisoning, privacy, and adversarial attacks.
  • Evaluate new security technologies and make recommendations to strengthen our application
  • Be a champion of Coupa’s Secure Software Development Lifecycle (SSDLC) methodologies, integrating security earlier into the development pipeline.
  • Work closely with the Operations Security team to review and define our best practices

What You Will Bring to Coupa:

  • Leadership & Experience: 2+ years as a Lead Software Engineer or Lead AppSec Engineer; able to independently drive projects from design through delivery.
  • Technical Expertise: Strong in Java, .NET, or Python; experienced building secure web applications/microservices and designing complex, distributed systems.
  • Security Architecture & Threat Modeling: Skilled in formal security architecture/design reviews and threat modeling methods (STRIDE, DREAD).
  • Security Foundations: Deep knowledge of OWASP Top 10, SANS Top 25, identity and access management (SAML, OIDC, SSO), OAuth flows, and core cryptographic algorithms (DES, RSA, HMAC, SHA, etc.).
  • Systems & Development Practices: Familiar with design patterns, scalability, high availability, concurrency, and SQL/NoSQL databases; strong communication, self-motivation, and continuous learning mindset.
  • Additional/Preferred Skills: Background in AI/ML security (MLOps, adversarial robustness), compliance frameworks (HIPAA, PCI, SOX, FedRAMP), plus conference presentations or open-source contributions.

The estimated pay range for this role is $125,000 - $162,000

The starting salary for the successful candidate will be based on permissible, non-discriminatory factors such as skills, experience, and geographic location.

Coupa complies with relevant laws and regulations regarding equal opportunity and offers a welcoming and inclusive work environment. Decisions related to hiring, compensation, training, or evaluating performance are made fairly, and we provide equal employment opportunities to all qualified candidates and employees. 

Please be advised that inquiries or resumes from recruiters will not be accepted.

By submitting your application, you acknowledge that you have read Coupa’s Privacy Policy and understand that Coupa receives/collects your application, including your personal data, for the purposes of managing Coupa's ongoing recruitment and placement activities, including for employment purposes in the event of a successful application and for notification of future job opportunities if you did not succeed the first time. You will find more details about how your application is processed, the purposes of processing, and how long we retain your application in our Privacy Policy.

Top Skills

.Net
Java
Python

Coupa Boston, Massachusetts, USA Office

53 State Street Suite 1205, Boston, MA, United States, 02109

Similar Jobs at Coupa

7 Hours Ago
Remote
US
128K-167K Annually
Senior level
128K-167K Annually
Senior level
Artificial Intelligence • Fintech • Information Technology • Logistics • Payments • Business Intelligence • Generative AI
The Sr. Manager, User Group Program will lead the global user group program, managing team operations, implementing Bevy, and overseeing event execution and community engagement.
Top Skills: BevyGoldcastMarketoSalesforceTableau
Yesterday
In-Office or Remote
Boston, MA, USA
Mid level
Mid level
Artificial Intelligence • Fintech • Information Technology • Logistics • Payments • Business Intelligence • Generative AI
The Proposal Leader manages the lifecycle of RFX bids, coordinates proposal teams, and ensures compliance and quality in submissions while leveraging technology to improve processes.
Top Skills: Google Gemini AiLoopio
Yesterday
In-Office or Remote
Boston, MA, USA
Senior level
Senior level
Artificial Intelligence • Fintech • Information Technology • Logistics • Payments • Business Intelligence • Generative AI
Responsible for managing the demand side of IT by aligning IT initiatives with business strategy, overseeing project intake, and maximizing value from technology investments.
Top Skills: AnaplanJIRA

What you need to know about the Boston Tech Scene

Boston is a powerhouse for technology innovation thanks to world-class research universities like MIT and Harvard and a robust pipeline of venture capital investment. Host to the first telephone call and one of the first general-purpose computers ever put into use, Boston is now a hub for biotechnology, robotics and artificial intelligence — though it’s also home to several B2B software giants. So it’s no surprise that the city consistently ranks among the greatest startup ecosystems in the world.

Key Facts About Boston Tech

  • Number of Tech Workers: 269,000; 9.4% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Thermo Fisher Scientific, Toast, Klaviyo, HubSpot, DraftKings
  • Key Industries: Artificial intelligence, biotechnology, robotics, software, aerospace
  • Funding Landscape: $15.7 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Summit Partners, Volition Capital, Bain Capital Ventures, MassVentures, Highland Capital Partners
  • Research Centers and Universities: MIT, Harvard University, Boston College, Tufts University, Boston University, Northeastern University, Smithsonian Astrophysical Observatory, National Bureau of Economic Research, Broad Institute, Lowell Center for Space Science & Technology, National Emerging Infectious Diseases Laboratories

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account