Senior Application Security Engineer
New
C
CanopySaaS, Accounting Software
This position is fully remote in Utah.Full-TimeSenior
Salary not disclosed
Apply NowOpens the employer's application page
Job Details
- Experience
- 8+ years
- Required Skills
- AWSKubernetes
Requirements
- 8+ years of professional experience in application security, security engineering, or a closely related discipline.
- Track record of driving substantial security initiatives from design through to production.
- Deep, hands-on expertise in cloud account/organization security (AWS preferred).
- Expertise in IAM and least-privilege design.
- Experience with Kubernetes and container security.
- Understanding of network security and zero-trust access (e.g., Tailscale, mTLS).
- Experience with web application security (WAF, CSP, authentication/anti-abuse).
- Knowledge of security observability, including SIEM, audit logging, CSPM, and runtime detection.
- Proficiency in secure SDLC and supply chain security, including SAST/DAST, secret scanning, SBOM, and artifact signing.
- Working understanding of how AI is shaping the security landscape, both offensively and defensively.
- Demonstrated ability to perform threat modeling for new features.
- Strong communication skills with the ability to translate security risk for cross-functional partners.
Responsibilities
- Help design and execute a multi-year application and platform security roadmap spanning cloud infrastructure, identity, network, application, observability, and the software supply chain.
- Harden AWS and Kubernetes environments, including IAM, workload identity, and network segmentation.
- Strengthen authentication and application-layer defenses, including anti-abuse protections and multi-tenant isolation.
- Build out the security observability stack, including audit logging, cloud posture monitoring, and threat detection.
- Embed security into the SDLC through CI/CD gates, secret scanning, threat modeling, and software supply chain integrity.
- Evaluate and adopt AI-powered security tooling for pentesting, code review, and anomaly detection.
- Serve as a trusted security resource for engineering teams by reviewing designs and raising security literacy.
- Support customer and compliance conversations requiring technical credibility.
View Full Description & ApplyYou'll be redirected to the employer's site