Senior Application Security Engineer

New
C
CanopySaaS, Accounting
This position is fully remote in Utah.Full-TimeSenior
Salary not disclosed
Apply NowOpens the employer's application page

Job Details

Experience
8+ years
Required Skills
AWSKubernetesCI/CD

Requirements

  • 8+ years of professional experience in application security, security engineering, or a closely related discipline.
  • Proven track record of driving substantial security initiatives from design through to production.
  • Deep, hands-on expertise with cloud account/organization security (AWS preferred).
  • Expertise in IAM and least-privilege design.
  • Hands-on experience with Kubernetes and container security.
  • Proficiency in network security and zero-trust access (e.g., Tailscale, mTLS).
  • Knowledge of web application security (WAF, CSP, authentication/anti-abuse).
  • Experience with security observability (SIEM, audit logging, CSPM, runtime detection).
  • Experience with secure SDLC and supply chain security (SAST/DAST, secret scanning, SBOM, artifact signing).
  • Working understanding of AI in the security landscape, including offensive and defensive applications.
  • Demonstrated ability to perform threat modeling for new features.
  • Strong communication skills for translating security risks to engineering and product teams.

Responsibilities

  • Help design and execute a multi-year application and platform security roadmap spanning cloud infrastructure, identity, network, application, observability, and the software supply chain.
  • Harden AWS and Kubernetes environments including IAM, workload identity, and network segmentation.
  • Strengthen authentication and application-layer defenses such as anti-abuse protections and multi-tenant isolation.
  • Build security observability stacks including audit logging, cloud posture monitoring, and runtime threat detection.
  • Embed security into the SDLC through CI/CD gates, secret scanning, threat modeling, and software supply chain integrity.
  • Evaluate and adopt AI-powered security tooling for anomaly detection, code review, and pentesting.
  • Serve as a trusted security resource to review designs and unblock engineering teams on secure implementation patterns.
  • Support customer and compliance conversations requiring technical credibility.
View Full Description & ApplyYou'll be redirected to the employer's site
View details
Apply Now