Senior Application Security Engineer
New
C
CanopySaaS, Accounting
This position is fully remote in Utah.Full-TimeSenior
Salary not disclosed
Apply NowOpens the employer's application page
Job Details
- Experience
- 8+ years
- Required Skills
- AWSKubernetesCI/CD
Requirements
- 8+ years of professional experience in application security, security engineering, or a closely related discipline.
- Proven track record of driving substantial security initiatives from design through to production.
- Deep, hands-on expertise with cloud account/organization security (AWS preferred).
- Expertise in IAM and least-privilege design.
- Hands-on experience with Kubernetes and container security.
- Proficiency in network security and zero-trust access (e.g., Tailscale, mTLS).
- Knowledge of web application security (WAF, CSP, authentication/anti-abuse).
- Experience with security observability (SIEM, audit logging, CSPM, runtime detection).
- Experience with secure SDLC and supply chain security (SAST/DAST, secret scanning, SBOM, artifact signing).
- Working understanding of AI in the security landscape, including offensive and defensive applications.
- Demonstrated ability to perform threat modeling for new features.
- Strong communication skills for translating security risks to engineering and product teams.
Responsibilities
- Help design and execute a multi-year application and platform security roadmap spanning cloud infrastructure, identity, network, application, observability, and the software supply chain.
- Harden AWS and Kubernetes environments including IAM, workload identity, and network segmentation.
- Strengthen authentication and application-layer defenses such as anti-abuse protections and multi-tenant isolation.
- Build security observability stacks including audit logging, cloud posture monitoring, and runtime threat detection.
- Embed security into the SDLC through CI/CD gates, secret scanning, threat modeling, and software supply chain integrity.
- Evaluate and adopt AI-powered security tooling for anomaly detection, code review, and pentesting.
- Serve as a trusted security resource to review designs and unblock engineering teams on secure implementation patterns.
- Support customer and compliance conversations requiring technical credibility.
View Full Description & ApplyYou'll be redirected to the employer's site