Senior Application Security Engineer

14 hours, 11 minutes ago
Full-time
Senior
Cybersecurity
Canopy

Canopy

Canopy is a top accounting practice management software for accounting and tax firms, providing a complete suite of tools like CRM, document management, client portal, workflow, payments, and billing to streamline operations and improve client service.

Internet Software & Services
51-250
Founded 2014
$153M raised

Description

  • Design and execute a multi-year application and platform security roadmap across cloud, identity, network, application, observability, and supply chain security.
  • Harden AWS and Kubernetes environments, including account structure, IAM, workload identity, network segmentation, and zero-trust access.
  • Strengthen authentication, anti-abuse controls, secure headers, and multi-tenant isolation.
  • Build and improve security observability capabilities, including audit logging, cloud posture monitoring, runtime threat detection, and deception-based detection.
  • Embed security into the SDLC through CI/CD gates, secret scanning, threat modeling, and supply chain integrity controls such as SBOMs, artifact signing, and provenance.
  • Evaluate and adopt AI-powered security tools for pentesting, code review, and anomaly detection.
  • Partner with the security lead to prioritize hardening work alongside ongoing security operations.
  • Review engineering designs, unblock teams on secure implementation patterns, and improve security literacy across the organization.
  • Support customer and compliance conversations that require deep technical credibility.

Requirements

  • 8+ years of professional experience in application security, security engineering, or a closely related field.
  • Proven track record of driving security initiatives from design through production.
  • Deep hands-on experience with cloud account/organization security, preferably AWS.
  • Experience with IAM and least-privilege design, Kubernetes and container security, and network security/zero-trust access such as Tailscale or mTLS.
  • Experience with web application security, including WAF, CSP, authentication, and anti-abuse protections.
  • Experience with security observability, including SIEM/audit logging, CSPM, and runtime detection.
  • Experience with secure SDLC and supply chain security, including SAST/DAST, secret scanning, SBOMs, and artifact signing.
  • Working understanding of AI’s impact on security, including AI-assisted threats and AI-enabled defensive tools.
  • Experience threat modeling new features and influencing engineering decisions before code is written.
  • Strong communication skills and comfort working autonomously in a fast-moving environment.
  • Experience securing multi-tenant SaaS platforms, including tenant-isolation testing or red-teaming (preferred).
  • Relevant certifications such as OSCP, GWAPT, or GCSA (nice to have).
  • Experience building or operating detection engineering programs, including honeytokens or canary credentials (preferred).
  • Experience in regulated or compliance-heavy environments such as SOC 2 or ISO 27001 (preferred).
  • Hands-on experience securing AI/LLM-powered features or evaluating AI coding tools and agentic workflows (preferred).

Benefits

  • Flexible paid time off plus 10 company holidays.
  • Medical, dental, and vision coverage with an HSA match.
  • 401(k) with 100% employer match up to 3% and immediate eligibility with full vesting.
  • Mental health support through Impact Suite and an Employee Assistance Program.
  • Paid new parent leave and birthing parent leave.
  • Company-paid basic life and AD&D insurance plus long- and short-term disability coverage.
  • Peer recognition program, company events, employee resource groups, and a fully stocked kitchen.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Staff Application Security Engineer

Beyond Finance 251-1K Banks

Beyond Finance is hiring a Staff Application Security Engineer to own and advance application security across its product and cloud engineering teams.

AWS CI/CD CloudFormation Go Python React Native Ruby on Rails Secrets Management Terraform
13 hours, 26 minutes ago

Senior Security Engineer - Product Security

Ondo Finance 11-50 Diversified Financial Services

Ondo Finance is hiring a Senior Security Engineer for Product Security to secure its tokenized real-world asset platform by partnering with product engineering on threat modeling, secure reviews, and security-by-default delivery.

CI/CD Encryption Go JavaScript OAuth OpenID Connect Penetration Testing Python Rust Terraform TypeScript
2 days, 13 hours ago

Senior Application Security Engineer

Counterpart Health 51-200 hospital & health care

Counterpart Health is hiring a Senior Application Security Engineer to secure its AI-enabled primary care platform, Counterpart Assistant, by finding and fixing vulnerabilities that affect clinicians during live patient visits.

Penetration Testing
2 days, 14 hours ago

Staff Product Security Engineer

Chainguard 51-250 Internet Software & Services

Chainguard is hiring a Staff Product Security Engineer to embed security into its cloud-native product and delivery pipelines for hardened open source software.

AWS CI/CD GCP GitHub Actions Go Kubernetes OWASP Penetration Testing Python Secrets Management Tekton
3 days, 13 hours ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers