Application Security Engineer
Canopy
Role Description
As we scale, so does the trust our customers place in us to protect their data. We're hiring a Senior Application Security Engineer to help harden our platform — from how we isolate workloads and control access, to how we secure our network, harden our applications, achieve audit-grade observability, and lock down our software supply chain.
This is a hands-on, high-ownership role. You'll be a primary builder on a broad security roadmap spanning cloud infrastructure, identity, network, application, observability, and the software supply chain — turning it into shipped, operational reality alongside platform, infrastructure, and product engineering teams. We're looking for someone who can go deep on any one of these areas when needed, while staying comfortable moving across all of them, and who has a sharp read on how AI is reshaping both the threats we defend against and the tools we defend with.
This position is fully remote in Utah.
What You’ll Do
- Help design and execute a multi-year application and platform security roadmap spanning cloud infrastructure, identity, network, application, observability, and the software supply chain.
- Harden our AWS and Kubernetes environments — from account/organization structure and IAM to workload identity, network segmentation, and zero-trust access.
- Strengthen authentication and application-layer defenses, including anti-abuse protections, secure headers, and multi-tenant isolation.
- Build out the security observability stack: audit logging, cloud posture monitoring, runtime threat detection, and deception-based detection techniques.
- Embed security into the SDLC — CI/CD gates, secret scanning, threat modeling, and software supply chain integrity (SBOMs, artifact signing, provenance), accounting for the new risks and review needs introduced by AI-generated code and AI-assisted development workflows.
- Evaluate and adopt AI-powered security tooling — from AI-assisted pentesting and code review to anomaly detection — to help our small team punch above its weight.
- Work closely with the security lead to prioritize this work, balancing finite hardening projects against the ongoing operational load of running a security program that scales with the company.
- Serve as a trusted security resource for engineering teams — reviewing designs, unblocking teams on secure implementation patterns, and helping raise security literacy across the org.
- Support customer and compliance conversations where deep technical credibility is needed.
Qualifications
- 8+ years of professional experience in application security, security engineering, or a closely related discipline, with a track record of driving substantial security initiatives from design through to production.
- Deep, hands-on expertise across most of the following: cloud account/organization security (AWS preferred), IAM and least-privilege design, Kubernetes and container security, network security and zero-trust access (e.g., Tailscale, mTLS), web application security (WAF, CSP, authentication/anti-abuse), security observability (SIEM/audit logging, CSPM, runtime detection), and secure SDLC/supply chain security (SAST/DAST, secret scanning, SBOM, artifact signing).
- A working understanding of how AI is currently shaping the security landscape — both offensively (AI-assisted phishing, automated exploitation, LLM-specific attack surfaces) and defensively (AI-assisted detection, code review, and pentesting) — and the judgment to separate real risk and real value from hype.
- Demonstrated ability to go deep on a single domain when the problem demands it, and to reason credibly across all of them when setting priorities.
- Experience threat modeling new features and influencing engineering design decisions before code is written.
- Strong communication skills — able to translate security risk into terms that engineers, product managers, and leadership can act on.
- Comfort operating with significant autonomy in a fast-moving environment, and pulling in the right partners across the org to get things done.
Bonus Points
- Experience securing multi-tenant SaaS platforms, including tenant-isolation testing or red-teaming.
- Relevant certifications (e.g., OSCP, GWAPT, GCSA, or similar) — nice to have, not required.
- Experience building or operating detection engineering programs (honeytokens, canary credentials, runtime threat detection).
- Prior experience in a regulated or compliance-heavy environment (SOC 2, ISO 27001, etc.).
- Hands-on experience securing AI/LLM-powered features or evaluating the security posture of AI coding tools and agentic workflows.
Benefits
- Flexible Paid Time Off - you’re actually encouraged to use, plus 10 company holidays!
- ❤️ Health Benefits - including Medical, Dental, and Vision and an HSA Match.
- 401(k) - we match 100% up to 3% of your contribution. Eligibility is immediate with 100% vesting.
- Mental Health - all employees have access to Impact Suite & to our Employee Assistance Program (EAP).
- Paid New Parent Leave & Birthing Parent Leave - so you’re able to care for your little ones.
- ➕ Supplemental Benefits - including 100% company paid Basic Life & AD&D insurance and long & short-term disability coverage.
- Nectar - our peer-to-peer recognition program to help our employees recognize the amazing work being done by other Canopians!
- Company Events - including monthly company-wide meetings, summer parties, and more.
- ERG Committees - to plan initiatives around continuing education, community outreach, recruiting, onboarding, and more.
- ☕ Fully-stocked kitchen - Keto? Vegan? Flexitarian? Mandalorian? We’ve got you covered.
- Role Description BioRender is seeking a Senior Application Security Engineer to join our Security team – an engineer first, who contributes directly to the codebase rather than managing security from the sidelines. You'll help define how security is built into our engineering...SuggestedFull timeRemote work
$100k - $140k
Role Description Zocdoc’s most important asset is our people. As an Application Security Engineer, you’ll play a meaningful role in helping our development organization build secure software with confidence. In this role, you’ll work closely with our Compliance, Security...SuggestedFull timeFlexible hours$120k - $145k
Role Description Parallels is seeking a highly motivated and talented Application Security Engineer to join our team. In this role, you will make security decisions that impact millions of our customers while gaining hands-on experience in exploit development and CVE discovery...SuggestedFull timeRemote work$97.1k - $161.8k
...for capturing and refining information security requirements and ensures their integration... ...in the areas of secure coding, application authentication, encryption, and quickly... ...areas as needed. ~Develop and implement engineering’s technical security policies and procedures...SuggestedFull timeWork experience placementWorldwide$100k - $150k
Role Description We are looking for an Application Security Engineer to embed security throughout the software development lifecycle, partnering with engineering teams to design secure systems, identify vulnerabilities, and reduce risk across our application portfolio....SuggestedFull timeLocal areaImmediate start$180k - $205.5k
Role Description Spring Health is looking for a Senior Application Security Engineer II to join our growing Application Security team. Reporting to the Manager, Application Security, you will play a key role in maturing and expanding our AppSec programs — including established...Full timeWork experience placementRemote workSleeping nights$180k - $200k
...Description Here at Virtru you'll join an innovative product security team that is helping secure some of the world's most... ...core, functions in a wide range of threat models. As an application security engineer you will help our engineering teams maintain and develop...Full timeFlexible hours- Role Description As a Senior Application Security Engineer, you’ll help shape the future of our AppSec program. You’ll work effectively and efficiently in a small, high-impact team, bringing a sense of ownership and community. You’ll have the opportunity to learn quickly...Full timeFlexible hours
$135.9k - $203.9k
...Startups to global organizations, build secure, high-quality software faster and... ...position will implement our industry-leading Application Security products and solutions within... ...You will work alongside our sales, sales engineering, customer success managers, product...Full timeRemote workWork from home- Role Description GuidePoint Security offers an inclusive set of Application Security services helping clients implement, fine tune and run their Application Security SAST, DAST and SCA tools. Many clients need assistance with either supplementing their Application Security...Full timeRemote workFlexible hours
$175k - $215k
Role Description We're looking for an Application Security Engineer to help build secure-by-default products and services across Quanata's AI-native insurance technology platform. In this role, you'll partner closely with Product, Engineering, and Security teams to identify...Extra incomeFull timeHome officeShift work$120k - $258.5k
Role Description Nordstrom is building a new Application Security team, built on a simple idea: teams shouldn’t have to choose between moving... ...of Application Security and partner closely with product engineering and DevOps, alongside our security peers in pentest, attack...Full time$190k - $273k
Role Description The Senior Application Security Engineer II is a senior individual contributor responsible for strengthening Apollo’s secure software development lifecycle and reducing application risk across product, platform, and AI-powered features. This role blends...Full timeFlexible hours$157k - $216k
Role Description AlphaSense is investing in the next generation of our Application Security capability, a continuous, AI-augmented, layered defense program built for a SaaS engineering organization where AI agents and human developers ship code side by side at high velocity...Full timeRemote work$101k - $152.4k
Role Description The Senior Application Security Engineer, Cybersecurity will serve as a key member of the Cybersecurity Technical Assessments team, providing advanced expertise in secure software development practices and application tooling. This role is responsible for...Full time$155k - $175k
Role Description The Senior Application Security Engineer is a hands-on technical leader responsible for securing Lumin Digital’s B2B2C SaaS platform across the full software development lifecycle. This role exists at the intersection of application security and AI-augmented...Full timeRemote workFlexible hours$180k - $215k
Role Description Monarch is seeking a Senior Application Security Engineer to join our Security Engineering team during a period of rapid growth. Reporting to the Head of Engineering Infrastructure, you will be a hands-on practitioner embedded across our product and engineering...Full timeWork at officeRemote workWeekend work$130k - $190k
...be the company's technical authority on the security of its software products. Bridges Information Security and Engineering — embedding security into the SDLC for a ~50... ...this role now: The company is maturing its application security function from a position of strength...Full timeHome office$111k - $144.4k
Role Description The Sr. Application Security Engineer is responsible for validating that application services are designed and implemented with high security standards. The role analyzes the security of applications in tandem with their underlying services, including connected...Full timeTemporary workWork experience placement- Role Description As an Application Security Engineer at Oneleet, you'll bring security depth to our product engineering teams as we expand our cybersecurity platform. You'll own the security judgment layer that sits between raw tooling output and what our customers actually...Full timeRemote work
$192k - $240k
Role Description As a Senior Application Security Engineer, you will focus on finding and responding to security vulnerabilities across the Brex platform. In this role, you will: ~Perform code reviews, design reviews, penetration testing, and vulnerability management....Full timeWork experience placement- Role Description The Application Security Engineer plays a crucial role in securing our growing portfolio of applications. This role will focus on integrating security best practices into the Software Development Lifecycle (SDLC), ensuring compliance with regulatory requirements...Full time
$125.6k - $172.7k
Role Description As an Application Security Engineer at Solventum, you will: ~Join a team of cybersecurity professionals motivated to secure Solventum's healthcare information systems and the personal health information of our clients and their patients. ~Operate and...Full timeFlexible hours- Role Description Our team is growing and we're hiring a Senior Application Security Engineer to join our engineering team and enable our next phase of growth. Canary's engineering team is fully remote! This role focuses on embedding security into the software development...Full timeRemote work
$100k - $130k
Role Description As a Senior Application Security Engineer at Bonterra, you will be embedded across the Engineering organization, partnering directly with development teams to drive vulnerability remediation, build security ownership, and close the gap between identified...Full timeLocal areaImmediate start$180k - $210k
Role Description We're hiring a Senior Application Security Engineer to join a small, high-leverage AppSec team. This is a deep-technical IC role with a staff-leaning scope: ~Set the technical direction and own delivery on how we find, fix, and prevent vulnerabilities...Full timeFlexible hours$177k - $225k
Role Description Are you passionate about securing global-scale ecommerce services and applications that power millions of customers across over a hundred countries... ...looking for a hands-on Principal Product Security Engineer to lead our Secure Development Lifecycle assurance...Full timeRemote work$140k - $180k
Role Description We’re seeking a Lead Application Security Engineer to help advance Zeta Global’s application and platform security posture through AI-native security practices, intelligent automation, and scalable security engineering. You’ll play a critical role in embedding...Full time$114k - $240k
Role Description As a senior individual contributor on the Application Security team, the Staff Application Security Engineer will help to define and drive Reltio’s application and product security architecture across a distributed, cloud-native SaaS platform. This role...Full timeShift work- ...vibrant, diverse, global and results focused. You'll find our 700+ team across 12 regions and 9 time zones. The Role The Application Security Engineer exists to embed security throughout the software development lifecycle at Pepperstone. You will partner with engineering...Work at officeRemote workFlexible hours
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Application Security Engineer. Be the first to apply!
- network applications engineer Remote
- project application engineer Remote
- hydraulic application engineer Remote
- application system engineer Remote
- application engineering manager Remote
- cnc applications engineer Remote
- field applications engineer Remote
- application security engineer Remote
- application performance engineer Remote
- senior application support engineer Remote

















