Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Application Security Engineer

Full-time

Canopy

Role Description

As we scale, so does the trust our customers place in us to protect their data. We're hiring a Senior Application Security Engineer to help harden our platform — from how we isolate workloads and control access, to how we secure our network, harden our applications, achieve audit-grade observability, and lock down our software supply chain.

This is a hands-on, high-ownership role. You'll be a primary builder on a broad security roadmap spanning cloud infrastructure, identity, network, application, observability, and the software supply chain — turning it into shipped, operational reality alongside platform, infrastructure, and product engineering teams. We're looking for someone who can go deep on any one of these areas when needed, while staying comfortable moving across all of them, and who has a sharp read on how AI is reshaping both the threats we defend against and the tools we defend with.

This position is fully remote in Utah.

What You’ll Do

  • Help design and execute a multi-year application and platform security roadmap spanning cloud infrastructure, identity, network, application, observability, and the software supply chain.
  • Harden our AWS and Kubernetes environments — from account/organization structure and IAM to workload identity, network segmentation, and zero-trust access.
  • Strengthen authentication and application-layer defenses, including anti-abuse protections, secure headers, and multi-tenant isolation.
  • Build out the security observability stack: audit logging, cloud posture monitoring, runtime threat detection, and deception-based detection techniques.
  • Embed security into the SDLC — CI/CD gates, secret scanning, threat modeling, and software supply chain integrity (SBOMs, artifact signing, provenance), accounting for the new risks and review needs introduced by AI-generated code and AI-assisted development workflows.
  • Evaluate and adopt AI-powered security tooling — from AI-assisted pentesting and code review to anomaly detection — to help our small team punch above its weight.
  • Work closely with the security lead to prioritize this work, balancing finite hardening projects against the ongoing operational load of running a security program that scales with the company.
  • Serve as a trusted security resource for engineering teams — reviewing designs, unblocking teams on secure implementation patterns, and helping raise security literacy across the org.
  • Support customer and compliance conversations where deep technical credibility is needed.

Qualifications

  • 8+ years of professional experience in application security, security engineering, or a closely related discipline, with a track record of driving substantial security initiatives from design through to production.
  • Deep, hands-on expertise across most of the following: cloud account/organization security (AWS preferred), IAM and least-privilege design, Kubernetes and container security, network security and zero-trust access (e.g., Tailscale, mTLS), web application security (WAF, CSP, authentication/anti-abuse), security observability (SIEM/audit logging, CSPM, runtime detection), and secure SDLC/supply chain security (SAST/DAST, secret scanning, SBOM, artifact signing).
  • A working understanding of how AI is currently shaping the security landscape — both offensively (AI-assisted phishing, automated exploitation, LLM-specific attack surfaces) and defensively (AI-assisted detection, code review, and pentesting) — and the judgment to separate real risk and real value from hype.
  • Demonstrated ability to go deep on a single domain when the problem demands it, and to reason credibly across all of them when setting priorities.
  • Experience threat modeling new features and influencing engineering design decisions before code is written.
  • Strong communication skills — able to translate security risk into terms that engineers, product managers, and leadership can act on.
  • Comfort operating with significant autonomy in a fast-moving environment, and pulling in the right partners across the org to get things done.

Bonus Points

  • Experience securing multi-tenant SaaS platforms, including tenant-isolation testing or red-teaming.
  • Relevant certifications (e.g., OSCP, GWAPT, GCSA, or similar) — nice to have, not required.
  • Experience building or operating detection engineering programs (honeytokens, canary credentials, runtime threat detection).
  • Prior experience in a regulated or compliance-heavy environment (SOC 2, ISO 27001, etc.).
  • Hands-on experience securing AI/LLM-powered features or evaluating the security posture of AI coding tools and agentic workflows.

Benefits

  • Flexible Paid Time Off - you’re actually encouraged to use, plus 10 company holidays!
  • ❤️‍ Health Benefits - including Medical, Dental, and Vision and an HSA Match.
  • 401(k) - we match 100% up to 3% of your contribution. Eligibility is immediate with 100% vesting.
  • Mental Health - all employees have access to Impact Suite & to our Employee Assistance Program (EAP).
  • Paid New Parent Leave & Birthing Parent Leave - so you’re able to care for your little ones.
  • ➕ Supplemental Benefits - including 100% company paid Basic Life & AD&D insurance and long & short-term disability coverage.
  • Nectar - our peer-to-peer recognition program to help our employees recognize the amazing work being done by other Canopians!
  • Company Events - including monthly company-wide meetings, summer parties, and more.
  • ERG Committees - to plan initiatives around continuing education, community outreach, recruiting, onboarding, and more.
  • ☕ Fully-stocked kitchen - Keto? Vegan? Flexitarian? Mandalorian? We’ve got you covered.
Vacancy posted 7 days ago
Similar jobs that could be interesting for youBased on the Application Security Engineer in Remote vacancy
  • Job Role: Application Security Engineer with AWS, Cequence ,API Security(Remote)Location: RemotePrimary FocusDeployment and integration of Cequence API Security Wiz Federal Splunk and Cribl.AWS GovCloud federal government telecom or highly regulated cloud environments.Handson... 
    Suggested
    Remote work

    LTM

    Houston, TX
    3 days ago
  •  ...Premium and maintain $1.21 billion in surplus.Amerisure is hiring!! This role can sit remote. We’re looking for a Senior Application Security Engineer who can take ownership of security initiatives, shape our strategy, and partner closely with engineering teams to... 
    Suggested
    Full time
    Local area
    Remote work
    Flexible hours
    Shift work

    Amerisure Insurance Company

    Farmington Hills, MI
    1 day ago
  • $90k - $125k

     ...united by our mission of creating opportunities for people where they live, learn, and work.We are seeking a highly skilled Application Security Engineer with strong experience across secure code review, penetration testing, automation, and modern SDLC practices—including... 
    Suggested
    Full time
    Contract work
    Temporary work
    Work at office
    Local area
    Remote work
    3 days per week

    Nelnet

    Lincoln, NE
    13 hours ago
  •  ...of people and we’re just getting started.About The RoleOur Security Engineering team builds intelligent systems that protect Opendoor and our...  ...where they matter, not gates where they don't.As our Application Security Engineer, you'll own how we find, prioritize, and... 
    Suggested
    Work at office
    Monday to Friday
    Shift work

    Opendoor

    Miami, FL
    3 days ago
  • $100.63k - $167.79k

     ...your success while helping clients pursue their financial goals. Job Overview:As a member of the Information Security team, the Sr. Application Security Engineer will be responsible for helping to develop, mature, and sustain the Application Security program for the... 
    Suggested
    Full time
    Work from home

    LPL Financial

    Austin, TX
    3 days ago
  • $70 - $75 per hour

     ...Analyze global intelligence data to inform security protocols and architectural standards....  ...Skills & QualificationsCore Skills:• Application Security (AppSec)• Secure Software...  ...DSPM• Vulnerability Research & Reverse Engineering• Python and C Programming• Infrastructure... 
    Contract work
    Temporary work
    Remote work

    TEKsystems

    Dearborn, MI
    5 hours ago
  • $86.9k - $198k

    Application Security EngineerThe Opportunity: Integrate security practices throughout the software development lifecycle to enhance and maintain...  ...skillsMaster's degree in Cybersecurity, CS, Software Engineering, Information Assurance, or a related technical fieldCompensationAt... 
    Full time
    Contract work
    Part time
    Work at office
    Local area
    Remote work

    Booz Allen Hamilton

    Bethesda, MD
    2 days ago
  • $99k - $225k

    Application Security EngineerThe Opportunity:Everyone is trying to “harness the cloud,” but not everyone knows how. As a cloud computing infrastructure architect, you know how to take advantage of cloud capabilities. On our team of experienced professionals, you’ll use... 
    Full time
    Contract work
    Part time
    Work at office
    Local area
    Remote work

    Booz Allen Hamilton

    Huntsville, AL
    2 days ago
  • Opportunity OverviewTeam Overview:The Application Security Engineer, Agentic Secure Code Harness Engineer is a hands-on role responsible for operating, monitoring, and improving an AI-enabled AppSec harness used to evaluate application and infrastructure source code for... 
    Temporary work
    Work at office
    Home office
    Flexible hours
    3 days per week

    Edward Jones

    Tempe, AZ
    1 day ago
  • $160.3k - $240.5k

     ...architecture, retail, energy, and government. Our Product Security team keeps that platform, and the software built on top...  ...millions of creators and their users.We are seeking a Senior Application Security Engineer with profound expertise in application security. In this... 
    Full time
    Work at office
    Remote work
    Worldwide

    Unity Technologies

    Texas
    1 day ago
  • $111k - $144.4k

    Remote - US / Reno, NVAdministration - Enterprise Information Security /Full-Time /RemoteThe Sr. Application Security Engineer is responsible for validating that application services are designed and implemented with high security standards. The role analyzes the security... 
    Full time
    Temporary work
    Work experience placement
    Remote work

    Clear Capital

    Reno, NV
    4 days ago
  • $99k - $225k

    Application Security Engineer, LeadThe Opportunity: A well-designed network is critical to move data and enable financial institutions to achieve their missions, but how can an organization make sure their network will fit their evolving needs? Crafting the right network... 
    Full time
    Contract work
    Part time
    Work at office
    Local area
    Remote work

    Booz Allen Hamilton

    Colorado Springs, CO
    13 hours ago
  •  ...more details.Job SummaryThis role focuses on comprehensive application security testing and vulnerability management across the software development...  ...scripts and code in Java and Python as needed for security engineering and automation.Vulnerability Management & ComplianceEnsure... 
    Full time
    Work at office
    Local area
    Remote work
    1 day per week

    MUFG

    Jersey City, NJ
    13 hours ago
  • $140k - $190k

    DescriptionSenior Field Security Applications EngineerLocation: Campbell CA or Austin TXArteris connects innovation.Our technology helps the...  ...technology.Arteris is seeking a Senior Field Security Applications Engineer to drive customer adoption of the industry-leading Cycuity... 
    Contract work
    Remote work
    Night shift

    ARTERIS IP

    Austin, TX
    1 day ago
  • Role Description The primary responsibility of the Senior Application Security Engineer (AI-First Development) is to design, orchestrate, and validate the offensive security tooling and adversary-emulation capabilities used to find, prove, and help remediate exploitable... 
    Full time
    Flexible hours

    Las Vegas Sands Corp.

    Remote
    7 days ago
  • Role Description BioRender is seeking a Senior Application Security Engineer to join our Security team – an engineer first, who contributes directly to the codebase rather than managing security from the sidelines. You'll help define how security is built into our engineering... 
    Full time
    Remote work

    BioRender Inc.

    Remote
    7 days ago
  • $180k - $200k

     ...Description Here at Virtru you'll join an innovative product security team that is helping secure some of the world's most...  ...core, functions in a wide range of threat models. As an application security engineer you will help our engineering teams maintain and develop... 
    Full time
    Flexible hours

    Virtru

    Remote
    4 days ago
  • $120k - $145k

    Role Description Parallels is seeking a highly motivated and talented Application Security Engineer to join our team. In this role, you will make security decisions that impact millions of our customers while gaining hands-on experience in exploit development and CVE discovery... 
    Full time
    Remote work

    Parallels Inc

    Remote
    a month ago
  • $100k - $140k

    Role Description Zocdoc’s most important asset is our people. As an Application Security Engineer, you’ll play a meaningful role in helping our development organization build secure software with confidence. In this role, you’ll work closely with our Compliance, Security... 
    Full time
    Flexible hours

    Zocdoc

    Remote
    a month ago
  • $180k - $205.5k

    Role Description Spring Health is looking for a Senior Application Security Engineer II to join our growing Application Security team. Reporting to the Manager, Application Security, you will play a key role in maturing and expanding our AppSec programs — including established... 
    Full time
    Work experience placement
    Remote work
    Sleeping nights

    Spring Health

    Remote
    5 days ago
  • Role Description We are looking for a Senior Application Security Engineer to architect and build automated security layers within the SDLC, engineering AI-enabled secure code scanning, hardened baseline automation, and CI/CD security tooling integration within a large... 
    Full time
    Local area
    Remote work
    Flexible hours

    AgileEngine

    Remote
    13 hours ago
  • $134.6k - $175k

    Role Description We are looking for a Senior Application Security Engineer to break Counterpart Assistant before anyone else does. This is a hands-on offensive security role on our Eng Core team, the group responsible for foundational work across the platform. You will... 
    Full time
    Work at office
    Remote work
    Flexible hours

    Counterpart Health

    Remote
    6 days ago
  • Role Description DecisionPoint seeks an Application Security Engineer to perform advanced application-layer security assessments, secure coding reviews, vulnerability analysis, and security integration for enterprise applications supporting a federal and DoD-aligned mission... 
    Full time
    Local area
    Remote work

    DecisionPoint | Cortek

    Remote
    1 day ago
  • Role Description As an Application Security Engineer at Oneleet, you'll bring security depth to our product engineering teams as we expand our cybersecurity platform. You'll own the security judgment layer that sits between raw tooling output and what our customers actually... 
    Full time
    Remote work

    Oneleet

    Remote
    1 day ago
  • $157k - $216k

    Role Description AlphaSense is investing in the next generation of our Application Security capability, a continuous, AI-augmented, layered defense program built for a SaaS engineering organization where AI agents and human developers ship code side by side at high velocity... 
    Full time
    Remote work

    AlphaSense

    Remote
    5 days ago
  • $190k - $273k

    Role Description The Senior Application Security Engineer II is a senior individual contributor responsible for strengthening Apollo’s secure software development lifecycle and reducing application risk across product, platform, and AI-powered features. This role blends... 
    Full time
    Flexible hours

    Apollo.io

    Remote
    4 days ago
  • $175k - $215k

    Role Description We're looking for an Application Security Engineer to help build secure-by-default products and services across Quanata's AI-native insurance technology platform. In this role, you'll partner closely with Product, Engineering, and Security teams to identify... 
    Extra income
    Full time
    Home office
    Shift work

    Quanata

    Remote
    1 day ago
  • $130k - $190k

     ...be the company's technical authority on the security of its software products. Bridges Information Security and Engineering — embedding security into the SDLC for a ~50...  ...this role now: The company is maturing its application security function from a position of strength... 
    Full time
    Home office

    Mitek Systems

    Remote
    13 hours ago
  • $180k - $215k

    Role Description Monarch is seeking a Senior Application Security Engineer to join our Security Engineering team during a period of rapid growth. Reporting to the Head of Engineering Infrastructure, you will be a hands-on practitioner embedded across our product and engineering... 
    Full time
    Work at office
    Remote work
    Weekend work

    Monarch Money

    Remote
    3 days ago
  • $100k - $130k

    Role Description As a Senior Application Security Engineer at Bonterra, you will be embedded across the Engineering organization, partnering directly with development teams to drive vulnerability remediation, build security ownership, and close the gap between identified... 
    Full time
    Local area
    Immediate start

    Bonterra

    Remote
    2 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Application Security Engineer. Be the first to apply!