Application Security Engineer

SNTNL LLC
South Jordan, UT, United States
19 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
8 years minimum
Working hours
Regular working hours
Job source

Tech stack

Kubernetes Security Artificial Intelligence Amazon Web Services Software System Penetration Testing Audit Trail User Authentication Software as a Service Cloud Computing Code Review Continuous Integration Identity and Access Management Network Security
+12 more
Network Segmentation Systems Development Life Cycle Phishing Zero Trust Network Access Web Application Security Security Information and Event Management Large Language Models Software Security GWAPT Kubernetes Static Application Security Testing Dynamic Application Security Testing

Job description

  • Help design and execute a multi-year application and platform security roadmap spanning cloud infrastructure, identity, network, application, observability, and the software supply chain
  • Harden our AWS and Kubernetes environments - from account/organization structure and IAM to workload identity, network segmentation, and zero-trust access
  • Strengthen authentication and application-layer defenses, including anti-abuse protections, secure headers, and multi-tenant isolation
  • Build out the security observability stack: audit logging, cloud posture monitoring, runtime threat detection, and deception-based detection techniques
  • Embed security into the SDLC - CI/CD gates, secret scanning, threat modeling, and software supply chain integrity (SBOMs, artifact signing, provenance), accounting for the new risks and review needs introduced by AI-generated code and AI-assisted development workflows
  • Evaluate and adopt AI-powered security tooling - from AI-assisted pentesting and code review to anomaly detection - to help our small team punch above its weight
  • Work closely with the security lead to prioritize this work, balancing finite hardening projects against the ongoing operational load of running a security program that scales with the company
  • Serve as a trusted security resource for engineering teams - reviewing designs, unblocking teams on secure implementation patterns, and helping raise security literacy across the org
  • Support customer and compliance conversations where deep technical credibility is needed, Application processes can be a little stressful. Here are the stages of a typical interview process at Canopy:
  • Once your application is received, we will review it and get back to you if we feel like it’s a mutual fit!
  • 20-minute phone call with the People Team
  • 45-60-minute video or in-person interview with the Hiring Manager
  • 1-3 rounds of interviews, depending on the role
  • Final Interview

Requirements

  • 8+ years of professional experience in application security, security engineering, or a closely related discipline, with a track record of driving substantial security initiatives from design through to production
  • Deep, hands-on expertise across most of the following: cloud account/organization security (AWS preferred), IAM and least-privilege design, Kubernetes and container security, network security and zero-trust access (e.g., Tailscale, mTLS), web application security (WAF, CSP, authentication/anti-abuse), security observability (SIEM/audit logging, CSPM, runtime detection), and secure SDLC/supply chain security (SAST/DAST, secret scanning, SBOM, artifact signing)
  • A working understanding of how AI is currently shaping the security landscape - both offensively (AI-assisted phishing, automated exploitation, LLM-specific attack surfaces) and defensively (AI-assisted detection, code review, and pentesting) - and the judgment to separate real risk and real value from hype
  • Demonstrated ability to go deep on a single domain when the problem demands it, and to reason credibly across all of them when setting priorities
  • Experience threat modeling new features and influencing engineering design decisions before code is written
  • Strong communication skills - able to translate security risk into terms that engineers, product managers, and leadership can act on
  • Comfort operating with significant autonomy in a fast-moving environment, and pulling in the right partners across the org to get things done

Bonus Points

  • Experience securing multi-tenant SaaS platforms, including tenant-isolation testing or red-teaming
  • Relevant certifications (e.g., OSCP, GWAPT, GCSA, or similar) - nice to have, not required
  • Experience building or operating detection engineering programs (honeytokens, canary credentials, runtime threat detection)
  • Prior experience in a regulated or compliance-heavy environment (SOC 2, ISO 27001, etc.)
  • Hands-on experience securing AI/LLM-powered features or evaluating the security posture of AI coding tools and agentic workflows

Benefits & conditions

Pulled from the full job description

  • AD&D insurance
  • Health insurance
  • 401(k) matching
  • Paid time off
  • Vision insurance
  • Health savings account
  • Dental insurance, Flexible Paid Time Off - you’re actually encouraged to use, plus 10 company holidays!

️ Health Benefits - including Medical, Dental, and Vision and an HSA Match.

401(k) - we match 100% up to 3% of your contribution. Eligibility is immediate with 100% vesting.

Mental Health - all employees have access to Impact Suite & to our Employee Assistance Program (EAP).

Paid New Parent Leave & Birthing Parent Leave - so you’re able to care for your little ones.

Supplemental Benefits - including 100% company paid Basic Life & AD&D insurance and long & short-term disability coverage.

Nectar - our peer-to-peer recognition program to help our employees recognize the amazing work being done by other Canopians!

Company Events - including monthly company-wide meetings, summer parties, and more.

ERG Committees - to plan initiatives around continuing education, community outreach, recruiting, onboarding, and more.

  • Fully-stocked kitchen - Keto? Vegan? Flexitarian? Mandalorian? We’ve got you covered.

Our Values

We approach our work every day with a few things in mind:

Own - We own this place! We focus on outcomes, holding ourselves & each other accountable.

Win - We win by delighting our customers with the very best products and services.

Do Good - We work hard to be good people!

Embrace Curiosity & Candor - We approach everything with curiosity & we understand that candor is kindness and give the gift of feedback.

Act Startup Fast - We know the best way to become a world-class company is to always act like a tiny startup: fast, hungry, intense, and scrappy. But especially fast.

About the company

Canopy is a fast-growing SaaS company in South Jordan, Utah building simple, powerful software for accounting firms. We’re on a mission to help accountants build an autonomous firm - giving them back the time and tools they need to focus on what matters most: their clients.

We believe the accounting industry deserves world-class software, and we’re building exactly that. Our Practice Management Suite is purpose-built for firms that want to work smarter, grow faster, and deliver more value to the people they serve. We place a strong emphasis on delighting our customers, spotting and solving problems, and being good people along the way.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

2:28 min

Understanding Kubernetes architecture and core cluster components

Marc Nimmerrichter · WWC 2022

1:29 min

Evaluating phishing emails that leverage artificial time constraints

Mauro Verderosa · LIVE

1:22 min

Addressing the shortage of application security specialists

Joseph Katsioloudes Joseph Katsioloudes · WWC 2025

4:04 min

Overview of Kubernetes operators and custom resource definitions

Philipp Krenn · WWC 2022

2:39 min

Exposing stored XSS and phishing attacks via markdown

Ramona Schwering Ramona Schwering · WWC Europe 2026

Videos

See all

Related articles

See all