Application Security Engineer
Role details
Job location
Tech stack
Job description
- Help design and execute a multi-year application and platform security roadmap spanning cloud infrastructure, identity, network, application, observability, and the software supply chain
- Harden our AWS and Kubernetes environments - from account/organization structure and IAM to workload identity, network segmentation, and zero-trust access
- Strengthen authentication and application-layer defenses, including anti-abuse protections, secure headers, and multi-tenant isolation
- Build out the security observability stack: audit logging, cloud posture monitoring, runtime threat detection, and deception-based detection techniques
- Embed security into the SDLC - CI/CD gates, secret scanning, threat modeling, and software supply chain integrity (SBOMs, artifact signing, provenance), accounting for the new risks and review needs introduced by AI-generated code and AI-assisted development workflows
- Evaluate and adopt AI-powered security tooling - from AI-assisted pentesting and code review to anomaly detection - to help our small team punch above its weight
- Work closely with the security lead to prioritize this work, balancing finite hardening projects against the ongoing operational load of running a security program that scales with the company
- Serve as a trusted security resource for engineering teams - reviewing designs, unblocking teams on secure implementation patterns, and helping raise security literacy across the org
- Support customer and compliance conversations where deep technical credibility is needed, Application processes can be a little stressful. Here are the stages of a typical interview process at Canopy:
- Once your application is received, we will review it and get back to you if we feel like it's a mutual fit!
- 20-minute phone call with the People Team
- 45-60-minute video or in-person interview with the Hiring Manager
- 1-3 rounds of interviews, depending on the role
- Final Interview
Requirements
- 8+ years of professional experience in application security, security engineering, or a closely related discipline, with a track record of driving substantial security initiatives from design through to production
- Deep, hands-on expertise across most of the following: cloud account/organization security (AWS preferred), IAM and least-privilege design, Kubernetes and container security, network security and zero-trust access (e.g., Tailscale, mTLS), web application security (WAF, CSP, authentication/anti-abuse), security observability (SIEM/audit logging, CSPM, runtime detection), and secure SDLC/supply chain security (SAST/DAST, secret scanning, SBOM, artifact signing)
- A working understanding of how AI is currently shaping the security landscape - both offensively (AI-assisted phishing, automated exploitation, LLM-specific attack surfaces) and defensively (AI-assisted detection, code review, and pentesting) - and the judgment to separate real risk and real value from hype
- Demonstrated ability to go deep on a single domain when the problem demands it, and to reason credibly across all of them when setting priorities
- Experience threat modeling new features and influencing engineering design decisions before code is written
- Strong communication skills - able to translate security risk into terms that engineers, product managers, and leadership can act on
- Comfort operating with significant autonomy in a fast-moving environment, and pulling in the right partners across the org to get things done
Bonus Points
- Experience securing multi-tenant SaaS platforms, including tenant-isolation testing or red-teaming
- Relevant certifications (e.g., OSCP, GWAPT, GCSA, or similar) - nice to have, not required
- Experience building or operating detection engineering programs (honeytokens, canary credentials, runtime threat detection)
- Prior experience in a regulated or compliance-heavy environment (SOC 2, ISO 27001, etc.)
- Hands-on experience securing AI/LLM-powered features or evaluating the security posture of AI coding tools and agentic workflows
Benefits & conditions
Pulled from the full job description
- AD&D insurance
- Health insurance
- 401(k) matching
- Paid time off
- Vision insurance
- Health savings account
- Dental insurance, Flexible Paid Time Off - you're actually encouraged to use, plus 10 company holidays!
️ Health Benefits - including Medical, Dental, and Vision and an HSA Match.
401(k) - we match 100% up to 3% of your contribution. Eligibility is immediate with 100% vesting.
Mental Health - all employees have access to Impact Suite & to our Employee Assistance Program (EAP).
Paid New Parent Leave & Birthing Parent Leave - so you're able to care for your little ones.
Supplemental Benefits - including 100% company paid Basic Life & AD&D insurance and long & short-term disability coverage.
Nectar - our peer-to-peer recognition program to help our employees recognize the amazing work being done by other Canopians!
Company Events - including monthly company-wide meetings, summer parties, and more.
ERG Committees - to plan initiatives around continuing education, community outreach, recruiting, onboarding, and more.
- Fully-stocked kitchen - Keto? Vegan? Flexitarian? Mandalorian? We've got you covered.
Our Values
We approach our work every day with a few things in mind:
Own - We own this place! We focus on outcomes, holding ourselves & each other accountable.
Win - We win by delighting our customers with the very best products and services.
Do Good - We work hard to be good people!
Embrace Curiosity & Candor - We approach everything with curiosity & we understand that candor is kindness and give the gift of feedback.
Act Startup Fast - We know the best way to become a world-class company is to always act like a tiny startup: fast, hungry, intense, and scrappy. But especially fast.