Canopy

Application Security Engineer

Canopy$100K — $130K *
Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • 8+ years in application security or related field with proven success in security initiatives
  • Hands-on expertise in cloud security (preferably AWS), Kubernetes, and application defenses
  • Understanding of AI's impact on security, including threats and defensive tools
  • Ability to focus deeply on security domains while prioritizing across the board
  • Experience in threat modeling and influencing design decisions pre-development
  • Strong communication skills to convey security risks to diverse stakeholders
  • Comfortable working autonomously and collaborating across teams in a dynamic environment

Responsibilities

  • Design and implement a multi-year security roadmap for applications and platforms
  • Enhance security in AWS and Kubernetes through rigorous account management and zero-trust access controls
  • Fortify authentication and application defenses with modern protections
  • Develop a robust security observability framework for monitoring and threat detection
  • Integrate security best practices into the software development life cycle (SDLC)
  • Adopt AI-powered security tools to maximize team efficiency and capability
  • Support engineering teams by providing security insights and promoting security awareness

Benefits

  • Flexible Paid Time Off policy with encouragement to use it, plus 10 company holidays
  • Comprehensive health benefits, including medical, dental, vision, and HSA match
  • 401(k) plan with 100% match on contributions up to 3%, immediate eligibility and vesting
  • Mental health resources, Employee Assistance Program, and impact suite for wellness support
  • Generous parental leave policies for new and birthing parents
  • Company-paid life insurance and disability coverage for added peace of mind
  • Peer-to-peer recognition program to celebrate employee contributions
  • Engaging company events including monthly meetings and social gatherings
  • Commitment to employee resource groups for continuous education and outreach initiatives
  • On-site kitchen stocked with diverse food options to accommodate various diets
Full Job Description
Application Security Engineer

Canopy, South Jordan, UT

The Opportunity

As we scale, so does the trust our customers place in us to protect their data. We're hiring a Senior Application Security Engineer to help harden our platform - from how we isolate workloads and control access, to how we secure our network, harden our applications, achieve audit-grade observability, and lock down our software supply chain.

This is a hands-on, high-ownership role. You'll be a primary builder on a broad security roadmap spanning cloud infrastructure, identity, network, application, observability, and the software supply chain - turning it into shipped, operational reality alongside platform, infrastructure, and product engineering teams. We're looking for someone who can go deep on any one of these areas when needed, while staying comfortable moving across all of them, and who has a sharp read on how AI is reshaping both the threats we defend against and the tools we defend with.

This position is fully remote in Utah.

What You'll Do
  • Help design and execute a multi-year application and platform security roadmap spanning cloud infrastructure, identity, network, application, observability, and the software supply chain
  • Harden our AWS and Kubernetes environments - from account/organization structure and IAM to workload identity, network segmentation, and zero-trust access
  • Strengthen authentication and application-layer defenses, including anti-abuse protections, secure headers, and multi-tenant isolation
  • Build out the security observability stack: audit logging, cloud posture monitoring, runtime threat detection, and deception-based detection techniques
  • Embed security into the SDLC - CI/CD gates, secret scanning, threat modeling, and software supply chain integrity (SBOMs, artifact signing, provenance), accounting for the new risks and review needs introduced by AI-generated code and AI-assisted development workflows
  • Evaluate and adopt AI-powered security tooling - from AI-assisted pentesting and code review to anomaly detection - to help our small team punch above its weight
  • Work closely with the security lead to prioritize this work, balancing finite hardening projects against the ongoing operational load of running a security program that scales with the company
  • Serve as a trusted security resource for engineering teams - reviewing designs, unblocking teams on secure implementation patterns, and helping raise security literacy across the org
  • Support customer and compliance conversations where deep technical credibility is needed


What We're Looking For
  • 8+ years of professional experience in application security, security engineering, or a closely related discipline, with a track record of driving substantial security initiatives from design through to production
  • Deep, hands-on expertise across most of the following: cloud account/organization security (AWS preferred), IAM and least-privilege design, Kubernetes and container security, network security and zero-trust access (e.g., Tailscale, mTLS), web application security (WAF, CSP, authentication/anti-abuse), security observability (SIEM/audit logging, CSPM, runtime detection), and secure SDLC/supply chain security (SAST/DAST, secret scanning, SBOM, artifact signing)
  • A working understanding of how AI is currently shaping the security landscape - both offensively (AI-assisted phishing, automated exploitation, LLM-specific attack surfaces) and defensively (AI-assisted detection, code review, and pentesting) - and the judgment to separate real risk and real value from hype
  • Demonstrated ability to go deep on a single domain when the problem demands it, and to reason credibly across all of them when setting priorities
  • Experience threat modeling new features and influencing engineering design decisions before code is written
  • Strong communication skills - able to translate security risk into terms that engineers, product managers, and leadership can act on
  • Comfort operating with significant autonomy in a fast-moving environment, and pulling in the right partners across the org to get things done


Bonus Points
  • Experience securing multi-tenant SaaS platforms, including tenant-isolation testing or red-teaming
  • Relevant certifications (e.g., OSCP, GWAPT, GCSA, or similar) - nice to have, not required
  • Experience building or operating detection engineering programs (honeytokens, canary credentials, runtime threat detection)
  • Prior experience in a regulated or compliance-heavy environment (SOC 2, ISO 27001, etc.)
  • Hands-on experience securing AI/LLM-powered features or evaluating the security posture of AI coding tools and agentic workflows

We know many women do not apply for a job if they don't perfectly fit the description. We want you to apply anyway.

Why You Want to Work Here

Flexible Paid Time Off - you're actually encouraged to use, plus 10 company holidays!

♥ Health Benefits - including Medical, Dental, and Vision and an HSA Match.

401(k) - we match 100% up to 3% of your contribution. Eligibility is immediate with 100% vesting.

Mental Health - all employees have access to Impact Suite & to our Employee Assistance Program (EAP).

Paid New Parent Leave & Birthing Parent Leave - so you're able to care for your little ones.

+ Supplemental Benefits - including 100% company paid Basic Life & AD&D insurance and long & short-term disability coverage.

Nectar - our peer-to-peer recognition program to help our employees recognize the amazing work being done by other Canopians!

Company Events - including monthly company-wide meetings, summer parties, and more.

ERG Committees - to plan initiatives around continuing education, community outreach, recruiting, onboarding, and more.

Fully-stocked kitchen - Keto? Vegan? Flexitarian? Mandalorian? We've got you covered.

Interviewing @ Canopy

Application processes can be a little stressful. Here are the stages of a typical interview process at Canopy:
  • Once your application is received, we will review it and get back to you if we feel like it's a mutual fit!
  • 20-minute phone call with the People Team
  • 45-60-minute video or in-person interview with the Hiring Manager
  • 1-3 rounds of interviews, depending on the role
  • Final Interview

Interview processes can vary depending on the role. The People Team will give you a role-specific overview of the process during your first phone call.

Remember: This is your interview too! We know candidates are evaluating us just as much as we are them. We encourage you to bring questions to each of your interviews-our hiring teams will always make sure to save time for questions at the end!

About Canopy

The Canopy Group is an American investment and property management firm founded by Ray Noorda in 1995 through the Noorda Family Trust. It is headquartered in Lindon, Utah. At various times it has consisted of, or been known as, Canopy Technologies, Canopy Properties, and Canopy Ventures. The Canopy Group served as the parent company of various start-up technology companies. It was one of the first venture capital firms in the Utah area and, investing in over a hundred such companies, became a pioneer in the Utah high-technology space. One of the most well-known companies it invested in was The SCO Group. Canopy divested itself of SCO in 2005 with the settlement of the Yarro case. In 2011, Canopy's technology venture arm was purchased by Signal Peak Ventures. Today, Canopy provides real estate and rental space to high-tech companies.
Learn more about Canopy

Similar Jobs

More Jobs at Canopy

More Information Technology Jobs

Find similar Application Security Engineer jobs: