Canopy is a fast-growing SaaS company in South Jordan, Utah building simple, powerful software for accounting firms. They are seeking a Senior Application Security Engineer to help harden their platform and ensure the security of their applications and data. The role involves designing security roadmaps, enhancing cloud security, and embedding security practices into the software development lifecycle.
Responsibilities:
- Help design and execute a multi-year application and platform security roadmap spanning cloud infrastructure, identity, network, application, observability, and the software supply chain
- Harden our AWS and Kubernetes environments - from account/organization structure and IAM to workload identity, network segmentation, and zero-trust access
- Strengthen authentication and application-layer defenses, including anti-abuse protections, secure headers, and multi-tenant isolation
- Build out the security observability stack: audit logging, cloud posture monitoring, runtime threat detection, and deception-based detection techniques
- Embed security into the SDLC - CI/CD gates, secret scanning, threat modeling, and software supply chain integrity (SBOMs, artifact signing, provenance), accounting for the new risks and review needs introduced by AI-generated code and AI-assisted development workflows
- Evaluate and adopt AI-powered security tooling - from AI-assisted pentesting and code review to anomaly detection - to help our small team punch above its weight
- Work closely with the security lead to prioritize this work, balancing finite hardening projects against the ongoing operational load of running a security program that scales with the company
- Serve as a trusted security resource for engineering teams - reviewing designs, unblocking teams on secure implementation patterns, and helping raise security literacy across the org
- Support customer and compliance conversations where deep technical credibility is needed
Requirements:
- 8+ years of professional experience in application security, security engineering, or a closely related discipline, with a track record of driving substantial security initiatives from design through to production
- Deep, hands-on expertise across most of the following: cloud account/organization security (AWS preferred), IAM and least-privilege design, Kubernetes and container security, network security and zero-trust access (e.g., Tailscale, mTLS), web application security (WAF, CSP, authentication/anti-abuse), security observability (SIEM/audit logging, CSPM, runtime detection), and secure SDLC/supply chain security (SAST/DAST, secret scanning, SBOM, artifact signing)
- A working understanding of how AI is currently shaping the security landscape - both offensively (AI-assisted phishing, automated exploitation, LLM-specific attack surfaces) and defensively (AI-assisted detection, code review, and pentesting) - and the judgment to separate real risk and real value from hype
- Demonstrated ability to go deep on a single domain when the problem demands it, and to reason credibly across all of them when setting priorities
- Experience threat modeling new features and influencing engineering design decisions before code is written
- Strong communication skills - able to translate security risk into terms that engineers, product managers, and leadership can act on
- Comfort operating with significant autonomy in a fast-moving environment, and pulling in the right partners across the org to get things done
- Experience securing multi-tenant SaaS platforms, including tenant-isolation testing or red-teaming
- Relevant certifications (e.g., OSCP, GWAPT, GCSA, or similar) - nice to have, not required
- Experience building or operating detection engineering programs (honeytokens, canary credentials, runtime threat detection)
- Prior experience in a regulated or compliance-heavy environment (SOC 2, ISO 27001, etc.)
- Hands-on experience securing AI/LLM-powered features or evaluating the security posture of AI coding tools and agentic workflows