Job Opportunities API

The Public Ledger of Openings

← Back to the ledger

Application Security Engineer

Canopy
CompanyCanopy
CategoryEngineering
LocationSouth Jordan Utah
RemoteOn-site (inferred)
EmploymentNot stated
LevelNot stated
SalaryNot stated by the employer
Posted21 Jul 2026
Last verified30 Jul 2026
SourceEmployer career page (greenhouse)
Applications are handled by the employer, not by us.Apply on the employer's site →
Description
Application Security Engineer Canopy, South Jordan, UT   About Us Canopy is a fast-growing SaaS company in South Jordan, Utah building simple, powerful software for accounting firms. We're on a mission to help accountants build an autonomous firm — giving them back the time and tools they need to focus on what matters most: their clients. We believe the accounting industry deserves world-class software, and we're building exactly that. Our Practice Management Suite is purpose-built for firms that want to work smarter, grow faster, and deliver more value to the people they serve. We place a strong emphasis on delighting our customers, spotting and solving problems, and being good people along the way. Click here to see why our clients (and investors) love Canopy. Interested in learning more about Canopy & the industry? Check out our blog here where you can find great information on our product features, industry news, practice management, and more!   The Opportunity As we scale, so does the trust our customers place in us to protect their data. We're hiring a Senior Application Security Engineer to help harden our platform — from how we isolate workloads and control access, to how we secure our network, harden our applications, achieve audit-grade observability, and lock down our software supply chain. This is a hands-on, high-ownership role. You'll be a primary builder on a broad security roadmap spanning cloud infrastructure, identity, network, application, observability, and the software supply chain — turning it into shipped, operational reality alongside platform, infrastructure, and product engineering teams. We're looking for someone who can go deep on any one of these areas when needed, while staying comfortable moving across all of them, and who has a sharp read on how AI is reshaping both the threats we defend against and the tools we defend with. This position is fully remote in Utah.   What You’ll Do Help design and execute a multi-year application and platform security roadmap spanning cloud infrastructure, identity, network, application, observability, and the software supply chain Harden our AWS and Kubernetes environments — from account/organization structure and IAM to workload identity, network segmentation, and zero-trust access Strengthen authentication and application-layer defenses, including anti-abuse protections, secure headers, and multi-tenant isolation Build out the security observability stack: audit logging, cloud posture monitoring, runtime threat detection, and deception-based detection techniques Embed security into the SDLC — CI/CD gates, secret scanning, threat modeling, and software supply chain integrity (SBOMs, artifact signing, provenance), accounting for the new risks and review needs introduced by AI-generated code and AI-assisted development workflows Evaluate and adopt AI-powered security tooling — from AI-assisted pentesting and code review to anomaly detection — to help our small team punch above its weight Work closely with the security lead to prioritize this work, balancing finite hardening projects against the ongoing operational load of running a security program that scales with the company Serve as a trusted security resource for engineering teams — reviewing designs, unblocking teams on secure implementation patterns, and helping raise security literacy across the org Support customer and compliance conversations where deep technical credibility is needed   What We’re Looking For 8+ years of professional experience in application security, security engineering, or a closely related discipline, with a track record of driving substantial security initiatives from design through to production Deep, hands-on expertise across most of the following: cloud account/organization security (AWS preferred), IAM and least-privilege design, Kubernetes and container securit
HOUSE ADYour CV gets thirty seconds.CV writing and honest review. English & Greek.kaeros.app →