Senior Application Security Engineer
Canopy
| Company | Canopy |
| Category | Engineering |
| Location | South Jordan Utah |
| Remote | On-site (inferred) |
| Employment | Not stated |
| Level | Senior |
| Salary | Not stated by the employer |
| Posted | 21 Jul 2026 |
| Last verified | 31 Jul 2026 |
| Source | Employer career page (greenhouse) |
Description
Senior Application Security Engineer
Canopy, South Jordan, UT
About Us
Canopy is a fast-growing SaaS company in South Jordan, Utah building simple, powerful software for accounting firms. We're on a mission to help accountants build an autonomous firm — giving them back the time and tools they need to focus on what matters most: their clients.
We believe the accounting industry deserves world-class software, and we're building exactly that. Our Practice Management Suite is purpose-built for firms that want to work smarter, grow faster, and deliver more value to the people they serve. We place a strong emphasis on delighting our customers, spotting and solving problems, and being good people along the way.
Click here to see why our clients (and investors) love Canopy.
Interested in learning more about Canopy & the industry? Check out our blog here where you can find great information on our product features, industry news, practice management, and more!
The Opportunity
As we scale, so does the trust our customers place in us to protect their data. We're hiring a Senior Application Security Engineer to help harden our platform — from how we isolate workloads and control access, to how we secure our network, harden our applications, achieve audit-grade observability, and lock down our software supply chain.
This is a hands-on, high-ownership role. You'll be a primary builder on a broad security roadmap spanning cloud infrastructure, identity, network, application, observability, and the software supply chain — turning it into shipped, operational reality alongside platform, infrastructure, and product engineering teams. We're looking for someone who can go deep on any one of these areas when needed, while staying comfortable moving across all of them, and who has a sharp read on how AI is reshaping both the threats we defend against and the tools we defend with.
This position is fully remote in Utah.
What You’ll Do
Help design and execute a multi-year application and platform security roadmap spanning cloud infrastructure, identity, network, application, observability, and the software supply chain
Harden our AWS and Kubernetes environments — from account/organization structure and IAM to workload identity, network segmentation, and zero-trust access
Strengthen authentication and application-layer defenses, including anti-abuse protections, secure headers, and multi-tenant isolation
Build out the security observability stack: audit logging, cloud posture monitoring, runtime threat detection, and deception-based detection techniques
Embed security into the SDLC — CI/CD gates, secret scanning, threat modeling, and software supply chain integrity (SBOMs, artifact signing, provenance), accounting for the new risks and review needs introduced by AI-generated code and AI-assisted development workflows
Evaluate and adopt AI-powered security tooling — from AI-assisted pentesting and code review to anomaly detection — to help our small team punch above its weight
Work closely with the security lead to prioritize this work, balancing finite hardening projects against the ongoing operational load of running a security program that scales with the company
Serve as a trusted security resource for engineering teams — reviewing designs, unblocking teams on secure implementation patterns, and helping raise security literacy across the org
Support customer and compliance conversations where deep technical credibility is needed
What We’re Looking For
8+ years of professional experience in application security, security engineering, or a closely related discipline, with a track record of driving substantial security initiatives from design through to production
Deep, hands-on expertise across most of the following: cloud account/organization security (AWS preferred), IAM and least-privilege design, Kubernetes and container
You found the opening. Now track it.Tracker, radar and AI drafts in one place.erioun.com →