This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
Our team is growing and we're hiring a Senior Application Security Engineer to join our engineering team and enable our next phase of growth. Canary's engineering team is fully remote! This role focuses on embedding security into the software development lifecycle (SDLC) and partnering with developers to make secure design the default. You will own the strategy for application security tooling, automation, and developer enablement while collaborating closely with SREs, infra, and data engineers to keep our platform both secure and scalable.
Job Responsibility:
Define and enforce best practices for secure coding, dependency management, and design reviews across engineering teams
Integrate and manage SAST, DAST, and SCA tools within CI/CD pipelines (e.g., GitHub Actions)
Partner with developers on new features and systems to identify risks early in the lifecycle
Implement best practices for secrets handling, API authentication/authorization, and data protection
Build security guidelines, training, and reusable libraries/patterns so that teams can ship secure code faster
Triage and prioritize findings from bug bounties, penetration tests, and automated scans, ensuring timely resolution
Act as the bridge between application developers and platform engineers to align app security with infra and compliance requirements
Implement monitoring, alerting, and remediation for security incidents across our platform
Scan and remediate vulnerabilities in container images, OS packages, dependencies, and IaC templates
Design and maintain least-privilege IAM roles, secrets management, and authentication flows
Automate evidence gathering and control enforcement for SOC 2, ISO 27001, and others
Requirements:
6+ years in security engineering, DevSecOps, or related roles, including experience at scale
Excellent communication and teamwork abilities
Strong experience integrating security into modern SDLC pipelines