FREE ACCESS
5,000–10,000 jobs/day
See all jobs on Scoutfield
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.

Senior Application Security Engineer
Instructure. Own application security for code, dependencies, APIs, and the software development lifecycle behind Canvas, Mastery, and Parchment .
Core Competencies
Role fitCore Competencies
Use this summary to align your resume positioning with the role.
Demonstrates expertise in application security, including threat modeling, secure code reviews, and vulnerability management, while effectively communicating technical risks to product leadership. Proficient in building and maintaining CI/CD security automation and integrating security tooling to enhance developer security enablement.
Highest-signal resume keywords
Application SecurityThreat ModelingVulnerability ManagementCI/CD Security AutomationSnyk, CodeQL, and Wiz Code
ATS Keywords
Tailor your resumeApplicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills
Secure Code ReviewSASTSCA/Dependency SecurityAPI SecurityAuthentication/Authorization SecurityCompensating Controls DesignRisk AssessmentSecurity Tooling IntegrationSecure Defaults CreationDeveloper Security Training
Soft Skills
CommunicationDocumentationCollaborationProblem-SolvingTraining
Tools & Technologies
AWS SecurityCI/CD PipelinesSecurity Automation ToolsBug Bounty PlatformsData Pipelines
Industry Keywords
Risk ManagementSecurity On-Call RotationTechnical Specification ReviewBusiness Impact AssessmentHungarian Work Authorization
Tech Stack
Tools & technologiesAWSCloud
About the role
Key responsibilities & impact- Own application security for code, dependencies, APIs, and the software development lifecycle behind Canvas, Mastery, and Parchment
- Classify security risk in context and drive risk reduction
- Hand off residual risk to the risk management program with documented rationale
- Triage vulnerabilities, adjudicate severity, and partner with engineering teams to complete remediation
- Design and implement compensating controls when direct remediation is not possible
- Investigate false positives and document suppression decisions
- Build and maintain CI/CD security automation, pipeline gates, and checks
- Install, configure, integrate, and maintain application security tooling and data pipelines
- Conduct threat modeling with product and engineering teams
- Perform secure code reviews and review technical specifications against the security rubric
- Own SAST/SCA pipeline coverage, signal quality, and developer experience using Snyk, CodeQL, and Wiz Code
- Build secure-default shared libraries and patterns
- Enable developers through training, documentation, office hours, and design consultation
- Support bug bounty researcher communication and triage with the offensive security engineer
- Conduct recurring risk reviews with product leadership and translate technical risk into business impact
- Participate in security on-call rotation and provide subject-matter expertise during major incidents escalated beyond L2
Requirements
What you’ll need- Hands-on experience in application security areas such as threat modeling, secure code review, vulnerability management, SAST, SCA/dependency security, API security, authentication/authorization security, CI/CD security automation, security tooling integration, secure-by-default libraries/frameworks, developer security enablement/training, and bug bounty/vulnerability disclosure
- Experience with AWS security and/or cloud architecture
- Written and verbal fluency in English
- Ability to assess exposure, data sensitivity, exploitability, blast radius, and business impact
- Ability to triage vulnerabilities, adjudicate severity, drive remediation, and assess false positives
- Experience designing compensating controls and documenting risk reasoning
- Ability to build and maintain CI/CD security gates and checks
- Experience with Snyk, CodeQL, and Wiz Code
- Ability to conduct threat modeling, secure code review, and technical specification review
- Ability to create secure defaults and paved-road libraries
- Ability to provide developer training, documentation, office hours, and design consultation
- Ability to communicate technical risk to product managers and product leadership
- Willingness to participate in a security on-call rotation
- Must pass a background check
- Must provide accurate personal and professional information
- Must satisfy applicable Hungarian work authorization requirements
Benefits
Comp & perks- Competitive compensation
- Full-time employee participation in the ownership program
- Flexible work culture
- Generous time off, including local holidays and annual “Dim the Lights” period in late December
- Comprehensive wellness programs and mental health support
- Learning and development resources
- Professional development tools and tuition reimbursement
- Technology and tools needed to do your best work
- Motivosity employee recognition program
- Inclusive, supportive culture
- Background check and identity verification as part of the hiring process