bluedoor data·Job Postings API·bluedoor.sh ↗

HomeCompaniesCanary TechnologiesSenior Application Security Engineer

Senior Application Security Engineer

Canary Technologies · Remote - USA · Remote · Active · Lever

Job facts

FieldValue
CompanyCanary Technologies
TitleSenior Application Security Engineer
Normalized title-
Department / teamEngineering
LocationUnited States
Work modelRemote / Remote
Employment typeFull Time
Salary-
Statusactive
ATS providerLever
Posted / first seen2025-09-29 / 2026-05-29
Changed / last seen2026-05-29 / 2026-06-06

Related slices

PageWhat it containsOpen
Company jobsActive postings from Canary Technologies.Open
Company breakdownsRole, location, ATS, and work model facets for this company.Open
ATS provider jobsActive postings observed through Lever.Open
Provider filtered searchThe same provider as a filtered job collection.Open
Work model jobsActive Remote postings.Open
Lifecycle eventsOpen, update, close, and reopen events for this posting.Open
Original postingCanonical source or apply URL captured from the ATS.Open

Linked records

CompanyCanary Technologies
Sourced25bca28-aed6-4088-ba7a-6e2a715c9327
ATS providerLever

Description

About Us Canary Technologies is changing the game for hotels with modern software powered by Canary's hospitality-specific AI platform. Canary is utilized by 20,000+ hoteliers in 100+ countries to equip hoteliers with the technology they need to work smarter and wow their guests. Major hotel brands such as Wyndham, Marriott, IHG, Four Seasons, Rosewood, and Best Western trust Canary to deliver results. Canary was named a 2024 Deloitte Technology Fast 500™ company, a Most Innovative Company by Fast Company and a HotelTechReport Best Place to Work — and is backed by top Silicon Valley investors like Y Combinator, F-Prime, Brighton Park Capital and Insight Partners. Join us in shaping the future of hospitality! About the Role Our team is growing and we're hiring a Senior Application Security Engineer to join our engineering team and enable our next phase of growth. Canary's engineering team is fully remote! This role focuses on embedding security into the software development lifecycle (SDLC) and partnering with developers to make secure design the default. You will own the strategy for application security tooling, automation, and developer enablement while collaborating closely with SREs, infra, and data engineers to keep our platform both secure and scalable. We also work hard to ensure Canary is a fun and exciting place to work! Here are some of the additional benefits: Canary Days:  As a company we want to ensure that the team has time to recharge. Each month we provide company wide days off to ensure there is at least one extended weekend or day off. Self Improvement Club: We meet each month and share our personal goals for the month. Each individual is provided a budget towards any purchases that help us achieve these goals. Professional Development Chats: We provide budget to help drive cross functional professional development conversations across the organization. Travel Reimbursement: Team members are able to visit our offices across New York, San Francisco or Dallas when they choose, and are provided a travel stipend for doing so.  Spend time working with the team in their office, and use the rest of your time exploring a new city! Personal Travel Reimbursement: If you stay at a hotel that Canary works with, we provide a credit towards your stay. Canary Technologies is an equal opportunity employer. We recruit, employ, train, compensate and promote talent regardless of race, religion, ethnicity, national origin, citizenship, gender, gender identity, sexual orientation, age, veteran status, disability, genetic information or any other protected characteristic. Responsibilities Define and enforce best practices for secure coding, dependency management, and design reviews across engineering teams. Integrate and manage SAST, DAST, and SCA tools within CI/CD pipelines (e.g., GitHub Actions). Partner with developers on new features and systems to identify risks early in the lifecycle. Implement best practices for secrets handling, API authentication/authorization, and data protection. Build security guidelines, training, and reusable libraries/patterns so that teams can ship secure code faster. Triage and prioritize findings from bug bounties, penetration tests, and automated scans, ensuring timely resolution. Act as the bridge between application developers and platform engineers to align app security with infra and compliance requirements. Implement monitoring, alerting, and remediation for security incidents across our platform. Scan and remediate vulnerabilities in container images, OS packages, dependencies, and IaC templates. Design and maintain least-privilege IAM roles, secrets management, and authentication flows. Automate evidence gathering and control enforcement for SOC 2, ISO 27001, and others. Qualifications 6+ years in security engineering, DevSecOps, or related roles, including experience at scale. Excellent communication and teamwork abilities. Strong experience integrating security into modern SDLC pipelines. Hands-on with AppSec tooling (Snyk, OWASP ZAP, Burp Suite, SonarQube, Checkmarx, etc.). Solid understanding of web app security (OWASP Top 10, API security, auth flows, input validation). Familiarity with AWS/Kubernetes security. Strong programming skills (Python, Go, or JavaScript) to build tools, write secure code, and contribute to developer libraries. Proven track record in partnering with product and engineering teams to drive security adoption without slowing down velocity. Strong AWS security skills (IAM, KMS, Security Hub, GuardDuty, WAF). Experience with Kubernetes security (RBAC, OPA/Gatekeeper, network policies). Hands-on with Terraform, Helm, and GitOps practices. Familiarity with security tooling (Trivy, Falco, Snyk, Aqua). Knowledge of networking, encryption, and cloud-native security best practices.

Full job record

Job IDd3d8c223da3842c674d9d17b3cb1fd583dbfaa7f
Org ID096ddc59-9204-4451-b19e-606823ea9ed3
Source IDd25bca28-aed6-4088-ba7a-6e2a715c9327
Board IDd25bca28-aed6-4088-ba7a-6e2a715c9327
Providerlever
Provider Job Key04709e11-b0fe-4cb0-b38b-764b1f939b36
TitleSenior Application Security Engineer
Normalized Title
Statusactive
Activeyes
Location TextRemote - USA
Department
TeamEngineering
Employment TypeFull Time
Workplace Typeremote
Remote Policyremote
CountryUnited States
Region
City
Salary Raw
Salary Min
Salary Max
Salary Currency
Salary Period
Source URLhttps://jobs.lever.co/canarytechnologies/04709e11-b0fe-4cb0-b38b-764b1f939b36
Apply URLhttps://jobs.lever.co/canarytechnologies/04709e11-b0fe-4cb0-b38b-764b1f939b36/apply
First Seen At2026-05-29 07:02:51Z
Last Seen At2026-06-06 07:57:01Z
Last Checked At2026-06-06 07:57:01Z
Last Changed At2026-05-29 07:02:51Z
Inactive At
Source Posted At2025-09-29 17:03:24Z
Source Updated At
Raw Payload Uris3://job-postings-prod-raw-590183727216/raw/provider=lever/board=canarytechnologies/date=2026-06-06/2026-06-06T07-57-01-551Z-337490395a94d9c46387240485015180507d084bc0639d58e855cbb16bc5b9aa.json
Event Fields
{
  "content_hash": "fb28ec2fa02161903626de33687593d32bb6ced39be6c9c607e2a2332d002d6c",
  "source_hash": "3315d691633bc6dcb9ee116440849c1dc9fd5e01d8d6079541d65ae223598a2b",
  "last_changed_at": "2026-05-29T07:02:51.649Z",
  "active_status": "active"
}
Parsed Structured
{
  "language": "en",
  "location": {
    "raw": "Remote - USA",
    "city": null,
    "region": null,
    "country": "United States",
    "is_remote": true,
    "confidence": 0.95
  },
  "salary_max": null,
  "salary_min": null,
  "inferred_at": "2026-06-06T07:57:01.884Z",
  "launch_scope": {
    "reason": "english_us_canada",
    "included": true,
    "language": "en",
    "location": {
      "raw": "Remote - USA",
      "city": null,
      "region": null,
      "country": "United States",
      "is_remote": true,
      "confidence": 0.95
    },
    "countries": [
      "United States"
    ]
  },
  "remote_policy": "remote",
  "salary_period": null,
  "workplace_type": "remote",
  "salary_currency": null
}
Extensions
{}
Native Structured
{
  "lists": [
    {
      "text": "Responsibilities",
      "content": "\n<li>Define and enforce best practices for secure coding, dependency management, and design reviews across engineering teams.</li>\n<li>Integrate and manage SAST, DAST, and SCA tools within CI/CD pipelines (e.g., GitHub Actions).</li>\n<li>Partner with developers on new features and systems to identify risks early in the lifecycle.</li>\n<li>Implement best practices for secrets handling, API authentication/authorization, and data protection.</li>\n<li>Build security guidelines, training, and reusable libraries/patterns so that teams can ship secure code faster.</li>\n<li>Triage and prioritize findings from bug bounties, penetration tests, and automated scans, ensuring timely resolution.</li>\n<li>Act as the bridge between application developers and platform engineers to align app security with infra and compliance requirements.</li>\n<li>Implement monitoring, alerting, and remediation for security incidents across our platform.</li>\n<li>Scan and remediate vulnerabilities in container images, OS packages, dependencies, and IaC templates.</li>\n<li>Design and maintain least-privilege IAM roles, secrets management, and authentication flows.</li>\n<li>Automate evidence gathering and control enforcement for SOC 2, ISO 27001, and others.</li>\n"
    },
    {
      "text": "Qualifications",
      "content": "\n<li>6+ years in security engineering, DevSecOps, or related roles, including experience at scale.</li>\n<li>Excellent communication and teamwork abilities.</li>\n<li>Strong experience integrating security into modern SDLC pipelines.</li>\n<li>Hands-on with AppSec tooling (Snyk, OWASP ZAP, Burp Suite, SonarQube, Checkmarx, etc.).</li>\n<li>Solid understanding of web app security (OWASP Top 10, API security, auth flows, input validation).</li>\n<li>Familiarity with AWS/Kubernetes security.</li>\n<li>Strong programming skills (Python, Go, or JavaScript) to build tools, write secure code, and contribute to developer libraries.</li>\n<li>Proven track record in partnering with product and engineering teams to drive security adoption without slowing down velocity.</li>\n<li>Strong AWS security skills (IAM, KMS, Security Hub, GuardDuty, WAF).</li>\n<li>Experience with Kubernetes security (RBAC, OPA/Gatekeeper, network policies).</li>\n<li>Hands-on with Terraform, Helm, and GitOps practices.</li>\n<li>Familiarity with security tooling (Trivy, Falco, Snyk, Aqua).</li>\n<li>Knowledge of networking, encryption, and cloud-native security best practices.</li>\n"
    }
  ],
  "country": "US",
  "createdAt": 1759165404658,
  "updatedAt": null,
  "categories": {
    "team": "Engineering",
    "location": "Remote - USA",
    "commitment": "Full Time",
    "allLocations": [
      "Remote - USA"
    ]
  },
  "salaryRange": null,
  "workplaceType": "remote"
}
Get this page with API

Rendered from the bluedoor Job Postings API. Reproduce it:

GET https://api.bluedoor.sh/job-postings/v1/jobs/d3d8c223da3842c674d9d17b3cb1fd583dbfaa7f?include=descriptionJSON
GET https://api.bluedoor.sh/job-postings/v1/orgs/096ddc59-9204-4451-b19e-606823ea9ed3JSON
GET https://api.bluedoor.sh/job-postings/v1/sources/d25bca28-aed6-4088-ba7a-6e2a715c9327JSON
GET https://api.bluedoor.sh/job-postings/v1/jobs/d3d8c223da3842c674d9d17b3cb1fd583dbfaa7f/eventsJSON