SlipstreamJobsFresh Startup & VC-Backed Jobs

Senior Application Security Engineer

LearnPlatform - Budapest, Hungary - Hybrid - posted 2026-09-18

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Instructure is seeking a Senior Application Security Engineer to join its growing security engineering team and lead the Application Security branch. You will own the security of application code, dependencies, APIs, and development lifecycle for Canvas, Mastery, and Parchment—products used by tens of millions of students, instructors, and institutions worldwide. The role is fundamentally about risk reduction, not alert volume. You will classify and contextualize security findings by actual risk (exposure, data sensitivity, exploitability, blast radius, business impact), drive risk down through remediation or compensating controls, and hand off residual risk to the business with clear documentation of what remains and what resolution would require. Core engineering responsibilities include: vulnerability management and triage (partnering with engineering teams to drive remediation to completion); false-positive adjudication with recorded reasoning; CI/CD security automation to catch problems before they ship; and security tooling installation, configuration, and integration. Application Security specialization includes: threat modeling with product and engineering teams; secure code review for logic and authorization flaws; ownership of SAST/SCA pipeline (Snyk, CodeQL, Wiz Code) for coverage and developer experience; building secure defaults and paved-road libraries; developer enablement through training, documentation, and design consultation; bug bounty program collaboration; and technical specification review against security rubrics. A key differentiator is product partnership. You will work with both development teams (day-to-day code and fixes) and product management (risk visibility for prioritization). You'll conduct recurring risk reviews with product leadership, frame risk in specification feedback, and help product managers understand security implications in business terms—translating technical risk for non-engineering audiences. You will be on a security on-call rotation but focused on major incident escalation requiring deep expertise in tooling or application systems, not routine alert triage. The SOC handles L1/L2; you provide subject-matter expertise on demand for critical incidents. Instructure values flexible work culture with remote, hybrid, and in-office options varying by role and location. The company offers competitive compensation with ownership program participation, generous time off including an annual "Dim the Lights" recharge period in December, comprehensive wellness and mental health support, learning and development resources, and a culture rooted in inclusivity. REQUIREMENTS: The posting does not explicitly state years of experience, required certifications, or formal education requirements. However, the role expects: - Deep expertise in application security domains (code, dependencies, APIs, SDLC) - Proficiency with SAST/SCA tools (Snyk, CodeQL, Wiz Code) - Ability to perform threat modeling and secure code review - Experience with CI/CD security automation - Skill in risk classification and contextualization (not relying on tool severity alone) - Ability to communicate technical security risk to non-technical audiences (product managers) - Experience with vulnerability management and remediation workflows - Familiarity with compensating controls and false-positive adjudication - On-call incident response capability for major security incidents

Similar roles