Senior Application Security Engineer

Instructure
Budapest
Workplace: HybridFull timeHUF 1,750,000 - 2,000,000 monthlyFunction: CybersecuritySkills: ["Risk reduction","Cross-functional collaboration","Engineering judgment","Documentation","Developer enablement"]

Own application security for Canvas, Mastery, and Parchment—covering code, dependencies, APIs, and the SDLC. Drive risk classification and residual risk handoff, run vulnerability management, design compensating controls, adjudicate false positives, and build CI/CD security automation. Specialize in threat modeling, secure code review, SAST/SCA pipelines (Snyk, CodeQL, Wiz Code), and developer enablement while escalating major incidents as needed.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Instructure
Instructure
2 days ago

Senior Application Security Engineer

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 15 hours agoStatus: Live

Job Summary

Own application security for Canvas, Mastery, and Parchment—covering code, dependencies, APIs, and the SDLC. Drive risk classification and residual risk handoff, run vulnerability management, design compensating controls, adjudicate false positives, and build CI/CD security automation. Specialize in threat modeling, secure code review, SAST/SCA pipelines (Snyk, CodeQL, Wiz Code), and developer enablement while escalating major incidents as needed.
Location: Budapest
Workplace: Hybrid
Employment Type: Full time
Job Function: Cybersecurity
Seniority: Mid level

Key Responsibilities

  • •Perform application security risk classification and residual risk handoff, including exposure, data sensitivity, exploitability, blast radius, and business impact.
  • •Manage vulnerability triage and severity adjudication, partnering with engineering teams to drive remediation to completion.
  • •Implement compensating controls and document reasoning and expiry when vulnerabilities can’t be directly remediated.
  • •Run CI/CD security automation, including pipeline gates and checks that catch issues before release.
  • •Specialize in threat modeling, secure code review, SAST/SCA coverage (Snyk, CodeQL, Wiz Code), and secure defaults/libraries to enable developers.

Pay and Benefits

Salary: HUF 1,750,000 - 2,000,000 monthly
Perks:Remote WorkPaid LeaveWellness Stipend

Key Requirements

  • •Classify security risk in context and determine residual risk using a defined framework beyond tool-assigned severity.
  • •Drive vulnerability management through triage, severity adjudication, and remediation completion with owning engineering teams.
  • •Design compensating controls when direct remediation isn’t possible, including documented reasoning and expiry conditions.
  • •Perform threat modeling and secure code review to catch design-level and logic/authorization flaws scanners miss.
  • •Own SAST/SCA pipelines and developer experience, including tooling such as Snyk, CodeQL, and Wiz Code.
Skills:Risk reductionCross-functional collaborationEngineering judgmentDocumentationDeveloper enablement
Tech Stack:SnykCodeQLWiz CodeSASTSCACI/CDSDLCAPIsCVSS

Company Brief

Instructure
Builds and delivers learning management and education technology solutions, best known for the Canvas LMS platform, serving K–12 schools, higher education institutions, and corporate learning programs worldwide.
Industry: EdTech
Company Size: Enterprise (1,001+ employees)
Growth: Established Company
Funding: Private Equity Backed
Headquarters: Salt Lake City, United States
Founded: 2008
WebsiteLinkedIn