EU remote
Senior Application Security Engineer
About this role
At Instructure, we believe in the power of people to grow and succeed throughout their lives. Our goal is to amplify that power by creating intuitive products that simplify learning and personal development, facilitate meaningful relationships, and inspire people to go further in their education and careers. We do this by giving smart, creative, passionate people opportunities to create awesome. And that's where you come in: We're growing our security engineering team and building out a dedicated Application Security branch.
You'd be joining a team that owns the security of the application code, dependencies, APIs, and development lifecycle behind Canvas, Mastery, and Parchment products used by tens of millions of students, instructors, and institutions. What we're actually measuring is risk reduction. Not findings filed, not scan coverage, not tickets closed. This shapes the job: a large part of it is forming a defensible view of how much risk something actually carries, driving that risk down, and handing whatever remains to our risk management program so the business can decide about it explicitly.
We'd rather you correctly classify ten things and reduce the three that matter than route a thousand alerts. Our security engineering team is organized into two domain-specialized branches, Application Security and Cloud Infrastructure Security, so that engineers develop genuine depth rather than shallow coverage of everything. You'd own the application domain and get very good at it. We've written down what this role owns and what it doesn't, because we think ambiguity about ownership is one of the main ways security teams become frustrating places to work.
You'll work closely with product engineering teams. Many of the security outcomes we care about are achieved by developers, not by security engineers, so this role is measured substantially by whether you make it easier for developers to build secure software, not by how many findings you file. CORE ENGINEERING RESPONSIBILITIES These are the foundation of every engineering role on our security team. You'd own them for the application domain: code, dependencies, APIs, and the SDLC: Risk classification and residual risk handoff: Determine what risk a finding or design actually represents in context: exposure, data sensitivity, exploitability, blast radius, business impact.