Instructure
Senior Application Security Engineer
Part remote, part office, you need to live within commuting distance of a named location.
Hybrid · Budapest, Hungary
Employer listed it 5 days ago · Added 4 days ago
First listed 5 days ago and still open.
Salary
Not stated
Location
Hybrid · Budapest, Hungary
Timezone
Not stated
Contract
Full-time
Experience
Senior
Category
Software
This employer didn't state pay. Jobs like this usually pay around $175k–$230k a year, a typical range taken from 595 senior-level software roles on Nomaders that do state pay. It's a guide, not an offer.
Remote flexibility
Hybrid
This role is only partly remote, the employer expects time in the office around Budapest, Hungary, Hybrid, so you need to live within commuting distance.
What the employer says
- Source listing states candidate location: "Budapest, Hungary, Hybrid"
- Listing mentions "Hybrid"
What Nomaders makes of it
- Not suitable if you plan to move between countries
The quotes above are the employer's own words; the reading is ours. Always check the original listing and employment terms before working from another country.
About the role
At Instructure , we believe in the power of people to grow and succeed throughout their lives. Our goal is to amplify that power by creating intuitive products that simplify learning and personal development, facilitate meaningful relationships, and inspire people to go further in their education and careers. We do this by giving smart, creative, passionate people opportunities to create awesome. And that's where you come in:
We're growing our security engineering team and building out a dedicated Application Security branch. You'd be joining a team that owns the security of the application code, dependencies, APIs, and development lifecycle behind Canvas, Mastery, and Parchment products used by tens of millions of students, instructors, and institutions.
What we're actually measuring is risk reduction. Not findings filed, not scan coverage, not tickets closed. This shapes the job: a large part of it is forming a defensible view of how much risk something actually carries, driving that risk down, and handing whatever remains to our risk management program so the business can decide about it explicitly. We'd rather you correctly classify ten things and reduce the three that matter than route a thousand alerts.
Our security engineering team is organized into two domain-specialized branches, Application Security and Cloud Infrastructure Security, so that engineers develop genuine depth rather than shallow coverage of everything. You'd own the application domain and get very good at it. We've written down what this role owns and what it doesn't, because we think ambiguity about ownership is one of the main ways security teams become frustrating places to work.
You'll work closely with product engineering teams. Many of the security outcomes we care about are achieved by developers, not by security engineers, so this role is measured substantially by whether you make it easier for developers to build secure software, not by how many findings you file.
Core engineering responsibilities
These are the foundation of every engineering role on our security team. You'd own them for the application domain : code, dependencies, APIs, and the SDLC:
Risk classification and residual risk handoff: Determine what risk a finding or design actually represents in context: exposure, data sensitivity, exploitability, blast radius, business impact. Tool-assigned severity is an input, not an answer — a high CVSS score on an unreachable component may be low risk, and a medium score on a public endpoint handling student data may not be.
Severity is our call and so is the framework we level against: Drive that risk down, and where it can't be reduced to an acceptable level, build the case for what remains: what the risk is, what was attempted, what's left, and what resolution would take.
We don't accept risk ourselves, and we don't quietly carry it : see below for who does.
Vulnerability management : triage, severity adjudication, and driving remediation to completion for findings from our scanning tooling. This means partnering with the owning engineering team, not filing a ticket and walking away.
Compensating controls : when a vulnerability can't be directly remediated, design and implement a control that reduces the risk to an accepted level, and document the reasoning and expiry condition.
False-positive adjudication : investigate findings, determine genuine exploitability in context, and suppress non-issues with recorded reasoning. We treat suppression as an engineering judgment that needs a written justification, not a way to clear a queue.
CI/CD security automation : build and maintain the pipeline gates and checks that catch problems before they ship. We'd rather automate a class of issue than review for it forever.
Security tooling : installation, configuration, integration, and data pipelines for the application security toolchain.
Application security specialization
Threat modeling : work with product and engineering teams to find design-level problems before they're built.
Secure code review : manual review for the logic and authorization flaws that scanners reliably miss.
SAST/SCA pipeline : own our static analysis and dependency scanning (Snyk, CodeQL, Wiz Code) coverage, signal quality, and developer experience.
Secure defaults and paved-road libraries : build the shared libraries and patterns that make the secure path the easy path.
Developer enablement : training, documentation, office hours, and design consultation.
Product partnership : see below.
Bug bounty program : work with our offensive security engineer to aid in researcher communication and triage flow.
Technical specification review : review application specs against our security review rubric, escalating high-risk and novel designs to our Principal engineer or manager.
Requirements
The employer hasn't listed requirements separately, they're described in the role summary above and on the original listing.
Benefits
No benefits package published with this listing. Ask about it at first interview.
How to apply
- 1Check the flexibility label above, hybrid, matches where you plan to live and work.
- 2Tailor your CV to the role at Instructure, mentioning your remote working experience.
- 3Apply directly on the employer's careers page using the button below. Nomaders never handles your application.
Found 5d ago. Last checked today. Always confirm the details on the original posting, salary and location can change after publication.
Listing sourced from Company boards.
Similar roles
Other open software roles with comparable remote rules.
Free to apply, no account needed.
Typically $175k–$230k · You'll be taken to the employer's careers page.