Canary Technologies Corpremote

Salary
Posted
Jul 5, 2026
Location
Last confirmed open
Jul 21, 2026

What this job asks for AI summary

A senior individual-contributor role focused on weaving security throughout the software development lifecycle at a hospitality SaaS company. The engineer will own application security tooling and automation — integrating SAST, DAST, and SCA scanners into CI/CD pipelines, hardening AWS and Kubernetes infrastructure, managing secrets and IAM, and supporting compliance frameworks such as SOC 2 and ISO 27001. It suits an experienced DevSecOps or AppSec engineer comfortable writing code and collaborating closely with product and platform teams.

Senior level · 6+ years · Remote · Full-time

Must have (14)
SAST or DastCI/CDSnyk, Owasp Zap, Burp Suite, Sonarqube or CheckmarxOWASP Top 10AWS or KubernetesPython, Go or JavaScriptIAMKMSAWS Security HubGuardDutyWAFOPATerraformHelm
Nice to have (3)
GitHub ActionsTrivy, Falco or AquaSOC 2 or Iso 27001

“or” means any one of them counts — you don't need all of them.

We read this from the posting text with AI. Skim the description below before ruling yourself out.

How this req sits in the market our data

Roughly 1,300 people nationally plausibly meet what this posting asks for (information security analysts). range 270–2,000

Applicant volume Moderate — A normal amount of company. The rare requirements below are what will separate a shortlisted application from the rest.

What gives you an edge
Terraform11%

Rare in this occupation — lead with these, and say what you built with them.

What won't set you apart
Python62%CI/CD45%IAM45%

Most people in this occupation already list these. Still required — just not what gets you shortlisted.

What the occupation pays Median $132,021 (middle half $99,961–$167,095).

Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 28, 2026. It is a model, not a headcount.

Why we read it this way (8)

The JD lists AWS and Kubernetes security together under Qualifications with firm language ('Strong AWS security skills', 'Experience with Kubernetes security'), so both are treated as hard gates. The specific AWS services (IAM, KMS, Security Hub, GuardDuty, WAF) and Kubernetes controls (RBAC, OPA/Gatekeeper, network policies) are enumerated within those same required bullets.

AppSec tooling (Snyk, OWASP ZAP, Burp Suite, SonarQube, Checkmarx) is listed as a single 'Hands-on with' requirement under Qualifications; Snyk is used as the primary name with the others as alternatives since any one satisfies the requirement.

SAST, DAST, and SCA are listed together as a single integrated-tooling requirement in the Responsibilities section and reinforced in Qualifications; they are captured as one skill with alternatives.

Trivy, Falco, Snyk, and Aqua appear under 'Familiarity with security tooling' — softer language than the firm 'Strong'/'Proven' framing used elsewhere in Qualifications, so treated as preferred.

SOC 2 and ISO 27001 appear in Responsibilities (not Qualifications) as things the engineer will automate evidence for, not as a hard certification or knowledge gate; treated as preferred context.

No compensation figures are stated in the posting.

GitOps is listed alongside Terraform and Helm under Qualifications with 'Hands-on with' language; it is a practice rather than a named tool, so it is not emitted as a discrete skill — the concrete tools (Terraform, Helm) capture the requirement.

Caller marked this a fully-remote role — scored against the national candidate pool.

Read the full posting

The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.

Apply

Apply on employer site ↗