691,726open jobs
40,578companies
98,121added this week
Browse all
Salary
$66k – $75k per year
Location
Remote/Hybrid (Budapest, Hungary)
Seniority
Senior
Employment
Full-Time
Overview
Company
Impact
Profile match
Instructure is an education technology company headquartered in Salt Lake City, Utah, and founded in 2008. The company develops the Canvas learning management system along with the assessment, credentialing, and analytics products that make up its Instructure Learning Platform. Its software is used by schools, universities, and employers in more than 100 countries, and the company has been owned by the private equity firm KKR since 2024.

At Instructure, we believe in the power of people to grow and succeed throughout their lives. Our goal is to amplify that power by creating intuitive products that simplify learning and personal development, facilitate meaningful relationships, and inspire people to go further in their education and careers.

We do this by giving smart, creative, passionate people opportunities to create awesome. And that's where you come in:

We're growing our security engineering team and building out a dedicated Application Security branch. You'd be joining a team that owns the security of the application code, dependencies, APIs, and development lifecycle behind Canvas, Mastery, and Parchment products used by tens of millions of students, instructors, and institutions.

What we're actually measuring is risk reduction. Not findings filed, not scan coverage, not tickets closed. This shapes the job: a large part of it is forming a defensible view of how much risk something actually carries, driving that risk down, and handing whatever remains to our risk management program so the business can decide about it explicitly. We'd rather you correctly classify ten things and reduce the three that matter than route a thousand alerts.

Our security engineering team is organized into two domain-specialized branches, Application Security and Cloud Infrastructure Security, so that engineers develop genuine depth rather than shallow coverage of everything. You'd own the application domain and get very good at it. We've written down what this role owns and what it doesn't, because we think ambiguity about ownership is one of the main ways security teams become frustrating places to work.

You'll work closely with product engineering teams. Many of the security outcomes we care about are achieved by developers, not by security engineers, so this role is measured substantially by whether you make it easier for developers to build secure software, not by how many findings you file.

Core engineering responsibilities

These are the foundation of every engineering role on our security team. You'd own them for the application domain: code, dependencies, APIs, and the SDLC:

Risk classification and residual risk handoff: Determine what risk a finding or design actually represents in context: exposure, data sensitivity, exploitability, blast radius, business impact. Tool-assigned severity is an input, not an answer - a high CVSS score on an unreachable component may be low risk, and a medium score on a public endpoint handling student data may not be.

Severity is our call and so is the framework we level against: Drive that risk down, and where it can't be reduced to an acceptable level, build the case for what remains: what the risk is, what was attempted, what's left, and what resolution would take.

We don't accept risk ourselves, and we don't quietly carry it: see below for who does.

Vulnerability management: triage, severity adjudication, and driving remediation to completion for findings from our scanning tooling. This means partnering with the owning engineering team, not filing a ticket and walking away.

Compensating controls: when a vulnerability can't be directly remediated, design and implement a control that reduces the risk to an accepted level, and document the reasoning and expiry condition.

False-positive adjudication: investigate findings, determine genuine exploitability in context, and suppress non-issues with recorded reasoning. We treat suppression as an engineering judgment that needs a written justification, not a way to clear a queue.

CI/CD security automation: build and maintain the pipeline gates and checks that catch problems before they ship. We'd rather automate a class of issue than review for it forever.

Security tooling: installation, configuration, integration, and data pipelines for the application security toolchain.

Application security specialization

Threat modeling: work with product and engineering teams to find design-level problems before they're built.

Secure code review: manual review for the logic and authorization flaws that scanners reliably miss.

SAST/SCA pipeline: own our static analysis and dependency scanning (Snyk, CodeQL, Wiz Code) coverage, signal quality, and developer experience.

Secure defaults and paved-road libraries: build the shared libraries and patterns that make the secure path the easy path.

Developer enablement: training, documentation, office hours, and design consultation.

Product partnership: see below.

Bug bounty program: work with our offensive security engineer to aid in researcher communication and triage flow.

Technical specification review: review application specs against our security review rubric, escalating high-risk and novel designs to our Principal engineer or manager.

Product partnership

This role has two audiences, and the second one is often missing on security teams.

Development teams are the day-to-day collaboration the people writing the code and shipping the fixes. But product management needs to see the risk carried by their own products in terms they can act on.

Product managers make prioritization calls constantly. They should be making them with visibilityinto security risk rather than discovering it afterward. In practice that means recurring risk reviews with product leadership for your area, risk framing in your specification review feedback, and being the person a product manager can ask "how risky is this, really?" and get a straight, non-alarmist answer.

This is a different skill from developer collaboration: the audience is potentially less technical, the time horizon is longer, and the currency is business impact rather than remediation detail. If translating technical risk for a non-engineering audience is something you enjoy - or want to get good at - this part of the role has real room in it.

Major incident escalation

We have a SOC that handles the overwhelming majority of alerts plus L1 and L2 triage. You will be on a security on-call rotation but you wouldn't be doing routine alert triage.

But when a major incident escalates past L2 and resolution needs deep expertise in either the tooling that produced the alert or the application systems that are impacted, you may be pulled in as a subject-matter expert. This is limited to major incidents only, expertise on demand rather than first response. SecOps runs the incident, you're there for the depth of expertise not the process.

Get in on all the awesome at Instructure!

We offer competitive, meaningful benefits in every country where we operate. While they vary by location, here's a general idea of what you can expect:

  • Competitive compensation, plus all full-time employees participate in our ownership program - because everyone should have a stake in our success.

  • Flexible work culture. Our remote, hybrid and in-office collaboration spaces vary by role, team and location.

  • Generous time off, including local holidays and our annual “Dim the Lights” period in late December, when teams are encouraged to step back and recharge based on departmental needs.

  • Comprehensive wellness programs and mental health support

  • Learning and development resources, including professional development tools and tuition reimbursement, to support your growth

  • The technology and tools you need to do your best work

  • Motivosity employee recognition program

  • A culture rooted in inclusivity, support, and meaningful connection

We believe in hiring great people and treating them right. The more diverse we are, the better our ideas and outcomes.

Instructure is an Equal Opportunity Employer. We comply with applicable employment and anti-discrimination laws in every country where we operate.

All employees must pass a background check as part of the hiring process. To help protect our teams and systems, we’ve implemented identity verification measures. Candidates may be asked to verify their legal name, current physical location, and provide a valid contact number and residential address, in accordance with local data privacy laws.

Any attempt to misrepresent personal or professional information will result in disqualification.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
691,726 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account Continue with Google
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
Budapest
$79k – $119k per year • In office • Secret • Full-Time • 3+ years exp • Bachelor's Degree • Roy
DevOps
CI/CD
Management
Confluence
Jira
Agile
Scrum
UML
Apply
$118k per year • Remote • Full-Time • London
JavaScript
TypeScript
Node JS
Databases
PostgreSQL
Frontend
Next.js
React.js
DevOps
Terraform
GCP
Azure
CI/CD
Git
AWS
Kubernetes
Incident Management
GitHub
Management
Agile
Apply
Sr. Data Scientist 4 hours ago
$23k – $48k per year (Estimated) • In office • Full-Time • 6+ years exp • Chennai • Gurgaon
Python
SQL
Databases
Weaviate
Pinecone
FAISS
OpenSearch
AI/ML
LangGraph
AutoGen
LangChain
LlamaIndex
LoRA
MLFlow
XGBoost
Fine-tuning
Embeddings
Scikit-learn
Prompt Engineering
AI Agents
NLP
LightGBM
PEFT
QLoRA
Transformers
TensorFlow
PyTorch
LLM
RAG
OpenAI
Hugging Face
Multi-Agent Systems
Machine Learning
DevOps
GCP
Azure
CI/CD
AWS
Analytics
A/B Testing
Apply
$170k – $341k per year (Estimated) • Equity • Remote/Hybrid • Full-Time • 6+ years exp • Bachelor's Degree • San Jose
DevOps
GCP
Azure
CI/CD
AWS
Kubernetes
IAM
Cybersecurity
OWASP Top 10
Threat Modeling
Apply
$18k – $43k per year (Estimated) • Remote/Hybrid
Python
PowerShell
Bash
AI/ML
Anomaly Detection
DevOps
Terraform
Ansible
GCP
OpenShift
Loki
CloudFormation
Prometheus
Azure
CI/CD
AWS
Kubernetes
Grafana
Bitbucket
GitHub
GitLab
Amazon CloudWatch
Linux
Apply
$120k – $140k per year • Remote/Hybrid • Full-Time • 7+ years exp • Bachelor's Degree
Apply
$90k – $120k per year • Remote/Hybrid • Full-Time • Bachelor's Degree
Marketing
Salesforce
Apply
$60k – $90k per year • Remote/Hybrid • Full-Time • 3+ years exp • Bachelor's Degree
Management
Gmail
Marketing
Salesforce
Apply
$90k – $125k per year • Remote/Hybrid • Full-Time • Bachelor's Degree
Marketing
Salesforce
Apply
$65k – $70k per year • Remote/Hybrid • Full-Time • 2+ years exp • Bachelor's Degree
Apply
$38k – $85k per year (Estimated) • Remote/Hybrid • Full-Time • Bachelor's Degree • Budapest
Analytics
Microsoft Excel
Management
Agile
Apply
$58k – $111k per year (Estimated) • In office • Full-Time • 4+ years exp • Bachelor's Degree • Madrid • Belgrade • Budapest • Warsaw • Kyiv
DevOps
GCP
Management
Agile
Apply
$121k – $215k per year (Estimated) • Remote • Full-Time • 5+ years exp • Bachelor's Degree • Budapest
AI/ML
Computer Vision
DevOps
Terraform
CI/CD
AWS
Kubernetes
AWS Lambda
Amazon EC2
Amazon S3
Amazon ECS
Amazon CloudWatch
Unix
Cybersecurity
GDPR
Apply
$82k – $140k per year • In office • Full-Time • Bachelor's Degree • Budapest
Apply
$23k – $59k per year (Estimated) • In office • Full-Time • 3+ years exp • Bachelor's Degree • Budapest
Management
Microsoft Office
Apply
See all jobs
This is one of many
691,726 more open roles from verified company boards, updated every day.