Senior Application Security Engineer

2 weeks ago


Vancouver, Canada Spring Financial Full time

Senior Application Security Engineer at Spring FinancialJoin to apply for the Senior Application Security Engineer role at Spring Financial.About Spring Financial: Spring Financial is revolutionizing financial access for Canadians, providing smart credit-building, mortgage, and lending solutions. Millions struggle with high-interest debt and limited financial options—we’re here to change that. As one of Canada’s fastest-growing fintech companies, annually we help 1 million customers explore their financing options with ease—online, via text, or over the phone. To learn more about our products please visit our website: www.springfinancial.ca. Note: this is a full-time, permanent, hybrid position in downtown Vancouver, with 3 set days in the office and 2 WFH.Job OverviewAs a Senior Application Security Engineer at Spring Financial, you will lead technical efforts to secure the software systems that power our business. You are responsible for driving security best practices across our engineering organization — embedding secure development into how we design, build, and deploy software. You’ll work closely with product engineering, DevOps, platform, and compliance teams to identify risks, implement controls, and help teams ship secure, reliable features. You bring hands-on expertise in secure coding, threat modeling, and modern appsec tooling, along with the communication skills to influence cross-functional teams. This is primarily an individual contributor (IC) role, but may include leading a small team of engineers or acting as the technical owner for application security across the organization. You are expected to lead by example — through strong technical execution, collaborative problem-solving, and a practical, risk-aware approach to security. You’ll play a critical role in scaling our secure development lifecycle, supporting audit and compliance needs (e.g. SOC 2), and ensuring Spring’s applications can evolve quickly without compromising trust.What You’ll DoOwn Spring’s application security strategy and roadmap — aligning initiatives with risk priorities, business needs, and platform evolution.Lead the definition and rollout of secure development practices (e.g., threat modeling, secure code review, dependency management, static/dynamic analysis).Partner with engineering teams to identify and remediate security risks across applications, services, APIs, and cloud environments.Define and manage Spring’s SDL (Secure Development Lifecycle), embedding security reviews, tooling, and guardrails into CI/CD workflows.Support Spring’s compliance posture, including SOC 2 readiness, audit participation, and evidence gathering for application-level controls.Own or contribute to incident response efforts for application-related vulnerabilities or exposures.Evaluate and implement security tools and services (e.g., SAST, DAST, SBOM, secrets scanning, WAF, CSPM) that improve detection and resilience.Collaborate with platform, DevOps, and IT teams on access control, secret management, and zero-trust enforcement.Mentor and grow the appsec team, supporting both technical depth and cross-functional influence.Support audit and compliance efforts by providing evidence, documentation, and system-level controls related to application security.Act as a subject matter expert for product and engineering teams on secure architecture, data protection, and third-party risk.Track and communicate security posture through clear metrics, risk registers, and executive-level reporting.What You Should Already Have5+ years of experience in application security, software engineering, or security engineering roles, including at least 2 years in a leadership capacity.Deep knowledge of web and cloud application security principles, OWASP Top 10, and secure coding best practices.Experience implementing SDL processes and integrating security into CI/CD pipelines and agile environments.Familiarity with threat modeling frameworks (e.g., STRIDE, PASTA) and secure architecture reviews.Familiarity with cloud-native architecture (e.g., AWS, microservices, containerization, API gateways).Hands-on experience with modern appsec tools (e.g., Snyk, GitHub Advanced Security, Burp Suite, Semgrep, Checkov, or similar).Understanding of common identity, access, and secrets management patterns (e.g., OAuth, JWT, Vault, AWS IAM).Strong communication and collaboration skills; able to influence without authority and align across engineering and business stakeholders.Experience supporting compliance initiatives such as SOC 2, PCI DSS, or ISO 27001 is a plus.What We Will Give YouCompetitive annual salary ranging from $131,500 to $155,000, reflective of experience and impact.Comprehensive benefits package, including extended health, dental, and vision coverage — with 100% of monthly premiums covered by Spring.GRSP matching program to support your long-term financial goals.Transit-Friendly Employer (Transit allowance).A modern, collaborative workspace in the heart of downtown Vancouver.Ongoing career growth opportunities.This is a truly exciting time to join Spring Financial and we are looking forward to doing great things together Note: Upon applying, our Talent Acquisition team will review your resume. If you qualify, we will reach out to learn more about your experience and answer any questions you may have about the role, benefits, compensation, and more. Due to high application volume, we may not be able to respond to everyone. #J-18808-Ljbffr



  • Vancouver, Canada Brex Full time

    4 days ago Be among the first 25 applicants Get AI-powered advice on this job and more exclusive features. Why join us Brex is the AI-powered spend platform. We help companies spend with confidence with integrated corporate cards, banking, and global payments, plus intuitive software for travel and expenses. Tens of thousands of companies from startups to...


  • Vancouver, Canada Brex Full time

    4 days ago Be among the first 25 applicants Get AI-powered advice on this job and more exclusive features. Why join us Brex is the AI-powered spend platform. We help companies spend with confidence with integrated corporate cards, banking, and global payments, plus intuitive software for travel and expenses. Tens of thousands of companies from startups to...


  • Vancouver, Canada Brex Full time

    4 days ago Be among the first 25 applicants Get AI-powered advice on this job and more exclusive features. Why join us Brex is the AI-powered spend platform. We help companies spend with confidence with integrated corporate cards, banking, and global payments, plus intuitive software for travel and expenses. Tens of thousands of companies from startups to...


  • Vancouver, Canada Brex Inc. Full time

    ### Senior Application Security Engineer#### Vancouver, British Columbia, CanadaSenior Application Security Engineer**Why join us**Brex is the AI-powered spend platform. We help companies spend with confidence with integrated corporate cards, banking, and global payments, plus intuitive software for travel and expenses. Tens of thousands of companies from...


  • Vancouver, British Columbia, Canada Brex Full time $192,000 - $240,000 per year

    Engineering at BrexEngineering at Brex is about building systems that scale with speed and intention. Our teams span Software, Data, Security, and IT, and operate with high autonomy and deep collaboration. We tackle hard technical problems, own our outcomes, and push for excellence at every level — from architecture to deployment. It's an environment where...


  • Vancouver, Canada Brex Full time

    Why join us Brex is the AI-powered spend platform. We help companies spend with confidence with integrated corporate cards, banking, and global payments, plus intuitive software for travel and expenses. Tens of thousands of companies from startups to enterprises — including DoorDash, Flexport, and Compass — use Brex to proactively control spend, reduce...


  • Vancouver, British Columbia, Canada Brex Full time $192,000 - $240,000

    Why join usBrex is the AI-powered spend platform. We help companies spend with confidence with integrated corporate cards, banking, and global payments, plus intuitive software for travel and expenses. Tens of thousands of companies from startups to enterprises — including DoorDash, Flexport, and Compass — use Brex to proactively control spend, reduce...


  • Vancouver, Canada Brex Full time

    A leading financial services technology firm in Vancouver is seeking a Senior Application Security Engineer to find and address security vulnerabilities across their platform. The ideal candidate will have over 5 years of experience with penetration testing and secure development practices. Responsibilities include maintaining internal security tools and...


  • Vancouver, Canada Clio Full time

    Overview We are currently seeking a Senior Application Security Engineer to join our rapidly growing Security team. The Application Security team is responsible for emulating real-world adversaries to proactively discover, exploit, and help remediate critical security vulnerabilities across our applications. We provide an essential adversarial perspective,...


  • Vancouver, Canada Clio Full time

    Overview We are currently seeking a Senior Application Security Engineer to join our rapidly growing Security team. The Application Security team is responsible for emulating real-world adversaries to proactively discover, exploit, and help remediate critical security vulnerabilities across our applications. We provide an essential adversarial perspective,...