Senior Application Security Engineer

6 days ago


Vancouver, British Columbia, Canada Spring Financial Full time

About Us
Spring Financial is a Canadian financial technology company focused on making every day financial services simpler, faster, and more accessible.

We build technology that helps Canadians build credit, save money, and access lending products without unnecessary friction. Our platforms allow customers to apply and manage their finances online, by text, or over the phone, making the experience convenient and flexible.

Since launching in 2014, Spring has grown into one of Canada's largest fintechs, with over 250,000+ product originations across credit-building products, personal lending, and mortgage solutions.

We're a fast-growing, product-driven team that values practical solutions, strong execution, and thoughtful collaboration. We give people ownership, trust them to make decisions, and focus on building systems that scale reliably.

If you're interested in working on real-world fintech platforms used by hundreds of thousands of Canadians, Spring offers the opportunity to make a tangible impact through well-built technology.

NOTE: This is a full-time, permanent, hybrid position in downtown Vancouver, with 3 set days in the office and 2 WFH.

Job Overview
As a Senior Application Security Engineer at Spring Financial, you will lead technical efforts to secure the software systems that power our business. You are responsible for driving security best practices across our engineering organization — embedding secure development into how we design, build, and deploy software.

You'll work closely with product engineering, DevOps, platform, and compliance teams to identify risks, implement controls, and help teams ship secure, reliable features. You bring hands-on expertise in secure coding, threat modeling, and modern appsec tooling, along with the communication skills to influence cross-functional teams.

This is primarily an individual contributor (IC) role, but may include leading a small team of engineers or acting as the technical owner for application security across the organization. You are expected to lead by example — through strong technical execution, collaborative problem-solving, and a practical, risk-aware approach to security.

You'll play a critical role in scaling our secure development lifecycle, supporting audit and compliance needs (e.g. SOC 2), and ensuring Spring's applications can evolve quickly without compromising trust.

What You'll Do

  • Own Spring's application security strategy and roadmap — aligning initiatives with risk priorities, business needs, and platform evolution.
  • Lead the definition and rollout of secure development practices (e.g., threat modeling, secure code review, dependency management, static/dynamic analysis).
  • Partner with engineering teams to identify and remediate security risks across applications, services, APIs, and cloud environments.
  • Define and manage Spring's SDL (Secure Development Lifecycle), embedding security reviews, tooling, and guardrails into CI/CD workflows.
  • Support Spring's compliance posture, including SOC 2 readiness, audit participation, and evidence gathering for application-level controls.
  • Own or contribute to incident response efforts for application-related vulnerabilities or exposures.
  • Evaluate and implement security tools and services (e.g., SAST, DAST, SBOM, secrets scanning, WAF, CSPM) that improve detection and resilience.
  • Collaborate with platform, DevOps, and IT teams on access control, secret management, and zero-trust enforcement.
  • Mentor and grow the appsec team, supporting both technical depth and cross-functional influence.
  • Support audit and compliance efforts by providing evidence, documentation, and system-level controls related to application security.
  • Act as a subject matter expert for product and engineering teams on secure architecture, data protection, and third-party risk.
  • Track and communicate security posture through clear metrics, risk registers, and executive-level reporting.

What You Should Already Have

  • 5+ years of experience in application security, software engineering, or security engineering roles, including at least 2 years in a leadership capacity.
  • Deep knowledge of web and cloud application security principles, OWASP Top 10, and secure coding best practices.
  • Experience implementing SDL processes and integrating security into CI/CD pipelines and agile environments.
  • Familiarity with threat modeling frameworks (e.g., STRIDE, PASTA) and secure architecture reviews.
  • Familiarity with cloud-native architecture (e.g., AWS, microservices, containerization, API gateways).
  • Hands-on experience with modern appsec tools (e.g., Snyk, GitHub Advanced Security, Burp Suite, Semgrep, Checkov, or similar).
  • Understanding of common identity, access, and secrets management patterns (e.g., OAuth, JWT, Vault, AWS IAM).
  • Strong communication and collaboration skills; able to influence without authority and align across engineering and business stakeholders.
  • Experience supporting compliance initiatives such as SOC 2, PCI DSS, or ISO 27001 is a plus.

What We Will Give You

  • Competitive annual salary ranging from $131,500 to $155,000, reflective of experience and impact.
  • Comprehensive benefits package, including extended health, dental, and vision coverage — with 100% of monthly premiums covered by the Spring.
  • GRSP matching program to support your long-term financial goals.
  • Transit-Friendly Employer (Transit allowance).
  • A modern, collaborative workspace in the heart of downtown Vancouver.
  • Ongoing career growth opportunities.
  • This position is hybrid and requires in-office presence; relocation assistance is available for the hired candidate (if out of province)

This is a truly exciting time to join Spring Financial and we are looking forward to doing great things together

Please note: Upon applying, our Talent Acquisition team will review your resume. If you qualify, we will reach out to learn more about your experience and answer any questions you may have about the role, benefits, compensation, and more. Due to high application volume, we may not be able to respond to everyone.

Thank you for your interest We appreciate your time and look forward to reviewing your application



  • Vancouver, British Columbia, Canada Brex Full time

    Engineering at BrexEngineering at Brex is about building systems that scale with speed and intention. Our teams span Software, Data, Security, and IT, and operate with high autonomy and deep collaboration. We tackle hard technical problems, own our outcomes, and push for excellence at every level — from architecture to deployment. It's an environment where...


  • Vancouver, British Columbia, Canada Clio Full time

    Clio is the global leader in legal AI technology, empowering legal professionals and law firms of every size to work smarter, faster, and more securely.We are transforming the legal experience for all by bettering the lives of legal professionals while increasing access to justice.Summary:What your team does:We are currently seeking a Senior Application...


  • Vancouver, British Columbia, Canada Clio Full time

    Clio is the global leader in legal AI technology, empowering legal professionals and law firms of every size to work smarter, faster, and more securely.We are transforming the legal experience for all by bettering the lives of legal professionals while increasing access to justice.Summary:What your team does:We are currently seeking a Senior Application...


  • Vancouver, British Columbia, Canada Clio Full time $146,200 - $197,800

    Clio is the global leader in legal AI technology, empowering legal professionals and law firms of every size to work smarter, faster, and more securely. We are transforming the legal experience for all by bettering the lives of legal professionals while increasing access to justice.Summary:What your team does: We are currently seeking a Senior Application...


  • Vancouver, British Columbia, Canada Procurify Full time $122,000 - $157,000

    Senior Platform Security EngineerRemote within CanadaAbout The Team:The DevSecOps team owns the security, reliability, and overall management of Procurify's cloud platform. We design and operate scalable Cloud Infrastructure, implement and champion SRE best practices, and ensure the platform is resilient, cost-efficient, secure, and compliant. The DevSecOps...


  • Vancouver, British Columbia, Canada Warner Music Inc. Full time

    At Warner Music Group, we're a global collective of music makers and music lovers, tech innovators and inspired entrepreneurs, game-changing creatives and passionate team members. Here, we turn dreams into stardom and audiences into fans. We are guided by three core values that underpin everything we do across all our diverse businesses: • Curiosity: We...

  • Security Engineer

    2 days ago


    Vancouver, British Columbia, Canada Lendesk Full time

    The RoleWe're looking for a Senior Security Developer (aka Security Engineer) to join our Platform team and help safeguard the integrity of our applications, infrastructure, and data. This role is central to designing and implementing technical solutions that proactively prevent, detect, and respond to security threats. The ideal candidate brings a strong...


  • Vancouver, British Columbia, Canada RBC Full time

    Job DescriptionWhat is the Opportunity?Do you enjoy cyber security research and innovation, proactive thinking and problem solving, in a challenging and adaptive environment while constantly thinking outside of the box? If so, this opportunity is right for youRBC's Cloud Security Operations team is responsible for developing and investigating security alerts...


  • Vancouver, British Columbia, Canada Thales Full time

    Location: Vancouver - Pender St, CanadaThales people architect identity management and data protection solutions at the heart of digital security. Business and governments rely on us to bring trust to the billons of digital interactions they have with people. Our technologies and services help banks exchange funds, people cross borders, energy become smarter...

  • Applications Engineer

    2 weeks ago


    Vancouver, British Columbia, Canada Draganfly Innovations Inc. Full time

    bout Draganfly:Draganfly Inc. (the "Company") has been a recognized leader in technology within the commercial UAV space for over two decades. We helped establish the commercial market & adoption of multi-rotor helicopters for public safety, agriculture, aerial imaging, & more. As a leader who helped shape the industry, Draganfly's focus is on the sale of...