Senior Application Security Engineer

2 weeks ago


Vancouver, British Columbia, Canada Brex Full time

Engineering at Brex

Engineering at Brex is about building systems that scale with speed and intention. Our teams span Software, Data, Security, and IT, and operate with high autonomy and deep collaboration. We tackle hard technical problems, own our outcomes, and push for excellence at every level — from architecture to deployment. It's an environment where engineering is a craft, and builders become leaders.

What you'll do

As a Senior Application Security Engineer, you will focus on finding and responding to security vulnerabilities across the Brex platform. In this role, you will perform code reviews, design reviews, penetration testing, and vulnerability management. You will develop and maintain tooling to perform static and dynamic testing of the Brex platform and tooling which supports secure developer workflows. Application Security is part of our wider Financial Scale organization, which means you will work closely with Security Operations, GRC, Product Security, Front End Platform,  IT Infrastructure teams.

We're looking for individuals with a strong background and interest in penetration testing. You should have a demonstrated ability to find vulnerabilities in complex systems and craft exploits to demonstrate business impact. This role is highly cross functional and collaborative, you will have the opportunity to work with every engineering team across Brex. You should be enthusiastic about working with a variety of backgrounds, roles, and needs. Building a world-class financial service requires world-class security. 

Brex is pioneering the next wave of AI-driven financial services for dynamic, high-impact companies like Coinbase, Robinhood, and Anthropic. We're at the early stages of integrating AI across our product suite, this role will have the opportunity to influence and secure the future of AI Security at Brex. You'll be at the forefront of securing our novel AI implementations, identifying attack vectors in agentic-powered features, and partnering with product and engineering teams to build AI capabilities that our customers can trust with their critical financial operations.

Where you'll work

This role will be based in our Vancouver office. We are a hybrid environment that combines the energy and connections of being in the office with the benefits and flexibility of working from home. We currently require a minimum of three coordinated days in the office per week, Monday, Wednesday and Thursday. As a perk, we also have up to four weeks per year of fully remote work

Responsibilities

  • Identifying vulnerabilities, demonstrating business impact, and articulating the risk of specific vulnerabilities to drive prioritization efforts
  • Perform penetration testing and design reviews, looking for vulnerabilities and insecure designs, work with engineering and product to design secure product features
  • Maintain and build internal tools to automate security efforts, perform SAST and DAST testing of the Brex platform, and support secure development practices
  • Build and contribute to a culture of collaborative security excellence through technical leadership, learning sessions, and mentorship within the team and wider organization

Requirements

  • 5+ years work experience in an Application Security or related role
  • Ability to find vulnerabilities in complex systems, demonstrating business impact through custom attack chains
  • Experience with a wide range of secure development activities including— threat modeling, developer education, and incident response
  • Knowledge of Python, scripting languages, and AI/agentic workflows to automate tasks, build tools and improve productivity
  • Collaborative mindset paired with strong written and verbal communication skills

Bonus points

  • Proficiency with Kotlin, gRPC, GraphQL, Kubernetes
  • Previous experience as a software engineer
  • Consultancy experience performing web application security reviews
  • Experience with securing distributed systems in AWS and cloud environments
  • Experience with pentesting and securing agentic features and systems
  • Contributions to the wider technical community— open source, public research, mentorship, community organizing, blogging, CVEs, presentations, etc
  • Experience submitting to bug bounty programs or responsible disclosure programs

Compensation

The expected salary range for this role is $192,000 - $240,000 CAD. However, the starting base pay will depend on a number of factors including the candidate's location, skills, experience, market demands, and internal pay parity. Depending on the position offered, equity and other forms of compensation may be provided as part of a total compensation package.



  • Vancouver, British Columbia, Canada Spring Financial Full time

    About UsSpring Financial is revolutionizing financial access for Canadians, providing smart credit-building, mortgage, and lending solutions. Millions struggle with high-interest debt and limited financial options—we're here to change that.As one of Canada's fastest-growing fintech companies, annually we help 1 million customers explore their financing...


  • Vancouver, British Columbia, Canada Spring Financial Full time

    About UsSpring Financial is a Canadian financial technology company focused on making every day financial services simpler, faster, and more accessible.We build technology that helps Canadians build credit, save money, and access lending products without unnecessary friction. Our platforms allow customers to apply and manage their finances online, by text,...


  • Vancouver, British Columbia, Canada Clio Full time

    Clio is the global leader in legal AI technology, empowering legal professionals and law firms of every size to work smarter, faster, and more securely.We are transforming the legal experience for all by bettering the lives of legal professionals while increasing access to justice.Summary:What your team does:We are currently seeking a Senior Application...


  • Vancouver, British Columbia, Canada Clio Full time

    Clio is the global leader in legal AI technology, empowering legal professionals and law firms of every size to work smarter, faster, and more securely.We are transforming the legal experience for all by bettering the lives of legal professionals while increasing access to justice.Summary:What your team does:We are currently seeking a Senior Application...


  • Vancouver, British Columbia, Canada Procurify Full time $122,000 - $157,000

    Senior Platform Security EngineerRemote within CanadaAbout The Team:The DevSecOps team owns the security, reliability, and overall management of Procurify's cloud platform. We design and operate scalable Cloud Infrastructure, implement and champion SRE best practices, and ensure the platform is resilient, cost-efficient, secure, and compliant. The DevSecOps...


  • Vancouver, British Columbia, Canada Procurify Full time

    Senior Platform Security Engineer Remote within Canada About The Team: The DevSecOps team owns the security, reliability, and overall management of Procurify's cloud platform. We design and operate scalable Cloud Infrastructure, implement and champion SRE best practices, and ensure the platform is resilient, cost-efficient, secure, and compliant. The...


  • Vancouver, British Columbia, Canada Procurify Full time

    Remote within CanadaAbout The Team:The DevSecOps team owns the security, reliability, and overall management of Procurify's cloud platform. We design and operate scalable Cloud Infrastructure, implement and champion SRE best practices, and ensure the platform is resilient, cost-efficient, secure, and compliant. The DevSecOps team partners with other...


  • Vancouver, British Columbia, Canada Warner Music Inc. Full time

    At Warner Music Group, we're a global collective of music makers and music lovers, tech innovators and inspired entrepreneurs, game-changing creatives and passionate team members. Here, we turn dreams into stardom and audiences into fans. We are guided by three core values that underpin everything we do across all our diverse businesses: • Curiosity: We...

  • Security Engineer

    7 days ago


    Vancouver, British Columbia, Canada Lendesk Full time

    The RoleWe're looking for a Senior Security Developer (aka Security Engineer) to join our Platform team and help safeguard the integrity of our applications, infrastructure, and data. This role is central to designing and implementing technical solutions that proactively prevent, detect, and respond to security threats. The ideal candidate brings a strong...


  • Vancouver, British Columbia, Canada RBC Full time

    Job DescriptionWhat is the Opportunity?Do you enjoy cyber security research and innovation, proactive thinking and problem solving, in a challenging and adaptive environment while constantly thinking outside of the box? If so, this opportunity is right for youRBC's Cloud Security Operations team is responsible for developing and investigating security alerts...