Senior Application Security Engineer - Vancouver - Spring Financial

    Spring Financial
    Spring Financial Vancouver

    2 weeks ago

    Full time
    Description

    Senior Application Security Engineer at Spring Financial


    Join to apply for the Senior Application Security Engineer role at Spring Financial

    About Us


    Spring Financial is revolutionizing financial access for Canadians, providing smart credit‑building, mortgage, and lending solutions. Millions struggle with high‑interest debt and limited financial options—we're here to change that. As one of Canada's fastest‑growing fintech companies, annually we help 1 million customers explore their financing options with ease—online, via text, or over the phone. Our dynamic, innovative team thrives on collaboration, growth, and making a real impact.

    Our products can be explored on our website: NOTE: This is a full‑time, permanent, hybrid position in downtown Vancouver, with 3 set days in the office and 2 WFH.

    Job Overview


    As a Senior Application Security Engineer at Spring Financial, you will lead technical efforts to secure the software systems that power our business. You are responsible for driving security best practices across our engineering organization—embedding secure development into how we design, build, and deploy software. You'll work closely with product engineering, DevOps, platform, and compliance teams to identify risks, implement controls, and help teams ship secure, reliable features. This is primarily an individual contributor (IC) role, but may include leading a small team of engineers or acting as the technical owner for application security across the organization.

    You are expected to lead by example through strong technical execution, collaborative problem‑solving, and a practical, risk‑aware approach to security.

    You'll play a critical role in scaling our secure development lifecycle, supporting audit and compliance needs (e.g. SOC 2), and ensuring Spring's applications can evolve quickly without compromising trust.

    What You'll Do

    • Own Spring's application security strategy and roadmap — aligning initiatives with risk priorities, business needs, and platform evolution.
    • Lead the definition and rollout of secure development practices (e.g., threat modeling, secure code review, dependency management, static/dynamic analysis).
    • Partner with engineering teams to identify and remediate security risks across applications, services, APIs, and cloud environments.
    • Define and manage Spring's SDL (Secure Development Lifecycle), embedding security reviews, tooling, and guardrails into CI/CD workflows.
    • Support Spring's compliance posture, including SOC 2 readiness, audit participation, and evidence gathering for application‑level controls.
    • Own or contribute to incident response efforts for application‑related vulnerabilities or exposures.
    • Evaluate and implement security tools and services (e.g., SAST, DAST, SBOM, secrets scanning, WAF, CSPM) that improve detection and resilience.
    • Collaborate with platform, DevOps, and IT teams on access control, secret management, and zero‑trust enforcement.
    • Mentor and grow the appsec team, supporting both technical depth and cross‑functional influence.
    • Act as a subject matter expert for product and engineering teams on secure architecture, data protection, and third‑party risk.
    • Track and communicate security posture through clear metrics, risk registers, and executive‑level reporting.

    What You Should Already Have

    • 5+ years of experience in application security, software engineering, or security engineering roles, including at least 2 years in a leadership capacity.
    • Deep knowledge of web and cloud application security principles, OWASP Top 10, and secure coding best practices.
    • Experience implementing SDL processes and integrating security into CI/CD pipelines and agile environments.
    • Familiarity with threat modelling frameworks (e.g., STRIDE, PASTA) and secure architecture reviews.
    • Familiarity with cloud‑native architecture (e.g., AWS, microservices, containerisation, API gateways).
    • Hands‑on experience with modern appsec tools (e.g., Snyk, GitHub Advanced Security, Burp Suite, Semgrep, Checkov, or similar).
    • Understanding of common identity, access, and secrets management patterns (e.g., OAuth, JWT, Vault, AWS IAM).
    • Strong communication and collaboration skills; able to influence without authority and align across engineering and business stakeholders.
    • Experience supporting compliance initiatives such as SOC 2, PCI DSS, or ISO 27001 is a plus.

    What We Will Give You

    • Competitive annual salary ranging from $131,500 to $155,000, reflective of experience and impact.
    • Comprehensive benefits package, including extended health, dental, and vision coverage — with 100% of monthly premiums covered by Spring.
    • GRSP matching programme to support your long‑term financial goals.
    • Transit‑friendly employer (transit allowance).
    • A modern, collaborative workspace in the heart of downtown Vancouver.
    • Ongoing career growth opportunities.
    • This position is hybrid and requires in‑office presence; relocation assistance is available for the hired candidate (if out of province).

    This is a truly exciting time to join Spring Financial and we are looking forward to doing great things together

    Please note: Upon applying, our Talent Acquisition team will review your résumé. If you qualify, we will reach out to learn more about your experience and answer any questions you may have about the role, benefits, compensation, and more. Due to high application volume, we may not be able to respond to everyone.

    Thank you for your interest We appreciate your time and look forward to reviewing your application


    #J-18808-Ljbffr

  • Only for registered members Vancouver, British Columbia

    We re looking for a Security Engineer focused on Attack Surface Management (ASM) to help identify monitor and reduce our retail clients digital exposure. This role looks at our environment from an attacker s perspective finding internet facing assets misconfigurations and weak po ...

  • Only for registered members Vancouver

    +Insight Global is looking for a Security Engineer within Data & AI Security. · +Engineering secure, compliant, and resilient data and AI platforms across a rapidly scaling global business. · ...

  • Only for registered members Vancouver, British Columbia

    This is a high-profile team to join with a great leader. You will bring the experience and skills to the role.You will focus on protecting sensitive data and ensuring safe adoption of AI tools across the organization. · ...

  • Only for registered members Vancouver

    +This is a high-profile Security Engineer contact role working on a high-profile program with a local enterprise organization. · ...

  • Only for registered members Vancouver

    We are looking to hire a dynamic Junior Security Engineer to join the Attack Surface Management (ASM) team in Cybersecurity Engineering organization. · ...

  • Only for registered members Vancouver

    +We're looking for a Security Engineer focused on Attack Surface Management to help identify and reduce our retail clients digital exposure. · +Discover and monitor exposureAnalyze and prioritize riskReduce attack surface+<ul style= ...

  • Only for registered members Vancouver

    We're seeking an offensive-minded Security Engineer to help secure AI-enabled systems, agents, and LLM-integrated workflows across EA's games, services, and enterprise platforms. · ...

  • Only for registered members Vancouver, British Columbia

    The Business Security Enablement Guild (BSEG) is looking for a Lead Security Engineer to join us working out of our Vancouver office supporting the Next Gen DMP programs and initiatives. · Apply knowledge of security principles, theories and concepts to business and development l ...

  • Only for registered members Greater Vancouver Metropolitan Area

    We are looking for an AI Security Engineer to join our Cyber Security Engineering job family and focus on emerging field of Artificial Intelligence (AI) and Machine Learning (ML) security. · ...

  • Only for registered members Vancouver, British Columbia

    The EA SPORTS Security team helps make games safe secure and fun by developing in-game security features analysing data and responding to security incidents.Develop and implement security features across client applications and game servers. · Maintain legacy code to enhance perf ...

  • Only for registered members Vancouver, British Columbia

    This is starting as a 3 month contract in Vancouver with Insight Global. · Jr Security Engineer position at ASM team for Retail Apparel Client · ...

  • Only for registered members Vancouver, British Columbia

    Workstream is building an all-in-one HR, payroll and hiring platform for managing hourly workers. · ...

  • Only for registered members Vancouver, Canada

    Job summary · Workstream is building an all-in-one HR, payroll, and hiring platform for hourly workers. ResponsibilitiesFix security issues directly in the codebase. · Review designs and changes involving authentication and sensitive data. · ...

  • Only for registered members Vancouver, British Columbia

    Building the security foundation for dental's digital infrastructure. · ...

  • Only for registered members Vancouver, British Columbia

    This is an opportunity to join a fast-growing Canadian fintech organization focused on building secure, accessible, and trusted digital solutions for small businesses across the country. · You'll operate and manage vulnerability and exposure management platforms to identify, prio ...

  • Only for registered members Vancouver, British Columbia

    We are growing a lasting legacy in the beverage alcohol industry, with people first. · Implement and maintain cloud protection technologies. · Monitor cloud activity and respond to security incidents. · ...

  • Only for registered members Vancouver, British Columbia

    We are looking for a senior security engineer to drive a strong security culture. · ...

  • Only for registered members Vancouver, British Columbia Remote job

    We are looking for a Senior Security Engineer to join our talent network and connect with U.S. clients for flexible, project-based development work. · You will integrate directly into our client's team and work alongside their existing designers and engineers on a daily basis. · ...

  • Only for registered members BC, Canada

    A valued TELUS client is seeking a seasoned Microsoft Security Engineer to maintain, optimize, and secure their live enterprise environment. · ...

  • Only for registered members Vancouver Full time $150,000 - $180,000 (USD)

    + Workstream is a mission-driven company building an all-in-one HR, payroll, and hiring platform for managing hourly workers. · Embed yourself in software development lifecycle (SDLC). Perform code reviews and architectural analysis · Work side-by-side with software engineers to ...

  • Only for registered members Vancouver, Canada

    Come join our Data Center Engineering Team and work on one of the most advanced 3D-NAND and SSD technology portfolios in the world. · ...

Jobs
>
Senior application security engineer
>
Jobs for Senior application security engineer in Vancouver