Application Security Engineer II
springfinancial · Vancouver, British Columbia, Canada ·
- Work mode
- Hybrid
- Employment
- Full time
- Category
- Security
- Experience
- 3+ years
springfinancial · Vancouver, British Columbia, Canada ·
gamma · San Francisco
Encord · GB
savvy · NYC Office
jobgether · US
About us:
Spring Financial is a Canadian financial technology company focused on making every day financial services simpler, faster, and more accessible.
We build technology that helps Canadians build credit, save money, and access lending products without unnecessary friction. Our platforms allow customers to apply and manage their finances online, by text, or over the phone, making the experience convenient and flexible.
Since launching in 2014, Spring has grown into one of Canada’s largest fintechs, with over 250,000+ product originations across credit-building products, personal lending, and mortgage solutions. We’re a fast-growing, product-driven team that values practical solutions, strong execution, and thoughtful collaboration. We give people ownership, trust them to make decisions, and focus on building systems that scale reliably.
If you’re interested in working on real-world fintech platforms used by hundreds of thousands of Canadians, Spring offers the opportunity to make a tangible impact through well-built technology.
NOTE: This is a full-time, permanent, hybrid position in downtown Vancouver. 3 set days in the office and 2 WFH.
About the role:
As an Application Security Engineer II, you are an experienced practitioner who works independently to secure Spring’s applications, services, and APIs. You take ownership of application security across one or more product domains and play a central role in keeping those systems safe as they evolve. You understand the “why” behind the work, connecting security decisions to customer trust, regulatory commitments, and business outcomes. You demonstrate good judgment when working through ambiguity and elevate the security posture of the systems and teams around you.
You are responsible for designing and delivering moderately complex application security work, often navigating evolving requirements and unclear boundaries. You lead threat modeling sessions for new features, run secure code reviews on high-risk changes, and partner with engineering teams to remediate vulnerabilities in code, configurations, and dependencies. You help move security controls from advisory to enforced, with clear exception handling, so they protect delivery without blocking it unnecessarily. This is a core part of our current work. You make pragmatic choices that balance security rigor with delivery velocity, and you help teams understand which risks matter most. You contribute actively to Spring’s Secure Development Lifecycle (SDL), identifying gaps and proposing improvements that scale across engineering.
You are expected to use AI-powered tools to improve your productivity, especially for repetitive review tasks, vulnerability research, and remediation guidance. You incorporate these tools thoughtfully and remain accountable for validating their accuracy and security implications. You take full responsibility for the quality of your reviews and the controls you put in place. You help You help improve our automated security testing across code, dependencies, containers, infrastructure, and cloud configuration, and you treat false-positive reduction as a first-class problem because engineering trust in security tooling is a prerequisite for everything else we do.
You begin to work directly with product, engineering, and DevOps stakeholders, particularly on features that touch sensitive customer data, payment flows, or third-party integrations. You help clarify scope, translate security requirements into technical solutions, and provide insight into trade-offs and timelines. You represent application security in cross-functional conversations and take responsibility for delivering outcomes, not just findings. You also contribute to incident response, help our SOC 2 audit run smoothly by owning the evidence for application-level controls, and support cloud security and security monitoring work.
What you’ll do:
What we're looking for:
Requirements
Nice to have
What We Will Give You:
Please note: Upon applying, our Talent Acquisition team will review your resume. If you qualify, we will reach out to learn more about your experience and answer any questions you may have about the role, benefits, compensation, and more. Due to high application volume, we may not be able to respond to everyone.
Thank you for your interest! We appreciate your time and look forward to reviewing your application!
Invictus Direct · San Francisco, California, United States