About us:
Spring Financial is a Canadian financial technology company focused on making every day financial services simpler, faster, and more accessible.
We build technology that helps Canadians build credit, save money, and access lending products without unnecessary friction. Our platforms allow customers to apply and manage their finances online, by text, or over the phone, making the experience convenient and flexible.
Since launching in 2014, Spring has grown into one of Canada’s largest fintechs, with over 250,000+ product originations across credit-building products, personal lending, and mortgage solutions. We’re a fast-growing, product-driven team that values practical solutions, strong execution, and thoughtful collaboration. We give people ownership, trust them to make decisions, and focus on building systems that scale reliably.
If you’re interested in working on real-world fintech platforms used by hundreds of thousands of Canadians, Spring offers the opportunity to make a tangible impact through well-built technology.
NOTE: This is a full-time, permanent, hybrid position in downtown Vancouver. 3 set days in the office and 2 WFH.
About the role:
As an Application Security Engineer II, you are an experienced practitioner who works independently to secure Spring’s applications, services, and APIs. You take ownership of application security across one or more product domains and play a central role in keeping those systems safe as they evolve. You understand the “why” behind the work, connecting security decisions to customer trust, regulatory commitments, and business outcomes. You demonstrate good judgment when working through ambiguity and elevate the security posture of the systems and teams around you.
You are responsible for designing and delivering moderately complex application security work, often navigating evolving requirements and unclear boundaries. You lead threat modeling sessions for new features, run secure code reviews on high-risk changes, and partner with engineering teams to remediate vulnerabilities in code, configurations, and dependencies. You help move security controls from advisory to enforced, with clear exception handling, so they protect delivery without blocking it unnecessarily. This is a core part of our current work. You make pragmatic choices that balance security rigor with delivery velocity, and you help teams understand which risks matter most. You contribute actively to Spring’s Secure Development Lifecycle (SDL), identifying gaps and proposing improvements that scale across engineering.
You are expected to use AI-powered tools to improve your productivity, especially for repetitive review tasks, vulnerability research, and remediation guidance. You incorporate these tools thoughtfully and remain accountable for validating their accuracy and security implications. You take full responsibility for the quality of your reviews and the controls you put in place. You help You help improve our automated security testing across code, dependencies, containers, infrastructure, and cloud configuration, and you treat false-positive reduction as a first-class problem because engineering trust in security tooling is a prerequisite for everything else we do.
You begin to work directly with product, engineering, and DevOps stakeholders, particularly on features that touch sensitive customer data, payment flows, or third-party integrations. You help clarify scope, translate security requirements into technical solutions, and provide insight into trade-offs and timelines. You represent application security in cross-functional conversations and take responsibility for delivering outcomes, not just findings. You also contribute to incident response, help our SOC 2 audit run smoothly by owning the evidence for application-level controls, and support cloud security and security monitoring work.
What you’ll do:
- Lead threat modeling, secure code reviews, and security architecture reviews for features and services in your domains, including APIs and authentication flows.
- Partner with engineering teams to remediate vulnerabilities across applications, APIs, and cloud configurations, driving issues to closure.
- Own and evolve sections of Spring’s SDL, embedding security checks and guardrails into CI/CD pipelines, and moving them from advisory to enforced with clear exception handling.
- Operate, tune, and improve automated security testing across code, dependencies, containers, and infrastructure, so findings are accurate and actionable. (e.g., Snyk, GitHub Advanced Security, Burp Suite, Semgrep, Checkov).
- Help define how vulnerabilities are tracked, prioritized, and closed, including exceptions and risk acceptance."
- Use AI tools to accelerate vulnerability research, code review, and remediation guidance, validating output critically, and help build AI-assisted security automation with human review gates.
- Triage cloud security and monitoring findings, and contribute to logging and detection improvements
- Collaborate with platform and DevOps teams on identity, access, and secrets management patterns (e.g., OAuth/OIDC, SSO, JWT token handling, Vault, AWS IAM).
- Contribute to incident response for application-related vulnerabilities, including investigation, containment, and post-incident learning.
- Own the application-level evidence and controls needed to support SOC 2 and other compliance obligations, including privacy (and where applicable, PCI DSS) audits.
- Mentor early-career application security engineers and help raise the team’s technical bar.
What we're looking for:
Requirements
- 3+ years of experience in application security, security engineering, or software engineering with a security focus.
- Solid working knowledge of web and cloud application security principles, the OWASP Top 10, and secure coding best practices.
- Proficiency reviewing code in at least one modern language, and scripting to automate security tasks.
- Hands-on experience with at least one threat modeling framework (e.g., STRIDE, PASTA) and the ability to lead a session for a moderately complex feature.
- Hands-on experience running automated security testing in a development pipeline, including tuning rules and reducing false positives. (e.g., Snyk, GitHub Advanced Security, Burp Suite, Semgrep, Checkov, or similar).
- Working knowledge of AWS and cloud-native architecture (e.g., microservices, containers, API gateways).
- Solid understanding of identity, access, and secrets management patterns (e.g., OAuth/OIDC, SSO, JWT token handling, Vault, AWS IAM).
- Effective use of AI development and security tools in day-to-day work, and an understanding of AI-specific security risks (e.g., prompt injection, data leakage).
- Strong written and verbal communication; able to influence engineers without authority.
- Exposure to compliance programs such as SOC 2, PCI DSS, or ISO 27001 is a plus.
Nice to have
- A relevant security certification (e.g. eJPT, OSCP, OSWE, BSCP, or AWS Security Specialty)
- AI security training or certification (e.g., AWS Certified AI Practitioner, Hack The Box AI Red Teamer path or OSAI)
- Regular hands-on practice (e.g., PortSwigger Web Security Academy, Hack The Box)
- Bug bounty findings or CTF participation or open-source security contributions.
- Experience leading incident response or post-incident reviews
What We Will Give You:
- Competitive annual salary ranging from $85,000 to $115,000, reflective of experience and impact.
- Comprehensive benefits package, including extended health, dental, and vision coverage - with 100% of monthly premiums covered by the Spring.
- GRSP matching program to support your long-term financial goals.
- A modern, collaborative workspace in the heart of downtown Vancouver.
- Ongoing career growth opportunities
Please note: Upon applying, our Talent Acquisition team will review your resume. If you qualify, we will reach out to learn more about your experience and answer any questions you may have about the role, benefits, compensation, and more. Due to high application volume, we may not be able to respond to everyone.
Thank you for your interest! We appreciate your time and look forward to reviewing your application!