FREE ACCESS
5,000–10,000 jobs/day
See all jobs on Scoutfield
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.

Application Security Engineer – Level II
Spring Financial. Lead threat modeling, secure code reviews, and security architecture reviews for features and services, including APIs and authentication flows .
Core Competencies
Role fitCore Competencies
Use this summary to align your resume positioning with the role.
Demonstrates expertise in application security, secure coding practices, and vulnerability remediation, with a strong focus on integrating security into development processes and CI/CD pipelines. Proficient in threat modeling, automated security testing, and compliance with standards such as SOC 2 and PCI DSS.
Highest-signal resume keywords
Application SecurityThreat Modeling FrameworksAutomated Security TestingAWS Cloud SecuritySecure Coding Best Practices
ATS Keywords
Tailor your resumeApplicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills
Application SecuritySecure Coding PracticesThreat ModelingAutomated Security TestingVulnerability RemediationWeb Application SecurityCloud Application SecurityScripting for AutomationIdentity and Access ManagementCompliance Standards
Soft Skills
Strong CommunicationMentoringCollaboration
Tools & Technologies
SnykGitHub Advanced SecurityBurp SuiteSemgrepCheckovAWS IAMOAuth/OIDCJWTVault
Certifications & Qualifications
Relevant Security CertificationAI Security Training or Certification
Industry Keywords
OWASP Top 10SOC 2PCI DSSISO 27001Incident Response
Tech Stack
Tools & technologiesAWSCloudMicroservicesSpringVault
About the role
Key responsibilities & impact- Lead threat modeling, secure code reviews, and security architecture reviews for features and services, including APIs and authentication flows
- Partner with engineering teams to remediate vulnerabilities across applications, APIs, and cloud configurations, driving issues to closure
- Own and evolve sections of Spring’s Secure Development Lifecycle, embedding security checks and guardrails into CI/CD pipelines
- Move security controls from advisory to enforced with clear exception handling
- Operate, tune, and improve automated security testing across code, dependencies, containers, and infrastructure using tools such as Snyk, GitHub Advanced Security, Burp Suite, Semgrep, and Checkov
- Use AI tools to accelerate vulnerability research, code review, and remediation guidance while validating output critically
- Help build AI-assisted security automation with human review gates
- Triage cloud security and monitoring findings and contribute to logging and detection improvements
- Collaborate with platform and DevOps teams on identity, access, and secrets management patterns
- Contribute to incident response for application-related vulnerabilities, including investigation, containment, and post-incident learning
- Own application-level evidence and controls for SOC 2 and other compliance obligations, including privacy and applicable PCI DSS audits
- Mentor early-career application security engineers and raise the team’s technical bar
- Work with product, engineering, and DevOps stakeholders on sensitive customer data, payment flows, and third-party integrations
- Support cloud security and security monitoring work
Requirements
What you’ll need- 3+ years of experience in application security, security engineering, or software engineering with a security focus
- Solid working knowledge of web and cloud application security principles, the OWASP Top 10, and secure coding best practices
- Proficiency reviewing code in at least one modern language, and scripting to automate security tasks
- Hands-on experience with at least one threat modeling framework, such as STRIDE or PASTA, and ability to lead a session for a moderately complex feature
- Hands-on experience running automated security testing in a development pipeline, including tuning rules and reducing false positives
- Working knowledge of AWS and cloud-native architecture, including microservices, containers, and API gateways
- Solid understanding of identity, access, and secrets management patterns, including OAuth/OIDC, SSO, JWT token handling, Vault, and AWS IAM
- Effective use of AI development and security tools in day-to-day work
- Understanding of AI-specific security risks, such as prompt injection and data leakage
- Strong written and verbal communication; able to influence engineers without authority
- Relevant security certification, AI security training or certification, regular hands-on practice, bug bounty findings, CTF participation, open-source security contributions, incident response leadership, and post-incident review experience are nice to have
- Exposure to compliance programs such as SOC 2, PCI DSS, or ISO 27001 is a plus
Benefits
Comp & perks- Comprehensive benefits package, including extended health, dental, and vision coverage — with 100% of monthly premiums covered by the Spring
- GRSP matching program to support your long-term financial goals
- Modern, collaborative workspace in downtown Vancouver
- Ongoing career growth opportunities
- Hybrid work arrangement: 3 set days in the office and 2 WFH