Application Security, Senior Specialist

Interac Corp.

$85K — $105K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5+ years in application security, software security engineering, or related roles in FinTech, SaaS, or cloud-native environments.
  • Strong grasp of modern application architectures including microservices, APIs, containers, and serverless.
  • Expertise in DevSecOps practices and Secure Software Development Life Cycle (SDLC) frameworks.
  • Hands-on experience with security tools like SAST, SCA, DAST, and CI/CD security.
  • Proficient in at least one programming language (e.g., Java, Python, JavaScript, Go) and secure coding practices.
  • Experience in threat modeling, code reviews, and vulnerability assessments.
  • Knowledge of cloud security principles (AWS, Azure, or GCP).

Responsibilities

  • Embed security controls into all phases of the software development lifecycle.
  • Conduct secure design reviews, threat modeling, and architecture assessments.
  • Partner with engineering teams to ensure secure coding practices are followed.
  • Perform application security assessments and manual code reviews.
  • Triage and track remediation of vulnerabilities across systems.
  • Maintain and optimize security tools within the CI/CD pipelines.
  • Act as a security advisor, delivering training to elevate security awareness.

Benefits

  • Generous vacation and wellness days to recharge.
  • Comprehensive employer-paid benefits coverage.
  • Market-leading employer-funded RRSP program.
  • Flexible hybrid work model for work-life balance.
  • 24/7 employee and family assistance program access.
  • Pregnancy and parental leave top-up.
  • Charitable donation matching with United Way.
Full Job Description

Who You Will Work With:

The Application Security, Senior Specialist will play a critical role in safeguarding our ecosystem by ensuring that our applications are designed, built, and deployed securely. You will work closely with engineering, product, cloud, and security teams to embed security into the software development lifecycle, model threats associated with the application, identify and assist engineering in mitigating vulnerabilities during build, reduce security defects into prod, and champion secure‑by‑design principles across the organization.

What YouWillDo:

Secure Development Lifecycle (SDLC) Enablement

  • Embed security controls and best practices into all phases of the SDLC.

  • Conduct secure design reviews, threat modeling, and architecture assessments for new and existing applications.

  • Partner with engineering teams to ensure secure coding practices and frameworks are consistently applied.

  • Provide guidance on secure API design, microservices security, and cloudnative application patterns.

Vulnerability Identification & Remediation

  • Perform application security assessments, including static/dynamic analysis, dependency scanning, and manual code review.

  • Triage, prioritize, and track remediation of vulnerabilities across web, mobile, and backend systems.

  • Collaborate with development teams to provide actionable remediation guidance and validate fixes.

  • Support penetration testing activities and coordinate followup actions.

Security Tooling, Automation & DevSecOps

  • Maintain and optimize AppSec tools such as SAST, SCA, DAST, secrets scanning, and container security platforms.

  • Integrate security tooling into CI/CD pipelines to enable automated, scalable security testing.

  • Identify opportunities to improve automation, reduce friction, and enhance developer experience.

Risk Assessment, Governance & Compliance

  • Assess applicationlevel risks and contribute to enterprise risk reporting.

  • Ensure application security practices align with regulatory requirements and industry standards (e.g., PCI DSS, SOC 2, OWASP).

  • Support audit activities by providing evidence, documentation, and subjectmatter expertise.

CrossFunctional Collaboration & Security Advocacy

  • Act as a trusted advisor to engineering, product, and cloud teams on application security matters.

  • Deliver training, workshops, and secure coding sessions to elevate security awareness across the organization.

  • Communicate complex security issues in a clear, actionable way to both technical and nontechnical stakeholders.

  • Stay current with emerging threats, vulnerabilities, and security technologies, and proactively assess their impact on the organization.

WhatYou Bring:

  • 5+ years of experience in application security, software security engineering, or related roles within FinTech, SaaS, or cloudnative environments.

  • Strong understanding of modern application architectures (microservices, APIs, containers, serverless).

  • Expertise in DevSecOps practices and SSDLC frameworks

  • Handson experience with SAST, SCA, DAST, secrets scanning, and CI/CD security tooling.

  • Proficiency in at least one programming language (e.g., Java, Python, JavaScript, Go) and familiarity with secure coding practices.

  • Experience performing threat modeling, code reviews, and vulnerability assessments.

  • Knowledge of cloud security principles (AWS, Azure, or GCP).

  • Familiarity with OWASP Top 10, CWE, NIST, and other security frameworks.

  • Strong communication skills and the ability to influence without authority.

  • A proactive, problemsolving mindset and a passion for building secure, resilient systems.

  • Cybersecurity certifications such as CISSP, CSSLP, CCSP, OSCP

  • Eligibility to work for Interac Corp. in Canada in a full-time capacity. 

WhatWereOffering:

The hiringrangefor this position is85,000 - $105,000, and you will also be eligible for our short-term incentive plan. The exact amount will depend on factors such as skills, experience, and job-related knowledge, butInteracscommitment goes beyond compensation. Our Total Rewards package is designed to support your well-being and future, and includes:

  • Generous vacation and wellness days to help you recharge

  • Comprehensive employer-paid benefits coverage for peace of mind

  • Market-leading employer-funded RRSP program to invest in your future

  • Flexible hybrid work model for better work-life balance

  • Accessto afree and confidential 24/7 employee & familyassistanceprogram to offer support for you and your immediate family

  • Pregnancy and parental leave top-up to support growing families

  • Charitable donation matching with United Way to amplify your impact

Additional Pre-Employment Requirements:

To ensure the integrity of our organization, successful candidates will be required to complete background checks, which may include, Canadian Criminal Credit Check, Canadian ID Cross-Check, Public Safety Verification, 5-year Employment Verification, Education Verification, Credit Check, and Social Media Check.

Similar Jobs

More Jobs at Interac Corp.

More Information Technology Jobs

Find similar Application Security, Senior Specialist jobs: