Application Security, Senior Specialist

Interac

Toronto

Hybrid

CAD 85,000 - 105,000

Full time

3 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Generous vacation & wellness days
Benefits coverage
RRSP program
Flexible hybrid work model
24/7 Employee & family assistance
Parental leave top-up
Charitable donation matching

Job summary

Interac Corp. in Canada is seeking an Application Security, Senior Specialist to safeguard our ecosystem by embedding security into the software development lifecycle and champion secure-by-design practices.

You will partner with engineering, product, cloud, and security teams to model threats, guide remediation, and build scalable DevSecOps capabilities across web, mobile, and backend systems.

Qualifications

  • 5+ years of experience in application security, software security engineering, or related roles.
  • Strong understanding of modern application architectures (microservices, APIs, containers, serverless).
  • Expertise in DevSecOps practices and SSDLC frameworks.
  • Hands-on experience with SAST, SCA, DAST, secrets scanning, and CI/CD security tooling.
  • Proficiency in at least one programming language (e.g., Java, Python, JavaScript, Go).
  • Experience performing threat modeling, code reviews, and vulnerability assessments.
  • Knowledge of cloud security principles (AWS, Azure, or GCP).
  • Familiarity with OWASP Top10, CWE, NIST, and other security frameworks.
  • Strong communication skills and the ability to influence without authority.
  • Cybersecurity certifications such as CISSP, CSSLP, CCSP, OSCP.

Responsibilities

  • Embed security controls into all phases of the SDLC and conduct secure design reviews and threat modeling.
  • Perform application security assessments (static/dynamic analysis, dependency scanning) and coordinate remediation.
  • Support penetration testing activities and coordinate follow-up actions.
  • Maintain and optimize AppSec tools (SAST, SCA, DAST, secrets scanning) and integrate into CI/CD pipelines.
  • Assess application-level risks and ensure regulatory alignment (PCI DSS, SOC2, OWASP).
  • Deliver training and secure coding sessions to raise security awareness across teams.

Skills

5+ years of experience
Microservices & APIs
DevSecOps
Security tooling
Programming languages
Threat modeling
Cloud security
OWASP knowledge
Communication
Certifications

Tools

SAST
SCA
DAST
Secrets scanning
Container security platforms

Job description

Who We Are

Every transaction matters. Every Canadian matters. At Interac, we protect both — driving trust, security, and inclusion, so our digital economy thrives. Founded in 1984, Interac connects Canadians through secure digital payments, advanced identity verification and industry-leading fraud protection. Connecting banks, businesses, and individuals, Interac enables millions to send, receive, and manage money safely and effortlessly every day — across both digital and physical environments. As the backbone of Canada’s financial ecosystem, Interac facilitates over 20 million transactions daily, supported by trusted partnerships with government and financial institutions. Consistently ranked as Canada’s most reputable financial technology brand, Interac is deeply embedded in the daily lives of Canadians.

Who You Will Work With

The Application Security, Senior Specialist will play a critical role in safeguarding our ecosystem by ensuring that our applications are designed, built, and deployed securely. You will work closely with engineering, product, cloud, and security teams to embed security into the software development lifecycle, model threats associated with the application, identify and assist engineering in mitigating vulnerabilities during build, reduce security defects into prod, and champion secure‑by‑design principles across the organization.

Secure Development Lifecycle (SDLC) Enablement

Embed security controls and best practices into all phases of the SDLC. Conduct secure design reviews, threat modeling, and architecture assessments for new and existing applications. Partner with engineering teams to ensure secure coding practices and frameworks are consistently applied. Provide guidance on secure API design, microservices security, and cloud‑native application patterns.

Vulnerability Identification & Remediation

Perform application security assessments, including static/dynamic analysis, dependency scanning, and manual code review. Triage, prioritize, and track remediation of vulnerabilities across web, mobile, and backend systems. Collaborate with development teams to provide actionable remediation guidance and validate fixes. Support penetration testing activities and coordinate follow‑up actions.

Security Tooling, Automation & DevSecOps

Maintain and optimize AppSec tools such as SAST, SCA, DAST, secrets scanning, and container security platforms. Integrate security tooling into CI/CD pipelines to enable automated, scalable security testing. Identify opportunities to improve automation, reduce friction, and enhance developer experience.

Risk Assessment, Governance & Compliance

Assess application‑level risks and contribute to enterprise risk reporting. Ensure application security practices align with regulatory requirements and industry standards (e.g., PCI DSS, SOC2, OWASP). Support audit activities by providing evidence, documentation, and subject‑matter expertise.

Cross‑Functional Collaboration & Security Advocacy

Act as a trusted advisor to engineering, product, and cloud teams on application security matters. Deliver training, workshops, and secure coding sessions to elevate security awareness across the organization. Communicate complex security issues in a clear, actionable way to both technical and non‑technical stakeholders. Stay current with emerging threats, vulnerabilities, and security technologies, and proactively assess their impact on the organization.

What You Bring
  • 5+ years of experience in application security, software security engineering, or related roles within FinTech, SaaS, or cloud‑native environments.
  • Strong understanding of modern application architectures (microservices, APIs, containers, serverless).
  • Expertise in DevSecOps practices and SSDLC frameworks.
  • Hands‑on experience with SAST, SCA, DAST, secrets scanning, and CI/CD security tooling.
  • Proficiency in at least one programming language (e.g., Java, Python, JavaScript, Go) and familiarity with secure coding practices.
  • Experience performing threat modeling, code reviews, and vulnerability assessments.
  • Knowledge of cloud security principles (AWS, Azure, or GCP).
  • Familiarity with OWASP Top10, CWE, NIST, and other security frameworks.
  • Strong communication skills and the ability to influence without authority.
  • A proactive, problem‑solving mindset and a passion for building secure, resilient systems.
  • Cybersecurity certifications such as CISSP, CSSLP, CCSP, OSCP.
  • Eligibility to work for Interac Corp. in Canada in a full‑time capacity.
What We’re Offering

The hiring range for this position is $85,000 - $105,000, and you will also be eligible for our short-term incentive plan. The exact amount will depend on factors such as skills, experience, and job-related knowledge, but Interac’s commitment goes beyond compensation. Our Total Rewards package is designed to support your well-being and future, and includes:

  • Generous vacation and wellness days to help you recharge
  • Comprehensive employer-paid benefits coverage for peace of mind
  • Market-leading employer-funded RRSP program to invest in your future
  • Flexible hybrid work model for better work-life balance
  • Access to a free and confidential 24/7 employee & family assistance program to offer support for you and your immediate family
  • Pregnancy and parental leave top-up to support growing families
  • Charitable donation matching with United Way to amplify your impact
Why Join Us?
  • Investing in the Future – Help us unlock digital prosperity for all Canadians.
  • Innovative Thinking – Collaborate on products, practices, and platforms that redefine what’s possible.
  • Inclusive Culture – Be empowered to bring your whole self to work and realize your full potential.
  • Inspiring Community – Work in an ecosystem where we lift each other up and rise together.
  • Intentional Support – Enjoy flexible, supportive offerings that prioritize your total wellness.
Additional Pre-Employment Requirements

To ensure the integrity of our organization, successful candidates will be required to complete background checks, which may include, Canadian Criminal Credit Check, Canadian ID Cross-Check, Public Safety Verification, 5-year Employment Verification, Education Verification, Credit Check, and Social Media Check.

Equal Opportunity Employer

Interac is also an equal opportunity employer committed to fostering a diverse and inclusive workplace. We believe that innovation thrives when people from different backgrounds, experiences, and perspectives come together. That’s why we are committed to providing fair and equitable employment opportunities for all individuals, without discrimination based on race, color, ancestry, ethnic origin, place of origin, citizenship, creed, sex, sexual orientation, gender identity or expression, age, marital or family status, disability, or any other characteristic protected by applicable law. If you require accommodation during any stage of the application or recruitment process, please contact us at humanresources@interac.ca. We will work with you to meet your needs.

About Interac Corp.

Interac empowers Canadians to transact digitally with confidence by providing payment and value exchange services. In helping to develop the future of money and data in Canada, security is the core of everything we do. We help keep Canadian customers safe and secure when transacting. With nearly 300 financial institutions connected to our network, Canadians choose Interac products over 20 million times a day on average to exchange money. Interac champions workplace culture, community, and corporate citizenship. We are proud to be one of Canada’s leading and most trusted financial brands.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

SOC Engineering, Lead
SOC Engineering, Lead

Interac Corp. • Toronto

Hybrid
CAD 120,000 - 135,000
Vacation days
Benefits package
RRSP plan
+4
Engineering Standards, Lead
Engineering Standards, Lead

Interac Corp. • Toronto

On-site
CAD 145,000 - 160,000
Generous vacation and wellness days
Employer-paid benefits coverage
RRSP program
+5
Leader, Governance, Risk & Compliance
Leader, Governance, Risk & Compliance

Interac Corp. • Toronto

Hybrid
CAD 150,000 - 180,000
Vacation & Wellness days
Benefits coverage
RRSP program
+4
Technical Support Coordinator
Technical Support Coordinator

Interac Corp. • Toronto

On-site
CAD 58,000 - 65,000
Generous vacation and wellness days
Employer-paid benefits
Fraud Strategy, Senior Specialist
Fraud Strategy, Senior Specialist

Interac Corp. • Toronto

Hybrid
CAD 85,000 - 105,000
Generous vacation days
Health & dental benefits
RRSP matching
+4
Technical Support Coordinator
Technical Support Coordinator

Interac • Toronto

On-site
CAD 58,000 - 65,000
Generous vacation and wellness days
Employer-paid benefits
RRSP program
+3
Incident Management, Lead
Incident Management, Lead

Interac • Toronto

Hybrid
CAD 125,000 - 155,000
Generous vacation and wellness days
Employer-paid benefits
RRSP program
+4
Incident Management, Lead (Bilingual)
Incident Management, Lead (Bilingual)

Interac • Toronto

Hybrid
CAD 125,000 - 155,000
Vacation & wellness days
Benefits coverage
RRSP program
+4
Technical Support Coordinator (Bilingual)
Technical Support Coordinator (Bilingual)

Interac Corp. • Toronto

On-site
CAD 58,000 - 65,000
Vacation and wellness days
Employer-paid benefits
RRSP matching
+3
Incident Management, Lead
Incident Management, Lead

Interac Corp. • Toronto

Hybrid
CAD 125,000 - 155,000
Vacation and wellness days
Employer-paid benefits
RRSP program
+4