368,530open jobs
9,432companies
50,439added this week
Browse all
Salary
$94k – $115k per year
Location
In office (Vancouver)
Seniority
Senior · 5+ years exp
Employment
Full-Time
Overview
Company
Impact
Profile match
Discover seamless integration of banking functionalities into your ERP or accounting software with FISPAN. FISPAN’s solution integrates with leading platforms like Oracle NetSuite, Sage Intacct, Microsoft Dynamics 365 Business Central, QuickBooks Online, and Xero.

Our Business

FISPAN Services Inc. (FISPAN) is an Enterprise SaaS FinTech company that allows banks to deploy embedded financial products and services to create a seamless banking connection for their corporate clients. Our product aims to provide instant scale and reach for banks who want to remove friction and add value by enabling their commercial banking clients to access banking services through their preferred ERP / accounting platform.

Founded in 2016 and headquartered in downtown Vancouver, FISPAN is on a mission to create the best product in the FinTech industry and fundamentally change the way that companies bank. Being the market leader in ERP Banking, we work with the world’s Tier 1 banks with assets exceeding $3T, including J.P. Morgan Chase, Wells Fargo, TD and Bank of Montreal.

We are looking for dynamic and passionate individuals to join our high performance team and contribute to our rapid growth and exciting journey.

Position Overview

As a Senior Security Engineer, you will provide senior-level expertise and advanced security analysis capabilities within our organization's security operations. Operating at a senior level, you will be a hands-on defender and attacker-mindset practitioner - running security monitoring, threat detection, and incident response, while proactively finding and closing gaps through vulnerability assessment and penetration testing. You will also apply that offensive mindset to the infrastructure you help secure: fine-tuning our SIEM, hardening cloud environments, implementing Zero Trust Architecture, and securing our CI/CD pipelines. You will champion an automation-first and AI-augmented mindset, using AI tooling and Infrastructure as Code (IaC) to scale detection, response, and testing across the board.

Note: This role operates on a hybrid schedule, requiring you to be in the downtown Vancouver office 1-3 days per week.

  • Security Operations & Threat Detection
    • Drive day-to-day execution of security operations, utilizing AI-assisted analysis to ensure rapid and proper coordination of incident response with all parties of interest.revised
    • Ensure all incident tickets are assigned, tracked, and resolved in compliance with operations SLAs.
    • Improve alert signal-to-noise ratios and integrate external threat intel with security monitoring tools.
    • Regularly update and continuously improve threat detection use cases, using AI tools to assist in rapid rule generation and threat modeling.
    • Continuously fine-tune our SIEM to reduce false positives, leveraging ML/AI capabilities to ensure pertinent data sources are onboarded and adequately parsed.
  • Offensive Security & Vulnerability Management
    • Plan and conduct internal penetration tests and vulnerability assessments across applications, networks, and cloud environments.
    • Demonstrate hands-on exploitation ability against common web vulnerabilities (e.g., SQL injection, XSS) to validate and clearly communicate findings - not just relying on scanner output.revised
    • Manually triage and identify complex or obfuscated attack patterns within raw log/SIEM data, beyond what pre-built alerts surface.revised
    • Perform red-team-style exercises and adversary simulation to validate detection and response capabilities, translating findings into concrete remediation and detection improvements.
    • Drive enterprise-wide vulnerability and configuration management, prioritizing and pushing remediation based on exploitability and business risk.revised
    • Coordinate and/or manage third-party penetration tests and bug bounty engagements, tracking findings through to closure.
    • Conduct structured threat modeling on new features, services, and architecture changes to proactively identify attack surfaces and prioritize testing and remediation.revised
    • Identify, assess, and mitigate emerging AI risks, with a specific focus on vulnerabilities related to cloud-based AI services and agent-based AI architectures.
  • Security Engineering & Infrastructure Hardening - supporting skillset, not the primary focus
    • Manage and secure cloud environments, using cloud firewalls and endpoint/CSPM platforms, informed by findings from testing and monitoring.
    • Deploy and maintain Zero Trust Architecture (ZTA).
    • Administer edge protections, including DDoS mitigation, WAF, and CDN configurations.
    • Integrate and manage security within the CI/CD pipeline, including DAST, SAST, and SCA.
    • Secure the software development lifecycle by integrating and managing scanning and repository tools.
    • Manage and secure containerized environments, ensuring safe image builds, dependency management, and secure deployments.
    • Secure user SaaS-based tools (Google Workspace, Atlassian, Slack), Mac-based MDM, and DNS/mail security.
  • Automation, Documentation & Leadership
    • Continually leverage generative AI, scripting, and Infrastructure as Code (IaC) across all tasks - from incident triage to exploit/test tooling to playbook creation to reduce manual toil and scale security operations.
    • Manage the development of security documents, such as incident playbooks and security operations procedures.
    • Develop and exercise attack/defense playbooks (tabletop exercises, purple-team drills), keeping all security operations documents up to date.
    • Lead and mentor junior personnel within the security team.
  • Skills & Experience Required
    • Strong written and verbal English communication skills, with a proven ability to break down intricate security risks and procedures for both technical and non-technical audiences.
    • Degree in information technology, computer science, cybersecurity, or a related field.
    • 5+ years of experience in security analysis, penetration testing, incident response, or a related field - with demonstrated hands-on offensive security experience (internal pentesting, red-teaming, or vulnerability research).
    • Demonstrated, hands-on ability to identify and exploit common web application vulnerabilities (e.g., SQL injection, XSS) in a live setting comfort working directly against a target, not just running automated tools.revised
    • Proven ability to manually read and interpret raw log/SIEM data to spot sophisticated or obfuscated attacker activity, not solely alert-driven triage.revised
    • OSCP required or in progress (or equivalent demonstrated offensive security capability); CISSP, CISM, or GCIH also valued.
    • AWS Security Certification or equivalent experience.
    • In-depth knowledge of security principles, attacker TTPs (e.g., MITRE ATT&CK), and common vulnerability classes (OWASP Top 10, etc.).
    • Strong understanding of network protocols, operating systems, and how to exploit and defend common misconfigurations.
    • Working knowledge of Infrastructure as Code (IaC), scripting/automation, and modern AI assistants to streamline security workflows, testing, and incident response fluent enough to assess and harden IaC, not necessarily its primary builder.
    • Familiarity with containerization and orchestration platforms (Kubernetes, Helm, Docker) and secure image/dependency management practices.
    • Knowledge of security frameworks and standards, such as NIST, ISO 27001, and CIS Controls.
    • Familiarity with regulatory requirements, such as PCI DSS and GDPR.
    • Practical experience applying structured threat modeling approaches to assess risk and prioritize security testing.revised
    • Understanding of the threat landscape surrounding AI technologies, specifically evaluating and securing cloud and agent-based models.
    • Strong analytical and problem-solving skills, paired with excellent communication and collaboration abilities.

Technology Stack

Experience with equivalent or similar tools is completely acceptable.

  • Offensive / testing - Burp Suite, Metasploit, Nmap, Cobalt Strike (or similar C2/pentest frameworks), Nessus / TenableIO
  • Logging & SIEM - Splunk
  • Cloud & endpoint - CrowdStrike (Host and CSPM), AWS Security, Cloud Firewalls (AWS/Fortinet)
  • Automation & IaC - Terraform, CloudFormation, Ansible, or similar; scripting in Python/Bash
  • Containers - Kubernetes, Helm, Docker
  • Pipeline security - Sonarcloud, Snyk, GitHub, Quay, Artifactory
  • Network & edge - Cloudflare/CloudFront (DDoS, WAF, CDN), ZScaler (ZTA)
  • Vuln management - TenableIO, Snyk, Artifactory
  • SaaS & email -Proofpoint, Google Workspace, Atlassian, Slack
  • Device mgmt - Mac-based MDM (JAMF or Kandji)

Why Work With Us?

Visionary Team, Proven Results

Our leadership bench brings deep, collective experiencein scaling high-growth FinTech companies through major funding cycles and critical market inflection points. This expertise creates a stable foundation, allowing you to focus on building and innovating. You will benefit directly from mentorship, expand your professional network, and learn the strategic decision-making processes required to lead a global, mature technology company.

Accelerated Career Ownership & DEI Commitment

We are an emerging high-growth company, and that means your career trajectory here is accelerated. Our employees are immediately given a high level of ownership and autonomy over complex, impactful projects.

As FISPAN continues to grow, we are committed to celebrating diversity, endorsing equity, and encouraging inclusion. We strive to eliminate bias throughout our recruitment process and build a culture where everyone feels they belong and can contribute their best work.

Strategic Total Rewards & Wellbeing

We invest in your success. Our total compensation packages are designed to be highly competitive, including a semi-annual bonus plan that give you a true stake in our future. Beyond your compensation, you benefit from:

  • Best-in-Class Equipment: The most modern MacBook and Apple equipment.
  • Prime Location: Our downtown Vancouver office offers coastal views and access to the building fitness center.
  • Flexibility: Generous benefits, including a family leave top-up program and our Work-From-Anywhere policy.

Purpose-Driven Culture & Prime Perks

Our culture is the foundation of our success. We operate with a "we over me" mentality, fostering strong, collaborative bonds built on Trust and Candor. You will also enjoy: fully stocked cupboards, weekly catered team lunches, and daily JJ Bean coffee runs to keep your energy high and your wallet happy.

Compensation Package

FISPAN believes in an atmosphere and culture when innovation can flourish, collaboration and teamwork are valued and transparency is at the core of it all. We want our employees to see how the ideas they help generate today have an impact on how we do business tomorrow. With that, the hiring salary range for this position is $130,000-$160,000 CAD annually; the base pay offered is based on comparable market data from companies of similar employee size, revenue and location. As part of our total rewards offering, permanent employees in this position may be eligible for our competitive semi-annual bonus program, subject to program eligibility requirements.

At FISPAN, we reward employees for achieving their objectives, going beyond the requirements of their job, demonstrating leadership, fostering innovation and advancing the organization as a whole. We value talented people of all backgrounds and characteristics that share our vision of being the number one platform for the business banking ecosystem.

Other components of our rewards offerings include support of career development, wellbeing, and personal growth.

  • Extended health and dental benefits
  • Paid time off
  • Savings and retirement plan matching
  • Parenthood top-up
  • Mentorship programs, and leadership series (to name a few)

Note: The incentive programs, benefits, and perks have certain eligibility requirements and may vary, only be partially or not at all available based on criteria such as location, employment status, etc. We’ll be happy to clarify eligibility for interviewing candidates.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
368,530 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
Vancouver
$23k – $57k per year (Estimated) • Remote • Full-Time • 6+ years exp
Python
Databases
OpenSearch
DevOps
AIOps
ArgoCD
AWS
Azure
CI/CD
Datadog
Docker
Dynatrace
GCP
GitHub Actions
Grafana
Incident Management
Jaeger
Jenkins
Kubernetes
New Relic
OpenTelemetry
Platform Engineering
Prometheus
SLI/SLO/SLA
Splunk
Terraform
GitHub
Apply
Cloud Engineer (AWS) 4 hours ago
In office • Full-Time • 5+ years exp • Bachelor's Degree • Dalian
Python
DevOps
AWS
CI/CD
CloudFormation
Docker
FinOps
GitHub Actions
Kubernetes
Terraform
GitHub
Apply
$37k – $80k per year (Estimated) • Remote/Hybrid • Full-Time • 7+ years exp • Pune
PowerShell
Python
AI/ML
Anomaly Detection
DevOps
AppDynamics
AWS
Azure
CI/CD
GCP
Grafana
Incident Management
Prometheus
Splunk
Apply
$19k – $47k per year (Estimated) • Remote • Full-Time • Perm
C#
C#
ASP.NET Core
Dapper
Entity Framework Core
Databases
Apache Kafka
ClickHouse
ElasticSearch
PostgreSQL
RabbitMQ
Redis
DevOps
CI/CD
Docker
Docker Compose
GitHub Actions
Kubernetes
TeamCity
GitHub
GitLab
Apply
$17k – $43k per year (Estimated) • In office • Full-Time • Tomsk
C#
Java
Python
DevOps
CI/CD
Docker
Git
Grafana
Graylog
Kubernetes
Prometheus
Splunk
Apply
$100k – $120k per year • In office • Full-Time • 7+ years exp • Vancouver
DevOps
Amazon EKS
AWS
Kubernetes
IAM
Cybersecurity
Threat Modeling
Apply
$135k – $170k per year • In office • Full-Time • 10+ years exp • Bachelor's Degree • Vancouver
Java
Java
Spring Framework
Databases
Apache Kafka
RabbitMQ
Apply
$44k – $58k per year • Remote/Hybrid • Full-Time • 2+ years exp • Associate's Degree • Vancouver
Bash
Python
SQL
Databases
MS SQL
MySQL
Oracle
PostgreSQL
DevOps
AWS
Azure
GCP
VMWare
Windows Server
Apply
$86k – $187k per year (Estimated) • In office • Full-Time • Bachelor's Degree • Vancouver
C#
JavaScript
Python
Java
Java
Spring Boot
Mobile
JUnit
DevOps
Azure
Azure DevOps
CI/CD
Git
GitHub Actions
GitLab CI
Jenkins
Rest API
QA
Rest-Assured
Selenium
TestNG
Apply
$79k – $97k per year • Remote • Full-Time • Vancouver
JavaScript
SQL
PHP
PHP
WordPress
Design
Figma
Webflow
Marketing
GA4
Hotjar
Apply
$142k – $208k per year • Equity • In office • Full-Time • 8+ years exp • Toronto • Montreal • Vancouver • Quebec
AI/ML
AI Agents
Apply
Product Designer 2 days ago
$67k – $191k per year (Estimated) • In office • 3+ years exp • Vancouver
Design
Figma
Apply
See all jobs
This is one of many
368,530 more open roles from verified company boards, updated every day.