
Security Engineer
- DevSecOps
- Secrets Management
- Threat Modeling
- IaC
- GitLab CI/CD
- SAST
- DAST
- AI
- TLS
- Linux
- Windows
- IAM
- C#
- C++
- Rust
- Java
- Git
- Python
- Bash
- Copilot
- Cursor
- Claude
- Terraform
- Ansible
- CloudFormation
- NIST
- ISO 27001
- SOC2
- CompTIA Security+
- GCP
- Incident Response
What’s in it for you as an employee of QFG?
Health & wellbeing resources and programs
Paid vacation, personal, and sick days for work-life balance
Competitive compensation and benefits packages
Work-life balance in a hybrid environment with at least 3 days in office
Career growth and development opportunities
Opportunities to contribute to community causes
Work with diverse team members in an inclusive and collaborative environment
This job posting is for an existing vacancy.
We’re looking for our next Security Engineer. Could It Be You?
The Security Engineer is a hands-on application security engineer within the DevSecOps team. This role investigates how applications work, identifies vulnerabilities through source code review and manual testing, assesses design risks, and works with developers to implement and verify fixes. Success is measured by a demonstrable reduction in exploitable weaknesses across the software portfolio. The role requires practical development experience and the ability to investigate security issues independently, with scanners, SaaS platforms, and automation supporting the underlying engineering work.
Need more details? Keep reading…
In this role, responsibilities include but are not limited to:
Secure Code Review: Reviewing application source code and tracing untrusted input across APIs, services, and data stores. Identifying root causes of authorization, injection, cryptographic, and secrets management flaws, including issues that automated scanners miss.
Threat Modeling and Secure Design: Working with developers to map data flows, trust boundaries, and abuse cases for new features and integrations. Evaluating authentication, session management, authorization, and sensitive data handling, and translating risks into concrete design changes and testable security requirements.
Application Security Testing: Manually testing web applications and APIs for access control failures, cross-tenant data exposure, and business logic abuse. Using intercepting proxies, debuggers, and targeted test code to reproduce weaknesses in controlled environments and assessing their impact. Investigating relevant cloud, container, and IaC configurations when they contribute to an application attack path.
Vulnerability Investigation and Remediation: Investigating issues from manual reviews, testing, and scanners; establishing root cause, reachability, and exploitability. Producing reproducible evidence, contributing fixes with developers, and writing regression tests that demonstrate the vulnerable behavior is blocked without breaking intended functionality.
Security Automation and Supply Chain: Turning recurring vulnerability patterns into reusable tests, custom detection rules, and GitLab CI/CD checks. Using SAST, DAST, SCA, and secrets scanning to extend review coverage, and assess dependency exposure using SBOMs and code paths. Validating build and artifact integrity, tuning tools and merge request gates to support reliable engineering decisions.
Developer Collaboration: Explaining vulnerabilities using affected code, reproduction steps, and practical remediation options. Pairing with engineers on fixes, reviewing security-sensitive changes, and sharing secure coding patterns that prevent recurring defects.
AI Application Security: Assessing AI-integrated features and agentic workflows for prompt injection, sensitive data exposure, and unsafe tool permissions. Developing targeted abuse cases and validating authorization and isolation controls with application developers.
So are YOU our nextSecurity Engineer? You are if you…
Hold a Bachelor's degree in Computer Science, Software Engineering, Cybersecurity, or a related technical field
Have 2-4 years of experience in application security or security engineering with substantial hands-on application security work, including independently investigating vulnerabilities and working with developers on remediation
Have practical knowledge of HTTP/TLS, authentication and session handling, authorization, databases, and service-to-service communication in enterprise applications
Have the ability to trace behavior using code, logs, and Linux/Windows tools, and assess how cloud IAM, networking, containers, and IaC affect application security
Have meaningful hands-on software development experience in one or more languages such as C#, C++, Rust, Java, or Go with the ability to build, run, debug, and modify an existing codebase; trace API and data flows; and submit fixes with regression tests through Git-based code review
Have practical understanding of injection, authorization, cryptographic, and business logic flaws, plus language-specific risks such as memory safety, where applicable
Have hands-on experience with manual web/API security testing, intercepting proxies, and debugging, plus the ability to validate SAST, DAST, SCA, and secrets scanner findings against actual application behavior
Have proficiency in Python or Bash to develop targeted security tests, reproduction scripts, and maintainable automation
Have experience threat modeling application features and translating abuse cases into design changes and security tests with practical understanding of dependency risk, package managers, SBOMs, as well as build and artifact integrity
Have working knowledge of AI and agentic security risks
Have experience using AI coding assistants (e.g., Copilot, Cursor, Claude) to accelerate security reviews, remediation work, and the development of scripts, test cases, and custom tooling
Have the ability to independently explain, debug, and test AI-generated code and remediation suggestions, verifying correctness and security against the actual codebase before adopting them
Have excellent communication skills with the ability to independently explain technical concepts to different teams
Additional kudos if you…
Have experience authoring reusable infrastructure and configuration automation with tools such as Terraform, Ansible, or CloudFormation
Have experience with security frameworks such as NIST CSF, NIST SSDF, ISO 27001, or SOC 2
Have relevant security certifications (CompTIA Security+, AWS Certified Security – Specialty, GCP Professional Cloud Security Engineer, or equivalents)
Have experience with incident response and security investigations
Compensation Information:
Base salary range: $115,000 - $130,000
The final compensation package will be commensurate with the successful candidate's experience, skills, and geographic location (Canada). It includes a comprehensive benefits plan and a competitive incentive (bonus) program for Full-Time Permanent roles.
Sounds like you? Click below to apply!
#LI-NP1
#LI-Hybrid
Security Engineer · Questrade Financial Group