Questrade Financial Group

Security Engineer

Toronto, Ontario · Posted today

Opens jobs.dayforcehcm.com

Get a version of your resume written for this job.

Salary
Not listed
Job type
Not specified
Work mode
Not specified
Source
Dayforce (employer's hiring system)

Skills mentioned

Threat Modeling, Python, Java, Rust, C++, C#, Bash, AWS

About the role

What’s in it for you as an employee of QFG?

Health & wellbeing resources and programs

Paid vacation, personal, and sick days for work-life balance

Competitive compensation and benefits packages

Work-life balance in a hybrid environment with at least 3 days in office

Career growth and development opportunities

Opportunities to contribute to community causes

Work with diverse team members in an inclusive and collaborative environment

This job posting is for an existing vacancy.

We’re looking for our next Security Engineer. Could It Be You?

The Security Engineer is a hands-on application security engineer within the DevSecOps team. This role investigates how applications work, identifies vulnerabilities through source code review and manual testing, assesses design risks, and works with developers to implement and verify fixes. Success is measured by a demonstrable reduction in exploitable weaknesses across the software portfolio. The role requires practical development experience and the ability to investigate security issues independently, with scanners, SaaS platforms, and automation supporting the underlying engineering work.

Need more details? Keep reading…

In this role, responsibilities include but are not limited to:

Secure Code Review: Reviewing application source code and tracing untrusted input across APIs, services, and data stores. Identifying root causes of authorization, injection, cryptographic, and secrets management flaws, including issues that automated scanners miss.

Threat Modeling and Secure Design: Working with developers to map data flows, trust boundaries, and abuse cases for new features and integrations. Evaluating authentication, session management, authorization, and sensitive data handling, and translating risks into concrete design changes and testable security requirements.

Application Security Testing: Manually testing web applications and APIs for access control failures, cross-tenant data exposure, and business logic abuse. Using intercepting proxies, debuggers, and targeted test code to reproduce weaknesses in controlled environments and assessing their impact. Investigating relevant cloud, container, and IaC configurations when they contribute to an application attack path.

Vulnerability Investigation and Remediation: Investigating issues from manual reviews, testing, and scanners; establishing root cause, reachability, and exploitability. Producing reproducible evidence, contributing fixes with developers, and writing regression tests that demonstrate the vulnerable behavior is blocked without breaking intended functionality.

Security Automation and Supply Chain: Turning recurring vulnerability patterns into reusable tests, custom detection rules, and GitLab CI/CD checks. Using SAST, DAST, SCA, and secrets scanning to extend review coverage, and assess dependency exposure using SBOMs and code paths. Validating build and artifact integrity, tuning tools and merge request gates to support reliable engineering decisions.

Developer Collaboration: Explaining vulnerabilities using affected code, reproduction steps, and practical remediation options. Pairing with engineers on fixes, reviewing security-sensitive changes, and sharing secure coding patterns that prevent recurring defects.

AI Application Security: Assessing AI-integrated features and agentic workflows for prompt injection, sensitive data exposure, and unsafe tool permissions. Developing targeted abuse cases and validating authorization and isolation controls with application developers.

So are YOU our next Security Engineer? You are if you…

Hold a Bachelor's degree in Computer Science, Software Engineering, Cybersecurity, or a related technical field

Have 2-4 years of experience in application security or security engineering with substantial hands-on application security work, including independently investigating vulnerabilities and working with developers on remediation

Have practical knowledge of HTTP/TLS, authentication and session handling, authorization, databases, and service-to-service communication in enterprise applications

Have the ability to trace behavior using code, logs, and Linux/Windows tools, and assess how cloud IAM, networking, containers, and IaC affect application security

Have meaningful hands-on software development experience in one or more languages such as C#, C++, Rust, Java, or Go with the ability to build, run, debug, and modify an existing codebase; trace API and data flows; and submit fixes with regression tests through Git-based code review

Have practical understanding of injection, authorization, cryptographic, and business logic flaws, plus language-specific risks such as memory safety, where applicable

Have hands-on experience with manual web/API security testing, intercepting proxies, and debugging, plus the ability to validate SAST, DAST, SCA, and secrets scanner findings against actual application behavior

Have proficiency in Python or Bash to develop targeted security tests, reproduction scripts, and maintainable automation

Have experience threat modeling application features and translating abuse cases into design changes and security tests with practical understanding of dependency risk, package managers, SBOMs, as well as build and artifact integrity

Have working knowledge of AI and agentic security risks

Have experience using AI coding assistants (e.g., Copilot, Cursor, Claude) to accelerate security reviews, remediation work, and the development of scripts, test cases, and custom tooling

Have the ability to independently explain, debug, and test AI-generated code and remediation suggestions, verifying correctness and security against the actual codebase before adopting them

Have excellent communication skills with the ability to independently explain technical concepts to different teams

Additional kudos if you…

Have experience authoring reusable infrastructure and configuration automation with tools such as Terraform, Ansible, or CloudFormation

Have experience with security frameworks such as NIST CSF, NIST SSDF, ISO 27001, or SOC 2

Have relevant security certifications (CompTIA Security+, AWS Certified Security – Specialty, GCP Professional Cloud Security Engineer, or equivalents)

Have experience with incident response and security investigations

Compensation Information:

Base salary range: $115,000 - $130,000

The final compensation package will be commensurate with the successful candidate's experience, skills, and geographic location (Canada). It includes a comprehensive benefits plan and a competitive incentive (bonus) program for Full-Time Permanent roles.

Sounds like you? Click below to apply!

#LI-NP1

#LI-Hybrid

Job ID df-qfg-candidateportal-17985 · Original posting ↗