Security Engineer

Questrade Financial Group

• $115K — $130K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in Computer Science, Software Engineering, Cybersecurity, or a related field
  • 2-4 years of hands-on experience in application security or security engineering
  • Practical knowledge of HTTP/TLS and service-to-service communication
  • Experience with programming languages like C#, C++, Rust, Java, or Go
  • Hands-on testing experience with manual web/API security
  • Proficiency in Python or Bash for developing automation and security tests
  • Knowledge of AI risks and experience with AI coding assistants

Responsibilities

  • Conduct secure code reviews to identify vulnerabilities
  • Collaborate with developers on threat modeling and secure design
  • Perform manual testing of applications and APIs to uncover weaknesses
  • Investigate vulnerabilities and collaborate on remediation efforts
  • Automate security checks and enhance CI/CD processes to improve security coverage
  • Educate developers on vulnerabilities and secure coding practices
  • Evaluate security of AI-integrated features and workflows

Benefits

  • Comprehensive benefits plan
  • Competitive incentive (bonus) program
  • Flexible hybrid work environment
Full Job Description
We're looking for our next Security Engineer. Could It Be You?

The Security Engineer is a hands-on application security engineer within the DevSecOps team. This role investigates how applications work, identifies vulnerabilities through source code review and manual testing, assesses design risks, and works with developers to implement and verify fixes. Success is measured by a demonstrable reduction in exploitable weaknesses across the software portfolio. The role requires practical development experience and the ability to investigate security issues independently, with scanners, SaaS platforms, and automation supporting the underlying engineering work.

Need more details? Keep reading...

In this role, responsibilities include but are not limited to:
  • Secure Code Review: Reviewing application source code and tracing untrusted input across APIs, services, and data stores. Identifying root causes of authorization, injection, cryptographic, and secrets management flaws, including issues that automated scanners miss.
  • Threat Modeling and Secure Design: Working with developers to map data flows, trust boundaries, and abuse cases for new features and integrations. Evaluating authentication, session management, authorization, and sensitive data handling, and translating risks into concrete design changes and testable security requirements.
  • Application Security Testing: Manually testing web applications and APIs for access control failures, cross-tenant data exposure, and business logic abuse. Using intercepting proxies, debuggers, and targeted test code to reproduce weaknesses in controlled environments and assessing their impact. Investigating relevant cloud, container, and IaC configurations when they contribute to an application attack path.
  • Vulnerability Investigation and Remediation: Investigating issues from manual reviews, testing, and scanners; establishing root cause, reachability, and exploitability. Producing reproducible evidence, contributing fixes with developers, and writing regression tests that demonstrate the vulnerable behavior is blocked without breaking intended functionality.
  • Security Automation and Supply Chain: Turning recurring vulnerability patterns into reusable tests, custom detection rules, and GitLab CI/CD checks. Using SAST, DAST, SCA, and secrets scanning to extend review coverage, and assess dependency exposure using SBOMs and code paths. Validating build and artifact integrity, tuning tools and merge request gates to support reliable engineering decisions.
  • Developer Collaboration: Explaining vulnerabilities using affected code, reproduction steps, and practical remediation options. Pairing with engineers on fixes, reviewing security-sensitive changes, and sharing secure coding patterns that prevent recurring defects.
  • AI Application Security: Assessing AI-integrated features and agentic workflows for prompt injection, sensitive data exposure, and unsafe tool permissions. Developing targeted abuse cases and validating authorization and isolation controls with application developers.


So are YOU our next Security Engineer? You are if you...
  • Hold a Bachelor's degree in Computer Science, Software Engineering, Cybersecurity, or a related technical field
  • Have 2-4 years of experience in application security or security engineering with substantial hands-on application security work, including independently investigating vulnerabilities and working with developers on remediation
  • Have practical knowledge of HTTP/TLS, authentication and session handling, authorization, databases, and service-to-service communication in enterprise applications
  • Have the ability to trace behavior using code, logs, and Linux/Windows tools, and assess how cloud IAM, networking, containers, and IaC affect application security
  • Have meaningful hands-on software development experience in one or more languages such as C#, C++, Rust, Java, or Go with the ability to build, run, debug, and modify an existing codebase; trace API and data flows; and submit fixes with regression tests through Git-based code review
  • Have practical understanding of injection, authorization, cryptographic, and business logic flaws, plus language-specific risks such as memory safety, where applicable
  • Have hands-on experience with manual web/API security testing, intercepting proxies, and debugging, plus the ability to validate SAST, DAST, SCA, and secrets scanner findings against actual application behavior
  • Have proficiency in Python or Bash to develop targeted security tests, reproduction scripts, and maintainable automation
  • Have experience threat modeling application features and translating abuse cases into design changes and security tests with practical understanding of dependency risk, package managers, SBOMs, as well as build and artifact integrity
  • Have working knowledge of AI and agentic security risks
  • Have experience using AI coding assistants (e.g., Copilot, Cursor, Claude) to accelerate security reviews, remediation work, and the development of scripts, test cases, and custom tooling
  • Have the ability to independently explain, debug, and test AI-generated code and remediation suggestions, verifying correctness and security against the actual codebase before adopting them
  • Have excellent communication skills with the ability to independently explain technical concepts to different teams


Additional kudos if you...
  • Have experience authoring reusable infrastructure and configuration automation with tools such as Terraform, Ansible, or CloudFormation
  • Have experience with security frameworks such as NIST CSF, NIST SSDF, ISO 27001, or SOC 2
  • Have relevant security certifications (CompTIA Security+, AWS Certified Security - Specialty, GCP Professional Cloud Security Engineer, or equivalents)
  • Have experience with incident response and security investigations


Compensation Information:
  • Base salary range: $115,000 - $130,000
  • The final compensation package will be commensurate with the successful candidate's experience, skills, and geographic location (Canada). It includes a comprehensive benefits plan and a competitive incentive (bonus) program for Full-Time Permanent roles.


Sounds like you? Click below to apply!

#LI-NP1

#LI-Hybrid

Similar Jobs

More Jobs at Questrade Financial Group

More Information Technology Jobs

Find similar Security Engineer jobs: