Security Engineer
Questrade Financial GroupQuestrade Financial Group (QFG), through its companies - Questrade, Questbank, Questrade Wealth Management, Community Trust Company, Zolo, and Flexiti, provides securities and foreign currency investment, professionally managed investment portfolios, mortgages, real estate services, financial services and more. We use cutting-edge technology to help Canadians become much more financially successful and secure. At QFG, we combine human-centric collaboration with AI-driven innovation to redefine financial services. The ideal candidate will be a catalyst for change, using AI to transform and deliver unparalleled customer experiences and shaping a future where AI empowers our teams to do their best work. Join our diverse, inclusive, and hybrid workplace to unleash your creativity and nurture your curiosity without limits. If you share this sense of infinite possibility, come shape your future at QFG. What’s in it for you as an employee of QFG? Health & wellbeing resources and programs Paid vacation, personal, and sick days for work-life balance Competitive compensation and benefits packages Work-life balance in a hybrid environment with at least 3 days in office Career growth and development opportunities Opportunities to contribute to community causes Work with diverse team members in an inclusive and collaborative environment This job posting is for an existing vacancy. We’re looking for our next Security Engineer. Could It Be You? The Security Engineer is a hands-on application security engineer within the DevSecOps team. This role investigates how applications work, identifies vulnerabilities through source code review and manual testing, assesses design risks, and works with developers to implement and verify fixes. Success is measured by a demonstrable reduction in exploitable weaknesses across the software portfolio. The role requires practical development experience and the ability to investigate security issues independently, with scanners, SaaS platforms, and automation supporting the underlying engineering work. Need more details? Keep reading… In this role, responsibilities include but are not limited to: Secure Code Review: Reviewing application source code and tracing untrusted input across APIs, services, and data stores. Identifying root causes of authorization, injection, cryptographic, and secrets management flaws, including issues that automated scanners miss. Threat Modeling and Secure Design: Working with developers to map data flows, trust boundaries, and abuse cases for new features and integrations. Evaluating authentication, session management, authorization, and sensitive data handling, and translating risks into concrete design changes and testable security requirements. Application Security Testing: Manually testing web applications and APIs for access control failures, cross-tenant data exposure, and business logic abuse. Using intercepting proxies, debuggers, and targeted test code to reproduce weaknesses in controlled environments and assessing their impact. Investigating relevant cloud, container, and IaC configurations when they contribute to an application attack path. Vulnerability Investigation and Remediation: Investigating issues from manual reviews, testing, and scanners; establishing root cause, reachability, and exploitability. Producing reproducible evidence, contributing fixes with developers, and writing regression tests that demonstrate the vulnerable behavior is blocked without breaking intended functionality. Security Automation and Supply Chain: Turning recurring vulnerability patterns into reusable tests, custom detection rules, and GitLab CI/CD checks. Using SAST, DAST, SCA, and secrets scanning to extend review coverage, and assess dependency exposure using SBOMs and code paths. Validating build and artifact integrity, tuning tools and merge request gates to support reliable engineering decisions. Developer Collaboration: Explaining vulnerabilities using affected code, reproductio…