Questrade Financial Group (QFG), through its companies - Questrade, Questbank, Questrade Wealth Management, Community Trust Company, Zolo, and Flexiti, provides securities and foreign currency investment, professionally managed investment portfolios, mortgages, real estate services, financial services and more. We use cutting-edge technology to help Canadians become much more financially successful and secure.
At QFG, we combine human-centric collaboration with AI-driven innovation to redefine financial services. The ideal candidate will be a catalyst for change, using AI to transform and deliver unparalleled customer experiences and shaping a future where AI empowers our teams to do their best work.
Join our diverse, inclusive, and hybrid workplace to unleash your creativity and nurture your curiosity without limits. If you share this sense of infinite possibility, come shape your future at QFG.
What’s in it for you as an employee of QFG?
-
Health & wellbeing resources and programs
-
Paid vacation, personal, and sick days for work-life balance
-
Competitive compensation and benefits packages
-
Work-life balance in a hybrid environment with at least 3 days in office
-
Career growth and development opportunities
-
Opportunities to contribute to community causes
-
Work with diverse team members in an inclusive and collaborative environment
This job posting is for an existing vacancy.
We’re looking for our next Security Engineer. Could It Be You?
The Security Engineer is a hands-on application security engineer within the DevSecOps team. This role investigates how applications work, identifies vulnerabilities through source code review and manual testing, assesses design risks, and works with developers to implement and verify fixes. Success is measured by a demonstrable reduction in exploitable weaknesses across the software portfolio. The role requires practical development experience and the ability to investigate security issues independently, with scanners, SaaS platforms, and automation supporting the underlying engineering work.
Need more details? Keep reading…
In this role, responsibilities include but are not limited to:
-
Secure Code Review: Reviewing application source code and tracing untrusted input across APIs, services, and data stores. Identifying root causes of authorization, injection, cryptographic, and secrets management flaws, including issues that automated scanners miss.
-
Threat Modeling and Secure Design: Working with developers to map data flows, trust boundaries, and abuse cases for new features and integrations. Evaluating authentication, session management, authorization, and sensitive data handling, and translating risks into concrete design changes and testable security requirements.
-
Application Security Testing: Manually testing web applications and APIs for access control failures, cross-tenant data exposure, and business logic abuse. Using intercepting proxies, debuggers, and targeted test code to reproduce weaknesses in controlled environments and assessing their impact. Investigating relevant cloud, container, and IaC configurations when they contribute to an application attack path.
-
Vulnerability Investigation and Remediation: Investigating issues from manual reviews, testing, and scanners; establishing root cause, reachability, and exploitability. Producing reproducible evidence, contributing fixes with developers, and writing regression tests that demonstrate the vulnerable behavior is blocked without breaking intended functionality.
-
Security Automation and Supply Chain: Turning recurring vulnerability patterns into reusable tests, custom detection rules, and GitLab CI/CD checks. Using SAST, DAST, SCA, and secrets scanning to extend review coverage, and assess dependency exposure using SBOMs and code paths. Validating build and artifact integrity, tuning tools and merge request gates to support reliable engineering decisions.
-
Developer Collaboration: Explaining vulnerabilities using affected code, reproduction steps, and practical remediation options. Pairing with engineers on fixes, reviewing security-sensitive changes, and sharing secure coding patterns that prevent recurring defects.
-
AI Application Security: Assessing AI-integrated features and agentic workflows for prompt injection, sensitive data exposure, and unsafe tool permissions. Developing targeted abuse cases and validating authorization and isolation controls with application developers.
So are YOU our next Security Engineer? You are if you…
-
Hold a Bachelor's degree in Computer Science, Software Engineering, Cybersecurity, or a related technical field
-
Have 2-4 years of experience in application security or security engineering with substantial hands-on application security work, including independently investigating vulnerabilities and working with developers on remediation
-
Have practical knowledge of HTTP/TLS, authentication and session handling, authorization, databases, and service-to-service communication in enterprise applications
-
Have the ability to trace behavior using code, logs, and Linux/Windows tools, and assess how cloud IAM, networking, containers, and IaC affect application security
-
Have meaningful hands-on software development experience in one or more languages such as C#, C++, Rust, Java, or Go with the ability to build, run, debug, and modify an existing codebase; trace API and data flows; and submit fixes with regression tests through Git-based code review
-
Have practical understanding of injection, authorization, cryptographic, and business logic flaws, plus language-specific risks such as memory safety, where applicable
-
Have hands-on experience with manual web/API security testing, intercepting proxies, and debugging, plus the ability to validate SAST, DAST, SCA, and secrets scanner findings against actual application behavior
-
Have proficiency in Python or Bash to develop targeted security tests, reproduction scripts, and maintainable automation
-
Have experience threat modeling application features and translating abuse cases into design changes and security tests with practical understanding of dependency risk, package managers, SBOMs, as well as build and artifact integrity
-
Have working knowledge of AI and agentic security risks
-
Have experience using AI coding assistants (e.g., Copilot, Cursor, Claude) to accelerate security reviews, remediation work, and the development of scripts, test cases, and custom tooling
-
Have the ability to independently explain, debug, and test AI-generated code and remediation suggestions, verifying correctness and security against the actual codebase before adopting them
-
Have excellent communication skills with the ability to independently explain technical concepts to different teams
Additional kudos if you…
-
Have experience authoring reusable infrastructure and configuration automation with tools such as Terraform, Ansible, or CloudFormation
-
Have experience with security frameworks such as NIST CSF, NIST SSDF, ISO 27001, or SOC 2
-
Have relevant security certifications (CompTIA Security+, AWS Certified Security – Specialty, GCP Professional Cloud Security Engineer, or equivalents)
-
Have experience with incident response and security investigations
Compensation Information:
-
Base salary range: $115,000 - $130,000
-
The final compensation package will be commensurate with the successful candidate's experience, skills, and geographic location (Canada). It includes a comprehensive benefits plan and a competitive incentive (bonus) program for Full-Time Permanent roles.
Sounds like you? Click below to apply!
At Questrade Financial Group of Companies, with multiple office locations around the world, we are committed to fostering a diverse, inclusive and accessible work environment. This is an environment where individuals are treated with dignity and respect. Here, the unique skills and experience you bring will be valued. You will be supported and motivated, so that you can harness your unlimited potential. Our team reflects the diversity of the communities we serve and operate in. Having a collaborative and diverse team helps us push boundaries to bring the future of fintech into existence - not only for the benefit of our customers, but for those who build their career with us.
Questrade Financial Group of companies Applicant Tracking System utilizes artificial intelligence (AI) for application screening. The AI system operates on predetermined criteria, with final decisions subject to human review.
Candidates selected for an interview will be contacted directly. If you require accommodation during the recruitment/selection process, please let us know and we will work with you to meet your needs.