Skip to content

Open nowPosted 2 days ago

Security Engineer

qfg70 open roles

Where
North American Centre, 5700 Yonge St, North York, ON M2N 5M9, Canada
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowSecurity Engineerqfg · North American Centre, 5700 Yonge St, North York, ON M2N 5M9, Canada
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on qfg's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.8% of postings close within 7 days. Measured by our own scanner across the market.

Share of postings closed within
  1. 1.6%1 day
  2. 3.4%3 days
  3. 7.8%7 days
  4. 14.3%14 days
  5. 33.7%30 days
This job: posted 2 days ago

The posting

What’s in it for you as an employee of QFG?

Health & wellbeing resources and programs 

Paid vacation, personal, and sick days for work-life balance

Competitive compensation and benefits packages

Work-life balance in a hybrid environment with at least 3 days in office

Career growth and development opportunities

Opportunities to contribute to community causes

Work with diverse team members in an inclusive and collaborative environment

  This job posting is for an existing vacancy.   We’re looking for our next Security Engineer. Could It Be You? The Security Engineer is a hands-on application security engineer within the DevSecOps team. This role investigates how applications work, identifies vulnerabilities through source code review and manual testing, assesses design risks, and works with developers to implement and verify fixes. Success is measured by a demonstrable reduction in exploitable weaknesses across the software portfolio. The role requires practical development experience and the ability to investigate security issues independently, with scanners, SaaS platforms, and automation supporting the underlying engineering work.   Need more details? Keep reading… In this role, responsibilities include but are not limited to: 

Secure Code Review: Reviewing application source code and tracing untrusted input across APIs, services, and data stores. Identifying root causes of authorization, injection, cryptographic, and secrets management flaws, including issues that automated scanners miss.

Threat Modeling and Secure Design: Working with developers to map data flows, trust boundaries, and abuse cases for new features and integrations. Evaluating authentication, session management, authorization, and sensitive data handling, and translating risks into concrete design changes and testable security requirements.

Application Security Testing: Manually testing web applications and APIs for access control failures, cross-tenant data exposure, and business logic abuse. Using intercepting proxies, debuggers, and targeted test code to reproduce weaknesses in controlled environments and assessing their impact. Investigating relevant cloud, container, and IaC configurations when they contribute to an application attack path.

Vulnerability Investigation and Remediation: Investigating issues from manual reviews, testing, and scanners; establishing root cause, reachability, and exploitability. Producing reproducible evidence, contributing fixes with developers, and writing regression tests that demonstrate the vulnerable behavior is blocked without breaking intended functionality.

Security Automation and Supply Chain: Turning recurring vulnerability patterns into reusable tests, custom detection rules, and GitLab CI/CD checks. Using SAST, DAST, SCA, and secrets scanning to extend review coverage, and assess dependency exposure using SBOMs and code paths. Validating build and artifact integrity, tuning tools and merge request gates to support reliable engineering decisions.

Developer Collaboration: Explaining vulnerabilities using affected code, reproduction steps, and practical remediation options. Pairing with engineers on fixes, reviewing security-sensitive changes, and sharing secure coding patterns that prevent recurring defects.

AI Application Security: Assessing AI-integrated features and agentic workflows for prompt injection, sensitive data exposure, and unsafe tool permissions. Developing targeted abuse cases and validating authorization and isolation controls with application developers.

  So are YOU our next Security Engineer? You are if you…

Hold a Bachelor's degree in Computer Science, Software Engineering, Cybersecurity, or a related technical field

Have 2-4 years of experience in application security or security engineering with substantial hands-on application security work, including independently investigating vulnerabilities and working with developers on remediation

Have practical knowledge of HTTP/TLS, authentication and session handling, authorization, databases, and service-to-service communication in enterprise applications

Have the ability to trace behavior using code, logs, and Linux/Windows tools, and assess how cloud IAM, networking, containers, and IaC affect application security

Have meaningful hands-on software development experience in one or more languages such as C#, C++, Rust, Java, or Go with the ability to build, run, debug, and modify an existing codebase; trace API and data flows; and submit fixes with regression tests through Git-based code review

Have practical understanding of injection, authorization, cryptographic, and business logic flaws, plus language-specific risks such as memory safety, where applicable

Have hands-on experience with manual web/API security testing, intercepting proxies, and debugging, plus the ability to validate SAST, DAST, SCA, and secrets scanner findings against actual application behavior

Have proficiency in Python or Bash to develop targeted security tests, reproduction scripts, and maintainable automation

Have experience threat modeling application features and translating abuse cases into design changes and security tests with practical understanding of dependency risk, package managers, SBOMs, as well as build and artifact integrity

Have working knowledge of AI and agentic security risks

Have experience using AI coding assistants (e.g., Copilot, Cursor, Claude) to accelerate security reviews, remediation work, and the development of scripts, test cases, and custom tooling

Have the ability to independently explain, debug, and test AI-generated code and remediation suggestions, verifying correctness and security against the actual codebase before adopting them

Have excellent communication skills with the ability to independently explain technical concepts to different teams

  Additional kudos if you…

Have experience authoring reusable infrastructure and configuration automation with tools such as Terraform, Ansible, or CloudFormation

Have experience with security frameworks such as NIST CSF, NIST SSDF, ISO 27001, or SOC 2

Have relevant security certifications (CompTIA Security+, AWS Certified Security – Specialty, GCP Professional Cloud Security Engineer, or equivalents)

Have experience with incident response and security investigations

  Compensation Information:

Base salary range: $115,000 - $130,000

The final compensation package will be commensurate with the successful candidate's experience, skills, and geographic location (Canada). It includes a comprehensive benefits plan and a competitive incentive (bonus) program for Full-Time Permanent roles.

  Sounds like you? Click below to apply! #LI-NP1 #LI-Hybrid

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against qfg's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on qfg's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    qfg's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.