Software Engineer Security Remediation (Level II)/DeVSecOPS
Offre en anglaisRemediate a backlog of software security findings including dependency upgrades, SAST/SCA fixes, and container image updates. Verify resolutions and escalate product-specific logic issues to the in-house engineering team.
- Hybride
- Québec, QC
- Publié 24 août 2026
- Postuler avant le 23 sept. 2026
- 1 poste
D’autres postes auxquels postuler directement
Des possibilités semblables publiées par des employeurs qui recrutent sur Jobs.ca, sans formulaire externe.
Forgeahead Solutions Corporation
Technical Lead and Senior Software Engineer
- Sur place
City of Toronto
Senior Project Manager CS
- Hybride
Desjardins
Analyste d'affaires système(BSA) Guidewire
- Hybride
Résumé du poste
Job Title: Software Engineer II Duration: 4+ months Location: Quebec City, QC, (Hybrid - 3 days onsite - Monday Tuesday and Thursday) Job Specification: Software Engineer Security Remediation (Level II) Overview : At Zebra, we are a community of innovators who come together to create new ways of working. United by curiosity and a culture of caring, we develop smart solutions that anticipate our customer's and partner's needs and solve their challenges. Being part of Zebra Nation means you are seen, heard, valued, and respected. Drawing from our unique perspectives, we collaborate to deliver on our purpose. Here you are part of a team pushing boundaries today to redefine the work of tomorrow for organizations, their employees, and those they serve. You'll have opportunities to learn and lead in a forward-thinking environment, defining your path to a fulfilling career while channeling your skills toward causes you care about—locally and globally. Come make an impact every day at Zebra. What We're Looking For: The Machine Vision team is engaging a contract Software Engineer to remediate a backlog of software security findings across the product portfolio over an approximately 4 month period. This is hands-on remediation work: fixing vulnerabilities directly in code and through security tooling, verifying resolution, and clearing findings efficiently while maintaining the engineering quality bar for a safety-relevant product line. The ideal candidate is a strong software engineer with real software-security judgment who fixes issues correctly and knows when a finding needs product-specific knowledge to escalate. Responsibilities • Remediate software security findings across the backlog: dependency upgrades, static-analysis (SAST) fixes, software-composition (SCA) issues, secrets removal/rotation, and container base-image updates. • Fix vulnerabilities directly in code and drive fixes through security tooling; verify each finding is genuinely resolved rather than suppressed. • Distinguish real findings from false positives; close out non-issues with documented justification and flag tool-accuracy problems. • Prioritize work by exploitability and impact, not severity label alone. • Escalate any finding that requires product-specific knowledge — safety-critical, real-time, or proprietary vision/robotics/firmware logic — to the in-house engineering team rather than modifying that code independently. • Meet the same CI/CD security gates, code-signing, and supply-chain controls as staff engineers so remediation does not create rework. • Track and report remediation progress against the backlog. Minimum Qualifications • Strong software engineer able to read and work in unfamiliar codebases confidently. • 4+ years of experience • Working knowledge of common software vulnerability classes and their real-world impact. • Hands-on experience with SAST/SCA/secrets-scanning tooling and dependency management, including remediating and verifying fixes. • Proficiency in one or more of C, C++, C#, Python JavasScript, TypeScript • Judgment to separate exploitable findings from noise and to escalate what requires product context. • Familiarity with Git-based workflows and CI/CD pipelines. • Bachelor's degree in computer science or equivalent with practical experience. Preferred Qualifications • Prior security-remediation or application-security (AppSec) engagement experience. • Experience with machine-vision, imaging, embedded, or robotics software. • Exposure to code signing, SBOMs, or hardened container images.
Ce que vous ferez
Remediate a backlog of software security findings including dependency upgrades, SAST/SCA fixes, and container image updates. Verify resolutions and escalate product-specific logic issues to the in-house engineering team.
Exigences
Requires 4+ years of software engineering experience with proficiency in languages like C++, C#, or Python and knowledge of vulnerability classes. A Bachelor's degree in computer science or equivalent practical experience is required.
Compétences indiquées
- JavaScriptSouhaitée
- TypeScriptSouhaitée
- C++Souhaitée
- GitSouhaitée
- PythonSouhaitée
Autres compétences pertinentes
Relevées dans la description du poste. Confirmez les exigences importantes ci-dessus.
- Security Remediation
- SAST
- SCA
- Dependency Management
- C
- C++
- C#
- Python
- JavaScript
- TypeScript
- Git
- CI/CD Pipelines
- Vulnerability Management
- Container Security
- Application Security
- Software Engineering
Domaines d’emploi
- Software
- Security & Safety
- Technology
- Engineering
- Consulting
Renseignements supplémentaires
- Formation minimale
- Baccalauréat
- Expérience minimale
- 4+ ans
- Postuler avant le
- 23 sept. 2026
- Langue de l’offre
- anglais
- Heures de travail
- 40 heures par semaine
- Présence au bureau
- 3 jours par semaine
- Niveau d’expérience
- Mid-Senior level
- Mode de candidature
- La candidature directe est offerte