Back to job search
RS

Software Engineer

Remediate a backlog of software security findings by fixing vulnerabilities in code and utilizing security tooling. Track progress and escalate complex, product-specific safety-critical issues to the in-house engineering team.

  • Hybrid
  • Québec, QC
  • Posted Aug 24, 2026
  • Apply by Sep 23, 2026
  • 1 position

More jobs you can apply to directly

Similar opportunities posted by employers hiring on Jobs.ca, with no external application form.

Job summary

Job Title: Software Engineer II Duration: 4+ months (2026-08-31 to 2026-12-31, Total Hours: 667.50) Location: Quebec City, QC, CAN G1A 1C5(Hybrid - 3 days onsite - Monday Tuesday and Thursday) Job Specification: Software Engineer Security Remediation (Level II) What We're Looking For: The Machine Vision team is engaging a contract Software Engineer to remediate a backlog of software security findings across the product portfolio over an approximately 4 month period. This is hands-on remediation work: fixing vulnerabilities directly in code and through security tooling, verifying resolution, and clearing findings efficiently while maintaining the engineering quality bar for a safety-relevant product line. The ideal candidate is a strong software engineer with real software-security judgment who fixes issues correctly and knows when a finding needs product-specific knowledge to escalate. Responsibilities • Remediate software security findings across the backlog: dependency upgrades, static-analysis (SAST) fixes, software-composition (SCA) issues, secrets removal/rotation, and container base-image updates. • Fix vulnerabilities directly in code and drive fixes through security tooling; verify each finding is genuinely resolved rather than suppressed. • Distinguish real findings from false positives; close out non-issues with documented justification and flag tool-accuracy problems. • Prioritize work by exploitability and impact, not severity label alone. • Escalate any finding that requires product-specific knowledge — safety-critical, real-time, or proprietary vision/robotics/firmware logic — to the in-house engineering team rather than modifying that code independently. • Meet the same CI/CD security gates, code-signing, and supply-chain controls as staff engineers so remediation does not create rework. • Track and report remediation progress against the backlog. Minimum Qualifications • Strong software engineer able to read and work in unfamiliar codebases confidently. • 4+ years of experience • Working knowledge of common software vulnerability classes and their real-world impact. • Hands-on experience with SAST/SCA/secrets-scanning tooling and dependency management, including remediating and verifying fixes. • Proficiency in one or more of C, C++, C#, Python JavasScript, TypeScript • Judgment to separate exploitable findings from noise and to escalate what requires product context. • Familiarity with Git-based workflows and CI/CD pipelines. • Bachelor's degree in computer science or equivalent with practical experience. Preferred Qualifications • Prior security-remediation or application-security (AppSec) engagement experience. • Experience with machine-vision, imaging, embedded, or robotics software. • Exposure to code signing, SBOMs, or hardened container images.

What you’ll do

Remediate a backlog of software security findings by fixing vulnerabilities in code and utilizing security tooling. Track progress and escalate complex, product-specific safety-critical issues to the in-house engineering team.

Requirements

Requires a Bachelor's degree in Computer Science and over 4 years of software engineering experience. Candidates must be proficient in languages like C++, Python, or C# and have hands-on experience with SAST/SCA tools.

Listed skills

  • JavaScriptPreferred
  • TypeScriptPreferred
  • C++Preferred
  • GitPreferred
  • PythonPreferred

Other relevant skills

Identified from the job description. Confirm important requirements above.

  • Software Security Remediation
  • SAST
  • SCA
  • Dependency Management
  • C
  • C++
  • C#
  • Python
  • JavaScript
  • TypeScript
  • Git
  • CI/CD Pipelines
  • Vulnerability Management
  • Secrets Scanning
  • Container Security
  • Machine Vision

Job areas

  • Software
  • Security & Safety
  • Engineering
  • Technology
  • Consulting

Additional details

Minimum education
Bachelor’s degree
Minimum experience
4+ years
Apply by
Sep 23, 2026
Posting language
English
Working hours
40 hours per week
Office presence
3 days per week
Seniority
Associate
Application method
Direct apply is available