QXO logo

Lead Application Security Engineer, Code to Cloud

QXO

On-siteVancouver, WAlead$172kPosted 9h ago

Job description

As a Lead Application Security Engineer, Code to Cloud at QXO, you’ll be the recognized subject matter expert for application security across the company and own the engineering behind Code to Cloud: continuous security coverage across QXO’s software delivery lifecycle, from source code through pipeline execution to cloud runtime.

QXO is building a modern cybersecurity function from the ground up, automation-first. This is a large, enterprise-wide program spanning three engineering organizations, and you will run your part of it with limited oversight, defining the standards QXO builds against rather than applying someone else’s. Attackers operate at machine speed, and human-speed review cannot meet that, so we automate first.

QXO is a leading distributor and installer of building products serving an $800 billion market. The company’s mission is to modernize the building products industry through advanced technology and a best-in-class customer experience. QXO is North America’s largest distributor and installer of insulation, the second-largest distributor of roofing products, the second-largest publicly traded distributor of lumber and building materials, and the largest distributor of waterproofing products. The company is targeting $50 billion in annual revenue within the decade through accretive acquisitions and organic growth. For more information, visit QXO.com.

What You'll Do

  • Own the scanning and posture platform end to end across secrets, SAST, SCA, infrastructure-as-code, container images, and cloud runtime, at a false-positive rate engineers trust. Build the automation that routes, deduplicates, and prioritizes findings, with owner resolution, SLA tracking, and closure verification.

  • Build and run policy-based blocking controls in pull requests and CI/CD pipelines, as policy-as-code applied centrally and scoped to repository tiering, so coverage inherits to future repositories. Turn a gate on only when the baseline is triaged and false positives are under bar, and never block a team without a path forward.

  • Author the application security standards, secure design patterns, and remediation SLAs QXO builds against, own the exception and risk-acceptance workflow, and report on risk reduced rather than finding counts. Make threat modeling repeatable through templates and AI-assisted triage, producing testable requirements.

  • Sit in architecture and design reviews with principal engineers and reach a decision in the room: where a gateway-validated token stops being sufficient and service identity needs its own mechanism, how object-level authorization survives a list endpoint, and why a service must never take an authorization attribute from its caller. Review third-party integrations before production.

  • Set the technical bar for the practice: coach, review, and direct the security work of the champions network and third-party testing partners, and mentor engineers added to the team. Be the person engineering calls, explaining what a finding means and what it does not, so a blocked developer gets an answer the same day.

  • Own security testing of the running application, not just its source, and work with developers to remediate what it finds, verifying on retest. Lead the response when a critical vulnerability or exploit drops.

  • Lead the security integration of acquired engineering environments, bringing their repositories, pipelines, and cloud accounts under coverage without stalling delivery.

What You'll Bring

  • 8+ years in application security, product security, DevSecOps, or security engineering, most of it hands-on rather than advisory.

  • Hands-on experience owning an enterprise-scale security program across multiple teams and stakeholder groups with limited oversight, including setting standards others follow and reviewing the work of other engineers.

  • Depth in a cloud-native application protection or application security posture platform such as Wiz, Snyk, Prisma Cloud, or Orca. You have written policy and built on its API, not just read dashboards.

  • Pipeline enforcement you have actually shipped: policy-based blocking in pull requests and CI/CD, security policy-as-code, and the harder part, moving a control from advisory to blocking without an engineering revolt.

  • Threat modeling you have run, not just studied. STRIDE or an equivalent applied to real systems, extended with MITRE ATLAS and the LLM risk taxonomies where classical categories fall short on AI-enabled systems.

  • Architecture-level security judgment. You can hold your own with a principal engineer on authorization design in a distributed system: trust boundaries, token validation, service-to-service identity, and object-level access control.

  • Approachable, responsive, and constructive under pressure. You can tell a team their launch has a problem without becoming the reason they route around security.

  • An automation-first, AI-forward way of working, and a defensible view on securing AI itself: validating AI-generated code, and agentic risk including prompt injection, tool permissions, and the MCP supply chain.

  • Dynamic testing of running applications and APIs through DAST tooling, API security testing, or hands-on offensive work, and cloud security depth in a major public cloud, Google Cloud a plus.

  • Coding ability in Python, Go, or TypeScript, and writing that is tight, evidence-backed, and defensible when challenged.

Education & Certifications

  • Bachelor’s in computer science, information assurance, MIS, or equivalent practical experience; advanced degree preferred. Google Cloud certifications preferred, particularly Professional Cloud Security Engineer, DevOps Engineer, or Architect. CSSLP, GWAPT, OSWE, or OSCP a plus.

What you'll earn

  • Base pay range: $101,300 - $172,000

  • Annual performance bonus

  • 401(k) with employer match

  • Medical, dental, and vision insurance

  • PTO, company holidays, and parental leave

  • Paid Time Off/Paid Sick Leave: Applicants can expect to accrue 15 days of paid time off during their first year (4.62 hours for every 80 hours worked) and increased accruals after five years of service.

  • Paid training and certifications

  • Legal assistance and identity protection

  • Pet insurance

  • Employee assistance program (EAP)

To comply with Pay Transparency laws, employers must disclose an annual salary range. Actual offers depend on factors such as location, experience, skills, and market data. This position may also offer variable compensation.

Please contact careers@QXO.com if you have any questions related to this job posting.

QXO is an Equal Opportunity Employer.

We value diversity and do not discriminate on the basis of race, color, religion, gender or sexual orientation, national origin, age, disability, or any other protected status. Salary Range

USD $101,300.00 - USD $172,000.00 /Yr.