Thales Group

Cybersecurity Vulnerability Engineer

Thales Group$123K — $172K *
US-AnywhereRemote in Ottawa, ON
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor’s degree in computer information systems, engineering, or related field and 5+ years of cybersecurity experience.
  • 3–4 years in vulnerability management, analysis, or incident response.
  • Strong understanding of vulnerability exploitation, attack paths, and common security controls.
  • Ability to interpret vendor advisories and technical security research.
  • Familiarity with Windows, Linux, cloud technologies, and enterprise applications.

Responsibilities

  • Monitor and evaluate emerging vulnerabilities from trusted security sources.
  • Initiate and coordinate vulnerability response activities for impacted areas.
  • Collaborate with teams to validate risk and required actions.
  • Establish priorities, timelines, and escalation paths for vulnerabilities.
  • Track remediation of vulnerabilities and validate risk mitigation activities.
  • Analyze vulnerabilities to assess impact and exploitation prerequisites.
  • Translate complex vulnerability information into actionable guidance.

Benefits

  • Company-paid Extended Health, Dental, and Life insurance.
  • Retirement savings plans with company contributions and no vesting period.
  • Paid holidays, vacation days, and sick leave.
  • Voluntary life, critical illness, and long-term disability insurance.
  • Employee discounts on home, auto, and gym memberships.
Full Job Description
Location: Ottawa, Canada

This is a remote and localized role in Ottawa, ON.

Position Summary

Cyberattacks have been on the rise around the globe, with hackers and other criminals targeting businesses large and small to steal valuable information or bring computer networks to a halt. Cyber Security analysts are valued for their ability to protect an organization’s information and systems from such attacks.  

This position is responsible for providing ongoing information security services to all aspects of the on premise and cloud corporate IT environments. The Cybersecurity Vulnerability Engineer will require working across several security functions and have a strong primary focus on incident response activities.


Key Areas of Responsibility 

•    Must be able to monitor and evaluate newly disclosed and emerging vulnerabilities from Thales CTI, OSINT, Thales CERT, PSIRT, vendor advisories, security researchers, vulnerability databases, and other trusted sources.
•    Must be able to Initiate and coordinate enterprise vulnerability-response activities for vulnerabilities with potential impact to Thales businesses and networks.
•    Must be able to Engage infrastructure, IT, application, cloud, product, and security teams to validate exposure and determine required actions.
•    Must have working knowledge of threat actor tactics and techniques.
•    Must be able to establish clear ownership, priorities, response timelines, and escalation paths.
•    Must be able to track remediation and mitigation activities through completion and validate that identified risk has been appropriately addressed.
•    Must be able to escalate missed timelines, unresolved ownership, significant technical uncertainty, or material residual risk to appropriate leadership.
•    Must be able to maintain clear status reporting for technical teams, cybersecurity leadership, and other stakeholders.
•    Must be able to analyze newly disclosed vulnerabilities to understand affected components, exploitation prerequisites, attack vectors, required privileges, exploitability, potential impact, and available mitigations.
•    Must be able to review CVEs, vendor advisories, security-research publications, proof-of-concept information, exploit intelligence, and relevant technical documentation.
•    Must be able assess whether vulnerable technologies or configurations are present in the enterprise and partner with technology owners to validate actual exposure.
•    Responsible for translating complex vulnerability information into clear, actionable guidance for infrastructure, application, product-development, and leadership teams.
•    Responsible for partnering with detection and incident-response teams when a vulnerability requires investigation for possible prior exploitation or additional monitoring.


Basic Qualifications


•    Bachelor’s degree in computer information systems, programming, engineering or a related field with a minimum of 5+ years of cybersecurity experience, including at least 3–4 years in vulnerability management, vulnerability analysis, security engineering, incident response, threat intelligence, penetration testing, or a closely related technical security function.
•    5 to 7 years of experience in Cybersecurity domains.
•    3 to 5 years of experience in demonstrated experience analyzing CVEs and determining their relevance and actual impact within complex enterprise environments.
•    Strong understanding of vulnerability exploitation, attack paths, operating systems, enterprise applications, networking, authentication, privilege boundaries, and common security controls.
•    Ability to interpret vendor advisories, technical security research, proof-of-concept information, logs, configurations, and vulnerability evidence.
•    Working knowledge of Windows and Linux environments, network infrastructure, cloud technologies, virtualization, containers, and enterprise applications.
•    Ability to independently coordinate urgent, cross-functional technical response activities involving multiple teams and competing priorities.
•    Strong organizational skills and the ability to track multiple concurrent vulnerability-response activities through closure.

Preferred Qualifications
•    Strong knowledge of all aspects of information security within the Prevent, Detect and Respond domains.
•    Must be highly analytical and detail-oriented, with organizational skills to manage assigned work to completion.
•    Experience supporting large, complex, or globally distributed enterprise environments.
•    Experience working across corporate IT, shared infrastructure, software-development, cloud, and product environments.
•    Experience using scripting or automation with Python, PowerShell, APIs, SQL, or similar technologies to support vulnerability analysis and data correlation.


Physical Demands
Typical Office environment 


Special Position Requirements

Schedule: First Shift Monday through Friday; Core Business Hours Monday-Friday, etc.


Regulatory Compliance Requirements

Canada
Access to Trade Controlled Hardware, Software, Technical Information, Controlled Goods Program Clearance & Secret Security Clearance

What We Offer

  • Thales provides an extensive benefits program for all full-time employees working 24 or more hours per week and their eligible dependents, including the following:

  • Company paid Extended Health, Dental, HSA, Life, AD&D, Short-term Disability, Cancer Care Program, travel insurance, Employee Assistance Plan and Well-Being program.

  • Retirement Savings Plans (RRSP, DCPP, TFSA) with a company contribution and a match to a DCPP, with no vesting period.

  • Company paid holidays, vacation days, and paid sick leave.

  • Voluntary Life, AD&D, Critical Illness, Long-Term Disability.

  • Employee Discounts on home, auto, and gym membership.

Thales provides an extensive benefits program for all full-time employees working 24 or more hours per week and their eligible dependents, including the following: 

• Company paid Extended Health, Dental, HSA, Life, AD&D, Short-term Disability, Cancer Care Program, travel insurance, Employee Assistance Plan and Well-Being program.

• Retirement Savings Plans (RRSP, DCPP, TFSA) with a company contribution and a match to a DCPP, with no vesting period.

• Company paid holidays, vacation days, and paid sick leave. 

• Voluntary Life, AD&D, Critical Illness, Long-Term Disability.

• Employee Discounts on home, auto, and gym membership.

This position requires direct or indirect access to hardware, software or technical information controlled under the Canadian Export Control List, the Canadian Controlled Goods Program, the Canadian Industrial Security Program, the US International Traffic in Arms Regulations (ITAR) and/or the US Export Administration Regulations (EAR). All applicants must be eligible or able to obtain authorization for such access including eligibility to the Canadian Controlled Goods Program and able to obtain a Canadian NATO Secret clearance.

About Thales Group

Thales Group is a multinational company that specializes in providing advanced technology solutions for the aerospace, defense, and security industries. The company was founded in 2000 and is headquartered in Courbevoie, France. Thales Group operates in over 50 countries and has a strong focus on innovation and research and development. The company's products and services include avionics, cybersecurity, transportation systems, and more. Thales Group is committed to sustainability and has been recognized for its efforts to reduce its environmental impact.
Learn more about Thales Group
Size
83,000 employees
Industry
Founded
1976

Similar Jobs

More Jobs at Thales Group

  • Thales Group
    Human Resources Business Partner
    $100K — $140K *
    Burlington, ON L7L 0A4
    Manufacturing & Automotive
    In-Person
  • Thales Group
    Tactical Buyer
    $61K — $101K *
    Salt Lake City, UT 84118 (Salt Lake County)
    Aerospace & Defense
    In-Person
  • Thales Group
    Support Specialist
    $63K — $117K *
    Remote
    Information Technology
    Remote in Texas, US
  • Thales Group
    Accounting Specialist
    $60K — $102K *
    Overland Park, KS 66212 (Johnson County)
    Legal & Accounting
    Hybrid
  • Thales Group
    Technical Presales
    $137K — $229K *
    Austin, TX 78745 (Travis County)
    Technical Services
    In-Person

More Information Technology Jobs

Find similar Cybersecurity Vulnerability Engineer jobs: