Senior Cybersecurity Specialist, Vulnerability Management (Ottawa (Downtown), ON, CA)

Bank of Canada

$111K — $130K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5-7 years in vulnerability management and exposure assessment (on-premises/cloud)
  • Proficient in cloud security, particularly Microsoft Azure
  • Experience with security data analysis and reporting tools (e.g., Power BI)
  • Hands-on experience with vulnerability scanning platforms (e.g., Tenable, Qualys)
  • Understanding of AI tools for enhancing security analysis

Responsibilities

  • Lead the evolution of the Bank's vulnerability management program
  • Assess security posture of cloud solutions, focusing on Microsoft Azure
  • Conduct risk-based vulnerability analysis using threat intelligence
  • Maintain dashboards and reporting for actionable insights
  • Drive remediation workflows across various technical teams
  • Support third-party and cloud risk assessments
  • Participate in on-call support for security incidents

Benefits

  • Flexible and comprehensive benefits plan
  • Additional vacation days available for purchase
  • Indexed, defined-benefit pension plan
  • Hybrid work model with telecommuting options
  • Support for continuous professional development and learning opportunities
Full Job Description
Senior Cybersecurity Specialist, Vulnerability Management

What you need to know

Help build the next generation of cyber resilience at the Bank. Join the Bank's Cyber Security team to work on high-priority technical initiatives that strengthen how we detect, respond to, and recover from cyber threats in a rapidly evolving environment.

In this role, you will help shape the Bank's approach to exposure management by identifying, assessing, prioritizing, and driving remediation of vulnerabilities across on-premises and Microsoft Azure cloud environments.

What you will do

You will work closely with the Technical Vulnerability Assessment team, Cyber solution architects, implementation teams, security operations, and business stakeholders to assess new and existing solutions before they are introduced into the Bank's environment. You will help ensure that security risks are identified early, vulnerabilities are clearly understood, and practical remediation options are provided before implementation. Through hands-on technical testing, vulnerability validation, and clear reporting, you will play a key role in helping the Bank safely adopt new technologies while reducing exposure across its systems, applications, and services.

More specifically, you will:
  • Identify and perform hands-on security assessments of business and core IT solutions across operating system, web, database, application, API, microservices, and modern application architecture layers.
  • Research and understand underlying technologies and their implementation within the Bank of Canada environment.
  • Develop and communicate test plans.Execute assessments, identify vulnerabilities, and clearly communicate findings, exploitability, business impact, and remediation options.
  • Consult with implementation teams, security architects, and stakeholders to validate findings and develop practical solutions.
  • Prepare concise, actionable reports outlining risks and recommended mitigations.
  • Execute threat-informed testing, adversary emulation exercises, vulnerability assessments, and penetration tests aligned with the MITRE ATT&CK framework.
  • Validate vulnerabilities identified through automated scanning tools, eliminate false positives, and assess exploitability and business impact.
  • Identify and assess vulnerabilities related to authentication, authorization, business logic, data exposure, APIs, and third-party integrations, including validating associated security controls.
  • Conduct rapid security assessments of new and emerging commercial off-the-shelf (COTS) products before deployment within the Bank.
  • Collaborate with Security Operations teams to validate detection and response capabilities and provide recommendations to strengthen alerting, monitoring, and incident response effectiveness.
  • Assist in planning, organizing, and managing security assessment and remediation activities, including the development of project plans, schedules, and testing priorities.
  • Collaborate with architecture, development, quality assurance, operations, and security teams to define, implement, measure, and improve security controls.
  • Resolve complex security issues, assess technology-related risks and impacts at the functional and corporate levels, and support the resolution of security incidents as required.
  • Provide technical guidance, expertise, and support to Bank staff on security assessment findings, remediation activities, and security best practices.


What you need to succeed

You'll have expertise in several of the following areas:

Offensive Security & Penetration Testing
  • Network penetration testing
  • Web application security testing
  • API security testing
  • Adversary emulation and purple teaming


Identity, Cloud & Infrastructure Security
  • Active Directory and Microsoft Entra ID security
  • Cloud security assessments (Azure and AWS)
  • Container and Kubernetes security


Advanced Security Testing
  • AI and Large Language Model (LLM) security testing
  • Threat-informed testing using the MITRE ATT&CK framework
  • Vulnerability research, analysis and validation


Security Consulting & Communication
  • Technical report writing and presentation of findings
  • Translating complex technical risks into practical recommendations


Nice-to-have

Experience with:
  • Web application security, vulnerability assessments, and penetration testing.
  • Network, operating system, cloud, and infrastructure security controls.
  • Enterprise security technologies, including firewalls, IDS/IPS, authentication, and SIEM solutions.
  • Security architecture, risk assessment, and technical control design.
  • Manual security testing, vulnerability research, and proof-of-concept development.
  • Security risk assessment methodologies (e.g., HTRA, NIST).
  • Preparing and presenting technical findings to technical, business, and executive audiences.


Your education and experience

This position requires a University Degree or College Diploma in Computer Science, Engineering or related discipline with a minimum of five (5) years of recent and relevant work experience in the field of information and technology security, with a concentration in one or more of the following areas:
  • Technical vulnerability assessment and penetration testing, including at the application layer
  • Technical security risk assessment/audits on web, server and desktop applications
  • Web application security
  • Secure development and coding practices


A combination of education and experience may also be considered.

Innovative Mindset
We value candidates who demonstrate adaptability, curiosity, and a willingness to learn new technologies, including AI and digital tools. We seek individuals who can think critically about data, question existing processes, and find ways to simplify our work while embracing change and new ways of doing things.

Language requirement

The Bank's work environment is conducive to the use of both of Canada's official languages - English and French. Although the position language requirement is English or French essential, we do encourage everyone to improve their second language proficiency for future career growth and to contribute towards fostering a bilingual environment.

What you need to know
  • Priority will be given to Canadian citizens and permanent residents
  • Security level required: Be eligible to obtain Secret
  • There will be no relocation assistance provided
  • Please save a copy of the job poster. Once the closing date has passed, it will no longer be available.
  • The official title for this position is "Senior IT Security Assessment Specialist"


Hybrid Work Model
The Bank offers work arrangements that provide employees with flexibility, enable high-performing teams, and support an excellent workplace culture. Most employees can telework from home for a portion of each month as part of the Bank's hybrid work model, and they are expected on site at the Bank location a minimum of 12 days per month to help build connections between colleagues. You must live in Canada, and within reasonable commuting distance of the office.

What you can expect from us
This is a great opportunity to join a leading organization and be part of a high-performing team. We offer a competitive compensation and benefits package designed to meet your needs at every stage of your life and career. For more information on key benefits please visit A great deal to consider.

  • Salaries are based on qualifications and experience and typically range from $111,051 to $130,649 (job grade 17)
  • The Bank offers an incentive for successfully meeting expectations at 7 to 10% of your base salary. The Bank offers additional performance pay (5%) for those who exceed expectations. Exceptional performers who far exceed expectations may be eligible for higher performance pay.
  • Flexible and comprehensive benefits so you can choose the level of health, dental disability and life and/or accident insurance coverage that meets your needs
  • Extra vacation days (up to five each year) that you can purchase to add to your vacation entitlement
  • Indexed, defined-benefit pension


We wish to thank all applicants for their interest and effort in applying for this position. Only candidates selected for interviews will be contacted.

Similar Jobs

More Jobs at Bank of Canada

More Information Technology Jobs

Find similar Senior Cybersecurity Specialist, Vulnerability Management (Ottawa (Downtown), ON, CA) jobs: