We are looking for a Senior Vulnerability Management Specialist responsible for leading the identification, assessment, prioritization, reporting, and remediation oversight of cybersecurity vulnerabilities across enterprise technology environments. This role serves as a subject matter expert for vulnerability management practices, helping to reduce organizational risk by ensuring vulnerabilities are continuously monitored, analyzed, and addressed in alignment with business priorities and regulatory requirements. The Senior Analyst partners with infrastructure, cloud, application, and security teams to drive remediation efforts, improve security posture, and mature vulnerability management capabilities across the organization.
YOU'LL HAVE THE OPPORTUNITY TO:- Lead enterprise vulnerability management activities across on-premises, cloud, and hybrid environments.
- Conduct vulnerability assessments and analyze scan results from multiple security platforms.
- Validate, prioritize, and classify vulnerabilities based on risk, exploitability, business impact, and threat intelligence.
- Partner with infrastructure, application, cloud, and operations teams to coordinate remediation activities.
- Track and report remediation progress against established service-level agreements (SLAs).
- Develop risk-based vulnerability prioritization methodologies and processes.
- Investigate emerging threats and assess exposure to newly disclosed vulnerabilities and zero-day exploits.
- Produce executive and operational reporting, dashboards, and metrics related to vulnerability management performance.
- Support security audits, regulatory compliance requirements, and risk assessments.
- Maintain and optimize vulnerability scanning tools and related integrations.
- Provide technical guidance and mentorship to junior analysts and security team members.
- Contribute to continuous improvement initiatives, automation efforts, and vulnerability management program maturity.
YOU'LL THRIVE IN THIS ROLE IF YOU HAVE THE FOLLOWING SKILLS AND QUALITIES - Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or a related field, or equivalent work experience.
- 5+ years of cybersecurity experience with at least 3 years focused on vulnerability management.
- Experience with vulnerability management platforms such as Tenable, Qualys, Rapid7, or similar solutions.
- Strong understanding of CVSS, EPSS, KEV catalogs, and vulnerability prioritization methodologies.
- Experience working with Windows, Linux, networking, cloud, and containerized environments.
- Knowledge of security frameworks such as NIST CSF, CIS Controls, ISO 27001, or PCI DSS.
- Experience supporting remediation programs and managing cross-functional stakeholder relationships.
- Strong analytical, problem-solving, and risk assessment skills.
- Excellent written and verbal communication skills.
- Ability to present technical findings to both technical and executive audiences.
ASSETS: - CISSP, GSEC, CISM, GIAC, CRISC, or other relevant security certifications.
- Experience with cloud security platforms including Microsoft Azure, AWS, or Google Cloud Platform.
- Knowledge of threat intelligence and adversary tradecraft.
- Familiarity with attack surface management and exposure management programs.
- Experience with scripting and automation using Python, PowerShell, or similar languages.
- Knowledge of DevSecOps, CI/CD pipelines, and application security practices.
- Experience with EDR/XDR platforms, SIEM solutions, and Security Operations Centers (SOC).
- Understanding of penetration testing methodologies and vulnerability validation techniques.
- Experience working in highly regulated industries such as financial services, healthcare, or critical infrastructure.
- Bilingual (English and French) communication skills in Canadian environments.
#LI-Hybrid #LI-DF1