BRP Inc.

Senior Vulnerability Management Analyst

BRP Inc. • $95K — $115K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in Cybersecurity, Information Technology, or related field or equivalent experience.
  • 5+ years of cybersecurity experience, including 3 years in vulnerability management.
  • Proficiency with vulnerability management platforms like Tenable, Qualys, or Rapid7.
  • Strong understanding of CVSS, EPSS, and vulnerability prioritization methodologies.
  • Experience across diverse environments: Windows, Linux, cloud, and containers.
  • Familiarity with security frameworks such as NIST CSF and ISO 27001.
  • Strong analytical and risk assessment skills with excellent communication.

Responsibilities

  • Lead vulnerability management for on-premises, cloud, and hybrid environments.
  • Conduct thorough vulnerability assessments and analyze various scan results.
  • Prioritize and classify vulnerabilities based on risk and business impact.
  • Collaborate with infrastructure, application, and operations teams for remediation.
  • Monitor and report remediation progress against service-level agreements (SLAs).
  • Develop risk-based methodologies for vulnerability prioritization.
  • Investigate new threats and assess exposure to vulnerabilities.

Benefits

  • Opportunity to work in a hybrid environment.
  • Access to professional development and mentoring.
  • Engagement in continuous improvement initiatives.
  • Involvement in high-impact cybersecurity projects.
  • Participation in collaborative and innovative team environments.
Full Job Description
We are looking for a Senior Vulnerability Management Specialist responsible for leading the identification, assessment, prioritization, reporting, and remediation oversight of cybersecurity vulnerabilities across enterprise technology environments. This role serves as a subject matter expert for vulnerability management practices, helping to reduce organizational risk by ensuring vulnerabilities are continuously monitored, analyzed, and addressed in alignment with business priorities and regulatory requirements. The Senior Analyst partners with infrastructure, cloud, application, and security teams to drive remediation efforts, improve security posture, and mature vulnerability management capabilities across the organization.

YOU'LL HAVE THE OPPORTUNITY TO:

  • Lead enterprise vulnerability management activities across on-premises, cloud, and hybrid environments.
  • Conduct vulnerability assessments and analyze scan results from multiple security platforms.
  • Validate, prioritize, and classify vulnerabilities based on risk, exploitability, business impact, and threat intelligence.
  • Partner with infrastructure, application, cloud, and operations teams to coordinate remediation activities.
  • Track and report remediation progress against established service-level agreements (SLAs).
  • Develop risk-based vulnerability prioritization methodologies and processes.
  • Investigate emerging threats and assess exposure to newly disclosed vulnerabilities and zero-day exploits.
  • Produce executive and operational reporting, dashboards, and metrics related to vulnerability management performance.
  • Support security audits, regulatory compliance requirements, and risk assessments.
  • Maintain and optimize vulnerability scanning tools and related integrations.
  • Provide technical guidance and mentorship to junior analysts and security team members.
  • Contribute to continuous improvement initiatives, automation efforts, and vulnerability management program maturity.


YOU'LL THRIVE IN THIS ROLE IF YOU HAVE THE FOLLOWING SKILLS AND QUALITIES

  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or a related field, or equivalent work experience.
  • 5+ years of cybersecurity experience with at least 3 years focused on vulnerability management.
  • Experience with vulnerability management platforms such as Tenable, Qualys, Rapid7, or similar solutions.
  • Strong understanding of CVSS, EPSS, KEV catalogs, and vulnerability prioritization methodologies.
  • Experience working with Windows, Linux, networking, cloud, and containerized environments.
  • Knowledge of security frameworks such as NIST CSF, CIS Controls, ISO 27001, or PCI DSS.
  • Experience supporting remediation programs and managing cross-functional stakeholder relationships.
  • Strong analytical, problem-solving, and risk assessment skills.
  • Excellent written and verbal communication skills.
  • Ability to present technical findings to both technical and executive audiences.


ASSETS:

  • CISSP, GSEC, CISM, GIAC, CRISC, or other relevant security certifications.
  • Experience with cloud security platforms including Microsoft Azure, AWS, or Google Cloud Platform.
  • Knowledge of threat intelligence and adversary tradecraft.
  • Familiarity with attack surface management and exposure management programs.
  • Experience with scripting and automation using Python, PowerShell, or similar languages.
  • Knowledge of DevSecOps, CI/CD pipelines, and application security practices.
  • Experience with EDR/XDR platforms, SIEM solutions, and Security Operations Centers (SOC).
  • Understanding of penetration testing methodologies and vulnerability validation techniques.
  • Experience working in highly regulated industries such as financial services, healthcare, or critical infrastructure.
  • Bilingual (English and French) communication skills in Canadian environments.


#LI-Hybrid #LI-DF1

About BRP Inc.

BRP Inc. is a Canadian company that designs, develops, manufactures, distributes, and markets powersports vehicles and propulsion systems. The company's products include Ski-Doo and Lynx snowmobiles, Sea-Doo watercraft, Can-Am on- and off-road vehicles, Alumacraft and Manitou boats, Evinrude and Rotax marine propulsion systems, and Rotax engines for karts, motorcycles, and recreational aircraft. BRP was founded in 1942 and is headquartered in Valcourt, Quebec.
Learn more about BRP Inc.
Size
19,500 employees
Market Cap
$2.7 billion
Industry
NASDAQ

Similar Jobs

More Jobs at BRP Inc.

More Information Technology Jobs

Find similar Senior Vulnerability Management Analyst jobs: