Security Specialist, Vulnerability Management
Save this job and keep your search organized
Create a free account to save jobs, create alerts and return to this listing from your dashboard.
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Security Specialist, Vulnerability Management based in Canada.
This fully remote role offers the opportunity to build and operate a comprehensive, risk-based vulnerability management program across a complex technology environment. You will help protect cloud platforms, applications, Kubernetes and container environments, network infrastructure, software supply chains, and connected customer devices. The role is highly hands-on, requiring the ability to distinguish meaningful, exploitable vulnerabilities from scanner noise and prioritize remediation based on real-world risk. You will own the vulnerability lifecycle from discovery and validation through remediation, rescanning, reporting, and risk acceptance. Working closely with Engineering, DevOps, NOC, Product, Support, and Compliance teams, you will help reduce measurable security exposure without compromising service reliability. This is an excellent opportunity for a security engineer who combines strong technical depth with sound judgment, automation skills, and the ability to communicate risk clearly.
Accountabilities
- Establish comprehensive visibility across cloud, application, container, Kubernetes, network, endpoint, dependency, firmware, and customer-premises equipment environments, covering both internal and internet-facing assets.
- Design, configure, and maintain authenticated and unauthenticated vulnerability scans, agent-based assessments, cloud-native checks, container and dependency scans, attack-surface discovery, and targeted validation activities.
- Evaluate and administer vulnerability‑management and security-testing platforms, integrating multiple tools to provide effective coverage rather than relying on a single technology.
- Define safe scanning procedures, credentials, rate limits, exclusions, maintenance windows, and testing processes to minimize impact on production systems and customer environments.
- Review and validate vulnerability findings, distinguishing true positives, false positives, duplicates, accepted risks, mitigated conditions, and actionable vulnerabilities.
- Analyze CVEs using affected versions, configurations, package provenance, firmware or software inventories, runtime reachability, network exposure, privileges, exploit prerequisites, and existing security controls.
- Prioritize remediation using technical severity, known exploitation, exploit availability, exposure, reachability, asset criticality, customer impact, and compensating controls.
- Establish remediation targets by risk level, elevate actively exploited or internet-facing vulnerabilities, and coordinate emergency response when necessary.
- Partner with Engineering and DevOps teams on patches, upgrades, configuration changes, dependency updates, container rebuilds, firmware releases, and compensating controls, while verifying remediation through rescans or equivalent evidence.
- Manage vulnerability exceptions with documented rationale, appropriate approvals, compensating controls, expiration dates, and scheduled reassessments.
- Assess security risks across the complete cloud-to-device environment, including APIs, device‑management protocols, access networks, gateways, routers, ONTs, and connected‑home devices.
- Identify affected device models, hardware revisions, firmware branches, software components, and deployed customer cohorts, supporting safe remediation planning and rollout validation.
- Build automation and integrations for asset enrichment, deduplication, risk scoring, ticket creation, ownership routing, SLA tracking, notifications, rescanning, exception management, and evidence collection.
- Maintain dashboards and reporting covering vulnerability coverage, exploitable exposure, aging, remediation performance, repeat findings, exceptions, ownership, and risk trends.
- Develop operating standards, playbooks, and procedures for vulnerability handling, critical CVEs, zero-day response, scanner administration, and tool outages.
- Provide clear reporting to technical and executive stakeholders, distinguishing raw vulnerability volumes from material business risk and highlighting overdue actions or required decisions.
- Support audits and customer security inquiries with traceable evidence while maintaining strict controls over sensitive vulnerability and customer information.
Requirements
- 5+ years of hands-on experience in vuln