Lead Advisor, Infosec Threat and Vulnerability
4 days ago
Our culture lifts you up—there is no ego in the way. Our common purpose? We all want to win for our customers. We aim to always be evolving, dynamic, and ambitious. We believe in the power of genuine connections. Each employee is a part of what makes us unique on the market: agile and dedicated.
Time Type:
Regular
Job Description:
SUMMARY OF POSITION:
Reporting to the Manager, Information Security Governance Risk and Compliance, the InfoSec Threat and Vulnerability Management Senior Advisor will lead the design, implementation, reporting and remediation follow ups for vulnerability management. This also includes overseeing penetration testing, evaluating findings, translating findings into actionable tasks and supporting remediation.
The incumbent works to operate an effective and modern vulnerability and risk mitigation program, with an advanced understanding of the current state (threats, risks, people, processes and technologies), in collaboration with the other cybersecurity teams and business units.
**MAIN RESPONSIBILITIES**:
Leads and owns the Vulnerability Management function across all business units (BU).-
- Collaborates with the business units Vulnerability Analysts to consolidate all activities into a corporate InfoSec Vulnerability management database.-
- Collaborates with ERM (Enterprise Risk Management) and the Business Unit ISwg (Information Security working group) leaders to identify and prioritize high exposure vulnerabilities.Provides expertise in the prioritization of vulnerabilities based on real data, the risks posed, and the business context;Operates vulnerability management tools (in a shared responsibility model with the Analysts from the business units) and takes the ownership of constantly improving them;-
- Analyzes asset and vulnerability operational datasets to provide meaningful, actionable metrics and data visualizations;-
- Documents vulnerability analysis and assessment findings after performing risk analysis;-
- Advises business units on corrective actions and collaborates with InfoSec teams and ERM to ensure remediation and any adjustments that could be needed;-
- Identifies new security requirements, risks, trends and develops appropriate responses;-
- Coordinate and supervise penetration testing exercises with external vendors, other InfoSec teams and business units;-
- Translate findings into actionable tasks and follow up on vulnerability remediation plans with the different stakeholders;-
- Gather relevant data to report on vulnerability management metrics;-
- Partners with key stakeholders to develop and/or update information security documents such as policies, standards, procedures, training material;-
- Remains aware of technological trends and developments in the area of information security.ESSENTIAL REQUIREMENTS
ACADEMIC TRAININGRecognized certification in Computer Science, Information Security or any relevant domain.- WORK EXPERIENCEMinimum 5 years experience in information security, IT support or system management-
- Experience in vulnerability risk and analysis and coordinating vulnerability management efforts.- TECHNICAL COMPETENCIESTechnical understanding of general security vulnerabilities and their mechanisms of exploitation;-
- Expertise in setting up and operating Qualys and/or equivalent vulnerability management tool;-
- Experience in penetration testing is an asset;-
- Proficient in information security principles, and industry standards such as NIST and ISO;-
- Current industry standard security certification (Security+, SANS, Microsoft, Cisco etc.) is an asset;-
- Experience using tools to correlate unstructured data from various types of journals and event flows;-
- Experience with information security concepts related to threat and vulnerability management, system architecture and Internet and cloud technology;Knowledge of attack vectors, threat actors, and mitigation techniques;-
- Understanding of information security practices and policies.PARTICULAR COMPETENCIESPreferred fluency in French and English (spoken and written), to be able to collaborate with different Business Units in Quebec, Ontario and across the United States;-
- Has a collaborative business mindset with supporting work ethics;-
- Flexible and able to quickly adapt to change (embraces change);-
- Is viewed as a team player by peers and management;-
- Financial understanding of the impacts of his/her recommendations;-
- Be able to propose and negotiate solutions and initiatives;-
- Be fully autonomous and take ownership of the process;-
- Possess a strong capacity for analysis and synthesis;-
- Strong problem solving skills;-
- Excellent organizational and communication skills;-
- Attention to detail;-
- Ability to work under pressure and manage multiple priorities;-
- Capable of understanding technical details and then presenting in layman’s terms to a less technical audience (eg. executives, product owners, etc).Location:
Montréal, QC
Company:
Cogeco Communications
-
Infosec Product Owner, Grc
3 days ago
Montréal, Canada Business Development Bank of Canada Full timeWe are banking at another level. Choosing BDC as your employer means working in a healthy, inclusive, and skilled workplace that puts forward the best conditions to bring together unique teams where employees are empowered to act. It also means being at the centre of ambitious economic and financial projects to see further and to do things differently, to...
-
Infosec Specialist, Training
6 days ago
Montréal, Canada Business Development Bank of Canada Full timeNo other bank is doing what we do. At BDC, we help Canada and its entrepreneurs create a prosperous, inclusive and green economy. Our mission is to help Canadian businesses thrive by providing financing, capital and advisory services. We’re devoted to Canadian entrepreneurs. We’re also dedicated to our employees. Adaptable. Inspiring. Different....
-
Vulnerability Management Practice Leader
2 weeks ago
Montréal, QC, Canada National Bank of Canada Full timeA career as a vulnerability management practice leader in the information security team, CISO, at National Bank means acting as an expert and playing an important role in improving the vulnerability management practice. It is through your experience in operational cybersecurity, your in-depth knowledge of vulnerabilities and your strong leadership that you...
-
Senior SOC Lead: Incident Response
15 hours ago
Montréal-Est, Canada American Iron and Metal Full timeA leading metal recycling company in Montreal is seeking an experienced Senior SOC Analyst to act as a technical lead in the Security Operations Center. Responsibilities include advanced triage, incident response, and threat hunting. The ideal candidate has 7+ years of SOC experience, strong knowledge of security tools, and is fully bilingual in French and...
-
Cybersecurity Advisor
4 days ago
Montréal, Canada CTConsultants Full time**CTC007566 - Cybersecurity Advisor**: **Secteur industriel: Infrastructure**: **Type d'emploi: Contract**: **Durée: Eleven months**: **Mode de travail: Remote**: **Description**: Duration: 300 hours Possibility of extension: Yes Flexible hourly rate Remote: Hybrid. 10% in-office and 90% remote. Offices are in Montreal, Ottawa or...
-
Offensive Security Advisor
1 week ago
Montréal, Canada Desjardins Full timeAt Desjardins, we believe in equity, diversity and inclusion. We're committed to welcoming, respecting and valuing people for who they are as individuals, learning from their differences, embracing their uniqueness, and providing a positive workplace for all. At Desjardins, we have zero tolerance for discrimination of any kind. We believe our teams should...
-
Senior SOC Analyst – Incident Response
58 seconds ago
Montréal-Est, Canada American Iron and Metal Full timeJob DescriptionWe are looking for a Senior SOC Analyst to qualify events escalated through triage, perform investigations, digital forensics, threat hunting, and incident response in our Security Operations Center. You will act as a technical lead during major incidents and mentor junior analysts.What you’re responsible for:Advanced triage of SIEM,...
-
Senior SOC Analyst – Incident Response
15 hours ago
Montréal-Est, Canada American Iron and Metal Full timeCompany Description American Iron & Metal (AIM) is a family‑owned company and recognized global leader in the metal recycling industry with more than 125 sites and 4000 employees worldwide. We have continued to prosper for the last eight decades thanks to the dedication of our employees and the ongoing trust and support of our customers. Become part of...
-
IT Infra
5 days ago
Montréal, Canada BNP Paribas Full timeIn a changing world, unprecedented challenges require unmatched talent. Join one of Montreal's Top Employers in 2025. We are a dynamic and growing organization having its main establishment located in downtown Montreal and part of a leading international banking institution fully committed to building a more sustainable future. Note that the position may be...
-
Senior Manager, Cybersecurity Operations
3 minutes ago
Montréal, Canada CMHC Full timeJob Requisition ID: 10747 Position Status: Permanent Full Time Position Type: Hybrid Office Location: Ottawa (preferred), Montreal (QC) and Toronto (ON) will be considered Travel Requirement: Occasional Language Designation: Bilingual Language Skill Levels (Read/Write/Speak): CBC Security Requirement: Secret Salary: Our salaries...