Vulnerability Management Analyst
7 months ago
About This Role
Vos principaux rôle et responsabilités
Être un collaborateur individuel et excellent joueur d’équipe qui a à cœur d’améliorer et de soutenir l’entreprise. Coordonner et gérer la correction diligente des vulnérabilités de sécurité à travers un éventail de technologies. Repérer, résoudre et documenter tout faux positif dans les résultats d’évaluation des vulnérabilités. Posséder une bonne connaissance pratique de l’architecture Rapid7, des moteurs de balayage, des serveurs de collecte, des agents, des constructeurs de requêtes, des objectifs et des projets. Collaborer avec les équipes des applications et les responsables de secteurs pour soumettre des lettres de risque afin de se conformer avec le cadre de sécurité informatique et de gestion des risques de l’entreprise. Effectuer des évaluations hebdomadaires, mensuelles et ponctuelles de la vulnérabilité des serveurs, des systèmes utilisateur, des ressources réseau, des ressources publiques et des bases de données à l’aide de Rapid7, Burp Suite, SonarSource, Qualys, ou Mend. Gérer les configurations d’analyse, notamment le groupement des ressources, l’authentification appropriée, la mise à jour des modèles de balayage, la mise à jour des pools de moteurs de balayage et la programmation des analyses et des rapports. Gérer et dépanner les outils de gestion des vulnérabilités. Surveiller l’état général de l’analyse des vulnérabilités, la vérification de l’état du moteur et la génération de rapports, et s’assurer de la réussite du balayage avec l’authentification appropriée. Dépanner les balayages afin de détecter les ressources manquantes ou les balayages de ressources ayant eu une authentification incorrecte ou un échec d’authentification. Créer des demandes d’assistance auprès du fournisseur d’outils d’analyse pour obtenir un soutien approprié. Démontrer une bonne expérience pratique des outils DAST, SAST et SCA. Faire le suivi de la correction des vulnérabilités au moyen du système de demandes d’assistance et effectuer une validation à l’aide d’analyses ponctuelles. Se coordonner avec les équipes principales de réseau, de points de terminaison et de serveurs pour discuter des correctifs qui ne sont pas appliqués depuis longtemps, du niveau de correctif cible et des vulnérabilités courantes qui sont couvertes par le correctif correspondant. Connaitre la méthode d’évaluation des vulnérabilités CVSS (Common Vulnerability Scoring System), les concepts d’exploitation et de mises à jour correctives. Avoir une bonne connaissance des vulnérabilités des applications web, des outils d’évaluation et des méthodologies. Avoir au moins 3 ans d’expérience pratique avec les outils de détection des vulnérabilités susmentionnées et 5 à 8 ans d’expérience dans le domaine de la sécurité de l’information. CEH, Rapid7 Certified Administrator (obligatoire), Qualys Certification (obligatoire), Security+, ITIL ou d’autres certifications en matière de sécurité sont requises. Le poste sera offert au candidat sélectionné dont la performance durant l’entretien et la vérification des antécédents et des références seront positives. Ouvert uniquement aux candidats qui sont physiquement présents au Canada au moment de la candidature et qui sont citoyens canadiens ou résidents permanents. Ce poste n’est pas ouvert aux candidats titulaires d’un visa ou d’un permis de travail.Your main role and responsibilities
Be an individual contributor and a great team player with a mindset to improve and support the business. Co-ordinate and manage timely remediation of security vulnerabilities across various technologies. Identify, resolve, and document any false positive findings in vulnerability assessment results. Have a good hands-on knowledge with Rapid7 architecture, scan engines, collector servers, agents, query builder, goals, and projects. Collaborate with application teams and business unit owners to submit risk letters to comply with the organization's IT Security and Risk Management Framework. Perform weekly/monthly and ad-hoc vulnerability assessments for servers, user systems, network assets, public-facing assets and databases using Rapid7, Burp Suite, SonarSource, Qualys, or Mend. Manage scan configurations, including asset grouping and appropriate authentication; update scan templates; update scan engine pool; and schedule scans and reports. Manage and troubleshoot vulnerability management tools. Monitor overall vulnerability scan status, engine health check, report generation and ensure successful scan completion with proper authentication. Troubleshoot scans for any missing assets and assets scanned with improper authentication or authentication failure. Open support case with scanning tools vendor for appropriate support. Demonstrate good hands-on working experience with DAST, SAST & SCA tools. Track vulnerability remediation via ticketing system and perform validation by ad hoc scans. Coordinate with the core network, endpoint teams and server teams to discuss patches that are not applied for a longer time, target patch level, CVEs covered by the corresponding patches. Be knowledgeable of the Common Vulnerability Scoring System (CVSS) vulnerability assessment method, operation concepts and corrective updates. Have good knowledge of web application vulnerabilities, assessment tools and methodologies. Have a minimum of 3 years of hands-on experience working with above said vulnerability tools and 5 to 8 years of experience in the information security domain. CEH, Rapid7 Certified Administrator (Mandatory), Qualys Certification (Mandatory), Security+, ITIL or other security certifications are required. Job offer is based on the positive screening & interview along with the positive background & reference check. This position is only open to candidates who are physically present in Canada at the time of application and are Canadian citizens or permanent residents. This job is not open to candidates on a Work Visa/Work Permit.Position Type
RegularCAE thanks all applicants for their interest. However, only those whose background and experience match the requirements of the role will be contacted.
Equal Opportunity Employer
CAE is an equal-opportunity employer committed to diversity, equity, and inclusion. As "One CAE," we take affirmative action to ensure equal opportunity for all applicants regardless of race, nationality, colour, religion, sex, gender identity and expression, sexual orientation, disability, neurodiversity, Veteran status, age, or other legally protected characteristics.
If you don't see yourself fully reflected in every job requirement listed in the job posting, we still encourage you to reach out and apply. At CAE, everyone is welcome to contribute to our success. If reasonable accommodation is needed to participate in the job application or interview process, please get in touch with us at .
-
Edmonton, Alberta, Canada S.i. Systèmes Full timeAbout the RoleWe are seeking a seasoned Senior Vulnerability Specialist to join our team at S.i. Systèmes. The ideal candidate will have 7+ years of experience in Cyber Security with a focus on Vulnerability Management and Information Security.This role requires strong technical expertise, particularly with vulnerability management scoring systems and...
-
Cyber Security Analyst
6 months ago
Edmonton, Canada AutoCanada Inc. Full time**Cyber Security Analyst** As a member of the Cybersecurity and Compliance team, the Cybersecurity Analyst will oversee the monitoring and analysis of AutoCanada’s Information and Computing Technology (ICT) and data from a cybersecurity and data security perspective. They will develop security playbooks for Cybersecurity incident detection and response,...
-
Security Analyst
7 months ago
Edmonton, Canada CWB Financial Group Full timeAt CWB , we strive to build value for the people who choose us every day: our people, our clients and our investors. We do this by: - Putting people first and building relationships with intention- Seeking out and embracing new ideas- Believing that how we do things is as important as what we do Security Analyst Role Specifications Everyday flexibility....
-
Policy Analyst
6 months ago
Edmonton, Canada Beverage Container Management Board Full time**About the BCMB** The Beverage Container Management Board (BCMB) is the regulatory authority for beverage container recycling in Alberta. Established as a management board under Alberta’s Environmental Protection and Enhancement Act (EPEA), the BCMB is also a non-for-profit organization. BCMB leads the development of policy and programs that enables the...
-
Cybersecurity Analyst
6 months ago
Edmonton, Canada Cybera Full timeCybera is part of the National Research and Education Network (NREN) who are working collaboratively to design and deploy a federated Security Operations Centre (CanSSOC). CanSSOC is developing a Security Operations Centre (SOC) that will support the effective detection and response of cybersecurity threats critical to managing and reducing the growing...
-
Security Guard, Edmonton Vulnerable
6 months ago
Edmonton, Canada Backwoods Security Services Full time**Backwoods Security is currently seeking experienced full-time Security Guards to work Edmonton Vulnerable Sector** **Wage**:$18.00 / Hour **Shift: 10 Hour shifts,** **(Friday, Saturday & Sunday from 8pm to 6am)** **What we offer**: - Competitive Health Benefit Package - All uniforms and PPE - Career growth opportunities **Responsibilities**: -...
-
Security Guard, Edmonton Vulnerable
6 months ago
Edmonton, Canada Backwoods Security Services Full time**Backwoods Security is currently seeking experienced full-time Security Guards to work Edmonton Vulnerable Sector** **Wage**:$18.00 / Hour **Shift: 12 Hour shifts** **What we offer**: - Competitive Health Benefit Package - All uniforms and PPE - Career growth opportunities **Responsibilities**: - Maintain a safe and secure environment for our clients...
-
Senior Financial Analyst
3 weeks ago
Edmonton, Alberta, Canada McCOR Management (AB) Inc] Full timeJob SummaryWe are seeking a highly skilled Senior Financial Analyst to join our team at McCOR Management (AB) Inc. This role involves analyzing financial data, identifying trends, and providing insights to support business decisions.
-
Security Analyst
7 months ago
Edmonton, Canada Government of Alberta Full time**Job Information** Job Requisition ID: 48175 Ministry: Health Location: Edmonton Full or Part-Time: Full Time Hours of Work: 36.25 hours per week Permanent/Temporary: Ongoing Scope: Open Competition Classification: System Analyst Level 2 **Salary**: $2,718.86 to $3,733.10 bi-weekly ($70,962 - $97,433/year) The Ministry of Health leads work in the areas...
-
IT Security Analyst Iv
7 months ago
Edmonton, Canada WCB Alberta Full timeAs an equal opportunity employer, we are looking to build a diverse workforce that reflects the diversity of our clients and the customers we serve. Learn more about working for WCB at Careers - WCB Alberta Job Title: IT Security Analyst IV **Job Type**: Permanent / Full time Job Location: Edmonton, Alberta IT Security Analyst IV Business Technology...
-
Cybersecurity Platforms, Analyst
3 weeks ago
Edmonton, Canada ATCO Ltd. - Common Groups Full timeAt ATCO we are challenging the status quo and aspiring to make a positive impact on the world. With our commitment to accelerating the energy transition, we’ve become a meaningful player in the future of sustainable energy. While the rest of the industry is thinking, we are executing and bringing ideas and solutions to life. ATCO has a strong...
-
Policy Analyst
6 months ago
Edmonton, Canada EngageFirst Management Consults Full time**Job Title: Policy Analyst / Consultant** **Responsibilities** - support senior consultants in their information needs and provide analytical support, - identify information needs for problem solving and formulation of recommendations, - conduct document and internet search on topics related to policy, practices and performance management in the health and...
-
Finance Analyst
6 months ago
Edmonton, Canada Covenant Care Full time**About the Organization**: Is contributing to a mission driven organization important to you? Do you prefer to be a part of an organization that takes its mission as the basis for all decision making? The mission of Covenant Care and Covenant Living is to “continue the healing ministry of Jesus by serving with compassion, upholding the sacredness of life...
-
Accounting Analyst, Real Estate Financial
3 months ago
Edmonton, Canada AIMCo (Alberta Investment Management Corporation) Full timeCLOSING DATE: - October 3, 2024 Opportunity Do you thrive when finding solutions to complex problems? Do you relish the chance to tackle something without a proven course of resolution? This could be your next career adventure! Highly successful Accounting Analysts at AIMCo share many of the same characteristics. They are self-starting, curious and focus...
-
Analyst, Asset Management
6 months ago
Edmonton, Canada Epic Investment Services Full timeReporting to senior management, the Analyst/Senior Analyst will provide** **analysis and insight on strategic initiatives, and support to the asset management team. The role will provide national exposure across the Canadian Commercial Real Estate industry including Retail/Office/Industrial/Residential asset classes. The role provides an approachable...
-
IT Security Analyst Ii
2 months ago
Edmonton, Canada WCB Alberta Full timeAs an equal opportunity employer, we are looking to build a diverse workforce that reflects the diversity of our clients and the customers we serve. Learn more about working for WCB at Careers - WCB Alberta Job Title: IT Security Analyst II Job Type: Permanent / Full time Job Location: Edmonton, Alberta IT Security Analyst II Business Technology...
-
IT Senior Security Analyst
6 months ago
Edmonton, Canada MacEwan University Full timeOpportunity MacEwan University is seeking an IT Senior Security Analyst for a full-time continuing opportunity with the Information Technology Services department. As a senior technical role, this position coordinates the development and support of IT security infrastructure. They identify and implement enhancements that will improve reliability and...
-
New Grad Analyst, Fiduciary Management Rotational
4 months ago
Edmonton, Canada AIMCo (Alberta Investment Management Corporation) Full timeCLOSING DATE: - September 30, 2024 Opportunity Are you looking to complement your academic knowledge with professional ‘real world’ experience at a global multi-asset class institutional investment manager? Are you a purpose-driven individual who wants to contribute to your community? Do you enthusiastically follow financial markets or have a passion...
-
Project Management Analyst
6 months ago
Edmonton, Canada City of Edmonton Full time**Project Management Analyst** Up to 11 months **Job Number***: **47474** Reporting to the Manager, Performance and Continuous Improvement, the Project Management Analyst provides branch project management support and resides within the Office of the Fire Chief. This role works with various internal and external stakeholders to lead priority...
-
New Grad Analyst, Investment Management Rotational
4 months ago
Edmonton, Canada AIMCo (Alberta Investment Management Corporation) Full timeCLOSING DATE: - September 21, 2024 Opportunity Are you ready to kickstart your career with hands-on experience at a global multi-asset class institutional investment manager? If you're passionate about financial markets or economics and want to make a meaningful impact in your community, AIMCo's rotational program is the perfect opportunity for you. We...