Establish and operate a risk-based vulnerability management capability across cloud, applications, Kubernetes, containers, network infrastructure, software supply chain and cloud-managed customer-premises equipment
Establish authoritative visibility into vulnerabilities across cloud, application, container, Kubernetes, network, endpoint, dependency, firmware and CPE asset classes
Inventory the attack surface and define coverage for internet-facing and internal assets, cloud services, hosts, network devices, containers, Kubernetes clusters, applications, APIs, source code, dependencies, images, infrastructure as code and CPE/firmware
Design, configure and maintain authenticated and unauthenticated scans, agent-based assessments, cloud-native checks, container and dependency scans, attack-surface discovery and targeted validation tests
Evaluate, select and administer vulnerability-management tools and integrate results
Measure scan coverage, health, credential success, stale assets and blind spots; improve asset-to-owner mapping and data quality
Review findings and determine whether they are true positives, false positives, duplicates, accepted risks, mitigated conditions or actionable vulnerabilities
Analyze CVE applicability using versions, provenance, CPE/firmware bill of materials, reachability, configuration, exposure, privileges, exploit prerequisites and controls
Validate material findings using advisories, proof-of-concept analysis, logs, configuration evidence, package inspection and non-production testing
Monitor vulnerability intelligence and vendor advisories
Prioritize remediation using CVSS, CISA KEV, EPSS, exploit availability, exposure, reachability, asset criticality, tenant/customer impact and compensating controls
Define remediation and mitigation targets by risk tier and escalate actively exploited or internet-reachable vulnerabilities
Create remediation records and coordinate patches, upgrades, configuration changes, image rebuilds, dependency updates, firmware releases and compensating controls
Verify closure through rescans or equivalent evidence and manage documented risk exceptions
Assess vulnerabilities across the cloud-to-CPE service path, including device management, certificates, secrets, provisioning, telemetry, firmware delivery and administrative interfaces
Build integrations and automation for asset enrichment, deduplication, risk scoring, ticketing, ownership routing, SLA tracking, notifications, rescans, exception expiry and evidence collection
Maintain dashboards for coverage, exploitable exposure, aging, remediation performance, repeat findings, exceptions, ownership and risk trends
Develop playbooks, standards and procedures for vulnerability handling, critical CVEs, zero-day response, scanner administration and tool outages
Provide reporting to technical owners and leaders and support audits and customer security inquiries
Requirements
5+ years of hands-on experience in vulnerability management, vulnerability assessment, security engineering, product security, cloud security or a closely related discipline
Demonstrated ownership of enterprise scanning and vulnerability-management workflows
Strong CVE analysis skills and ability to determine applicability and exploitability
Experience with enterprise vulnerability platforms and complementary cloud, container, dependency, application and open-source scanning tools
Working knowledge of CVE/CWE, NVD, CVSS, CISA KEV, EPSS, vendor advisories, SBOMs and risk-based prioritization
Hands-on knowledge of Linux, TCP/IP, DNS, TLS/PKI, identity and access controls, APIs, cloud infrastructure, containers and Kubernetes
Ability to read code, package manifests, container images, configurations, logs and network evidence
Scripting or programming ability in Python, Go, PowerShell, Bash or comparable language
Experience integrating security platforms with APIs, ticketing and dashboards
Strong written and verbal communication
Bachelor’s degree in cybersecurity, computer science, engineering or equivalent practical experience
Preferred: security experience with service providers, broadband operators, telecom equipment/software vendors, managed-network providers or distributed device fleets
Preferred: experience assessing embedded Linux, firmware, broadband gateways, routers, ONTs, Wi-Fi/mesh systems or CPE/IoT products
Preferred: familiarity with TR-069/CWMP, TR-369/USP, TR-181, ACS/USP controllers, provisioning, telemetry, certificates and remote firmware lifecycle management
Preferred: experience with Google Cloud Platform, Kubernetes, Terraform, Helm, CI/CD and cloud-native security platforms
Preferred: experience with software composition analysis, SBOM/VEX, container/image scanning, secret scanning, SAST/DAST/API security testing and infrastructure-as-code scanning
Preferred: experience with coordinated vulnerability disclosure, penetration-test finding intake, zero-day response or product security incident response
Preferred: familiarity with NIST Cybersecurity Framework, NIST SP 800-40, CIS Controls, OWASP guidance, PCI DSS, SOC 2 or ISO 27001
Preferred: relevant certifications such as Security+, CySA+, GSEC, GCIH, GPEN, CISSP, CCSP or vendor-specific credentials
Work primarily during normal business hours, with on-call responsibility for critical, actively exploited or zero-day security escalations
Strict need-to-know access and evidence controls for sensitive vulnerability, exploit and customer information
Coordinate intrusive scans, validation tests and production-impacting work through approved change and maintenance processes
Benefits
Escalation availability for critical, actively exploited or zero-day vulnerabilities
Head of Information Security leading OpenZeppelin’s enterprise security, privacy, IT, and AI governance programs. Securing open - source infrastructure used across onchain finance and digital assets.
Red Team Security Engineer evaluating Motive's fleet - management platform and cloud environments. Executing adversary simulations, validating detection coverage, and driving remediation of security issues.
Information Systems Security Manager securing RideCo’s cloud - based on - demand transit platform. Leading compliance, risk management, incident response, and security operations.
Senior Security Specialist securing RBC’s cloud banking environments across AWS, Azure, and Google Cloud. Executing red/purple team exercises and refining offensive security tooling.
Senior Security Specialist operating BloodHound Enterprise for RBC, a Canadian bank. Mapping identity attack paths and prioritizing remediation across cloud, AD, DevOps, and PAM environments.
Staff Security Researcher conducting vulnerability research and penetration testing for GitLab’s AI - powered DevSecOps platform. Developing attack methodologies, tooling, and security improvements.
Principal Security Researcher securing GitLab’s AI - powered DevSecOps platform. Leading vulnerability research, AI attack analysis, penetration testing, and remediation across GitLab’s codebase.
Senior security advisor strengthening Desjardins's security posture across governance, data protection, and fraud prevention. Leading complex strategic initiatives for the Desjardins financial services organization.