Security Specialist, Vulnerability Management
$60 - $90 per hour- Remote job
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Security Specialist, Vulnerability Management based in Canada.
This fully remote role offers the opportunity to build and operate a comprehensive, risk-based vulnerability management program across a complex technology environment. You will help protect cloud platforms, applications, Kubernetes and container environments, network infrastructure, software supply chains, and connected customer devices. The role is highly hands-on, requiring the ability to distinguish meaningful, exploitable vulnerabilities from scanner noise and prioritize remediation based on real-world risk. You will own the vulnerability lifecycle from discovery and validation through remediation, rescanning, reporting, and risk acceptance. Working closely with Engineering, DevOps, NOC, Product, Support, and Compliance teams, you will help reduce measurable security exposure without compromising service reliability. This is an excellent opportunity for a security engineer who combines strong technical depth with sound judgment, automation skills, and the ability to communicate risk clearly.
Accountabilities:- Establish comprehensive visibility across cloud, application, container, Kubernetes, network, endpoint, dependency, firmware, and customer-premises equipment environments, covering both internal and internet-facing assets.
- Design, configure, and maintain authenticated and unauthenticated vulnerability scans, agent-based assessments, cloud-native checks, container and dependency scans, attack-surface discovery, and targeted validation activities.
- Evaluate and administer vulnerability-management and security-testing platforms, integrating multiple tools to provide effective coverage rather than relying on a single technology.
- Define safe scanning procedures, credentials, rate limits, exclusions, maintenance windows, and testing processes to minimize impact on production systems and customer environments.
- Review and validate vulnerability findings, distinguishing true positives, false positives, duplicates, accepted risks, mitigated conditions, and actionable vulnerabilities.
- Analyze CVEs using affected versions, configurations, package provenance, firmware or software inventories, runtime reachability, network exposure, privileges, exploit prerequisites, and existing security controls.
- Prioritize remediation using technical severity, known exploitation, exploit availability, exposure, reachability, asset criticality, customer impact, and compensating controls.
- Establish remediation targets by risk level, escalate actively exploited or internet-facing vulnerabilities, and coordinate emergency response when necessary.
- Partner with Engineering and DevOps teams on patches, upgrades, configuration changes, dependency updates, container rebuilds, firmware releases, and compensating controls, while verifying remediation through rescans or equivalent evidence.
- Manage vulnerability exceptions with documented rationale, appropriate approvals, compensating controls, expiration dates, and scheduled reassessments.
- Assess security risks across the complete cloud-to-device environment, including APIs, device-management protocols, access networks, gateways, routers, ONTs, and connected-home devices.
- Identify affected device models, hardware revisions, firmware branches, software components, and deployed customer cohorts, supporting safe remediation planning and rollout validation.
- Build automation and integrations for asset enrichment, deduplication, risk scoring, ticket creation, ownership routing, SLA tracking, notifications, rescanning, exception management, and evidence collection.
- Maintain dashboards and reporting covering vulnerability coverage, exploitable exposure, aging, remediation performance, repeat findings, exceptions, ownership, and risk trends.
- Develop operating standards, playbooks, and procedures for vulnerability handling, critical CVEs, zero-day response, scanner administration, and tool outages.
- Provide clear reporting to technical and executive stakeholders, distinguishing raw vulnerability volumes from material business risk and highlighting overdue actions or required decisions.
- Support audits and customer security inquiries with traceable evidence while maintaining strict controls over sensitive vulnerability and customer information.
- 5+ years of hands-on experience in vulnerability management, vulnerability assessment, security engineering, product security, cloud security, or a closely related discipline.
- Demonstrated experience owning enterprise vulnerability-management workflows, including scanner configuration, authenticated scanning, coverage analysis, finding validation, false-positive management, remediation tracking, and rescanning.
- Strong CVE analysis capabilities, with the ability to assess applicability and exploitability based on versions, configurations, exposure, reachability, privileges, controls, and business context.
- Experience with enterprise vulnerability platforms and practical familiarity with complementary cloud, container, dependency, application, and open-source security scanning tools.
- Working knowledge of CVE/CWE, NVD, CVSS, CISA Known Exploited Vulnerabilities, EPSS, vendor advisories, software bills of materials, and risk-based prioritization.
- Hands-on understanding of Linux, TCP/IP, DNS, TLS/PKI, identity and access controls, APIs, cloud infrastructure, containers, and Kubernetes.
- Ability to review code, package manifests, container images, configurations, logs, and network evidence to validate findings and guide remediation.
- Scripting or programming experience with Python, Go, PowerShell, Bash, or a comparable language, as well as experience integrating security platforms with APIs, ticketing systems, and dashboards.
- Strong written and verbal communication skills, with the ability to explain technical risk, uncertainty, trade-offs, and remediation decisions to engineers, operational teams, and leadership.
- Bachelor's degree in cybersecurity, computer science, engineering, or equivalent practical experience.
- Experience with service providers, broadband operators, telecommunications technology, managed networks, or large distributed device fleets is an asset.
- Familiarity with embedded Linux, firmware, broadband gateways, routers, ONTs, Wi-Fi/mesh systems, IoT, or other customer-premises equipment is an advantage.
- Knowledge of TR-069/CWMP, TR-369/USP, TR-181, device provisioning, telemetry, certificates, and remote firmware lifecycle management is considered an asset.
- Experience with Google Cloud Platform, Kubernetes, Terraform, Helm, CI/CD, and cloud-native security posture or workload-protection platforms is preferred.
- Experience with software composition analysis, SBOM/VEX, container and image scanning, secret scanning, SAST/DAST, API security testing, or infrastructure-as-code scanning is valuable.
- Familiarity with coordinated vulnerability disclosure, penetration-test findings, zero-day response, or product security incident response is a plus.
- Knowledge of security frameworks and standards such as NIST Cybersecurity Framework, NIST SP 800-40, CIS Controls, OWASP, PCI DSS, SOC 2, or ISO 27001 is advantageous.
- Relevant certifications such as Security+, CySA+, GSEC, GCIH, GPEN, CISSP, CCSP, or vendor-specific vulnerability-management credentials are welcome, although practical expertise is valued more highly than certification alone.
- Strong ownership, analytical thinking, prioritization, and problem-solving abilities, with the confidence to challenge scanner results and remediation claims constructively while maintaining clear evidence, accountability, and deadlines.
- Availability to work primarily during normal business hours, with escalation availability for critical, actively exploited, or zero-day vulnerabilities.
- Ability to manage sensitive vulnerability, exploit, and customer information according to strict need-to-know and evidence-control requirements.
- Contract position with an hourly compensation range of CAD $60–$90 per hour , depending on experience and expertise.
- Fully remote position available across Canada.
- Opportunity to work on a broad and technically complex security environment spanning cloud, applications, Kubernetes, networking, software supply chains, firmware, and connected devices.
- High-impact role with significant ownership in establishing and maturing a company-wide vulnerability management capability.
- Cross-functional collaboration with engineering, DevOps, operations, product, support, and compliance teams.
- Opportunity to work with modern security technologies and vulnerability-management platforms across multiple security domains.
- Inclusive and diverse working environment with a commitment to equal opportunity and objective, skills-based recruitment.
Requirements
Benefits
$85k - $100k per year
...drive. If you’re passionate about security, compliance, and helping teams work smarter... ...We are seeking an AppSec Security Specialist to support our growing security function... ...focus on application security, vulnerability management, and secure development practices across...SuggestedFull timeManual labor- .... By taking advantage of all structured and unstructured data — securing and protecting private information more effectively — Elastic’s... ...of AI. What is The Role We're looking for a Principal Product Manager to be the primary product voice for Elastic Security's most strategic...SuggestedFull time
- ...Opportunity A Toronto-based practice is seeking an experienced securities lawyer to join at the partner level. The role suits a lawyer... ...Liaise with securities regulators on behalf of clients Build and manage client relationships within the capital markets community...Suggested
- ...lifetime. About the Role Hasbro is seeking a Principal SAP Security Analyst to join our IT Security team in Montreal. This senior... ...knowledge, collaboration, and sound judgment. This role is not a people manager position, but it does provide technical direction to SAP...SuggestedLong term contractShift work
$170k - $210k per year
...Corporate & Securities Associate Location: Vancouver, BC Practice Area: Corporate / Securities Experience: 2-5 years Compensation: Commensurate with experience; comparable Vancouver market roles range $170,000–$210,000 This is a confidential search — the identity...Suggested- ...to shape legendary play that lasts a lifetime. À propos du poste Hasbro est à la recherche d'un(e) analyste principal(e) de la sécurité SAP pour se joindre à son équipe de sécurité TI à Montréal. Ce poste de contributeur(trice) individuel(le) senior jouera un rôle clé...Long term contract
- ...Customer Support Specialist I Function: Customer Experience Reports to: Manager, Customer Support Position Summary: The Customer Support Specialist... ...following 60 days of employment at 5% to help you secure your financial freedom. We offer a generous company...Long term contractTemporary workCasual workLocal areaRemote workWorldwideFlexible hoursShift work
- ...feedback. ️ Set People Up for Success Coordinate with hiring managers to ensure every new hire has the tools, access, and welcome they... ...a tight-knit HR team that actually likes each other. Your HR Manager is a mentor, not a micromanager. You'll collaborate daily with...Full timeRemote workWork from homeHome officeFlexible hours
- ...clients improve their operations and better serve their customers. Our solutions include advanced billing and customer relationship management tools, as well as powerful analytics and data management capabilities. We are proud to have been recognized by industry experts and...Full timeSummer workInternshipLocal areaRemote workHome officeFlexible hours
- ...Responsibility: Some of what you will do: As a Customer Success Specialist play a pivotal role in upholding our commitment to exceptional... ...and insights to drive product improvements and enhancements. Manage customer profiles with the subscription management platform (...Part timeRemote work
- ...Description Job Title: Workday Reporting, Security & HRIS Analyst (Remote – Canada) Company... ...-related business process controls Manage user provisioning, access reviews, security... ..., Finance, IT, and Audit teams to deliver secure and scalable Workday solutions Technical...Remote work
$116.2k - $155k per year
...This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Manager... ...management. Lead, coach, and develop a team of benefits specialists and administrators across regions, establishing performance expectations...Remote jobPermanent employmentFull timeContract workLocal areaHome officeFlexible hours$40k - $45k per year
...Innovation Starts With You. End-User Support Specialist Full time / Permanent Position... ...configuring, dispatching, shipping, and managing replacement Quest devices. This role... ...timely issue resolution, device lifecycle management, and close collaboration with internal support...RemplacementPermanent employmentFull timeRemote workWork from home- ...This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Lead Monitoring & Diagnostics Technical Support Specialist based in Canada. This fully remote role offers the opportunity to become a key technical...Remote jobRemplacementFull timeLocal areaRelocation
- ...Job Responsibility: Some of what you will do: Effectively manages project & complex orders for technology, from the point of order... ...challenges Coordinates project by working closely with Tech Specialists, vendors and clients. Reviews ship dates for adherence to original...Ongoing contractRemplacementFull timeRemote work
$76k - $104.5k per year
...and marketing channels. We are seeking a Technical Operations Specialist to support mobile app advertising initiatives. This role is... ...Proactively follow up on deliverables and drive projects forward Manage multiple workstreams in a fast-paced environment What You’ll...Local areaRemote workWork from homeHome office$95k - $125k per year
...you'll have an impact We're looking for a Revenue Enablement Manager to build and scale the programs that help our go-to-market... ...scales — for example, building out a small team of enablement specialists or coordinators as programs expand across functions. You'll have...Permanent employmentFor contractorsImmediate startRemote workWorldwide$110k - $140k per year
...work environment that empowers you to excel. Our Offensive Security professionals are on a mission to make the world a safer place,... ...clearly to technical and non-technical audiences ~ The ability to manage risk during live client engagements and operate within agreed...Remote work- ...and various available mortgage products, but is also passionate about creating amazing borrower experiences. What You’ll Be Doing Manage customer deal flow, while ensuring prioritization of files in progress. Act as a liaison between underwriter, lender and clients....
- ...emerge. Overview: We are looking for a Platform Engineering Manager with a strong hands-on engineering background to lead and grow a... ...-powered platform tooling. Rather than owning infrastructure or security directly, your team builds the tooling, guardrails, capacity...
- ...impact. About the role: As a Senior Analytics Implementation Specialist, you understand a client’s business and marketing requirements... ...implement enterprise-wide digital analytics and tag management solutions. This involves consulting IT departments and senior...Long term contractRemote work
$95k - $125k per year
...work from anywhere in Canada. The Senior Manager, Data Engineering leads a team of data... ...Product, Fundraising, Marketing, Engineering, Security, Analytics & Data Science, and... ...engaged in projects to ensure high quality, secure delivery that meets contractual scope, budget...Full timeHome officeFlexible hours- ...Description Job Opportunity: Specialist, Data Analytics, Internal... ...; Expected End: July 2027) Security Clearance: Enhanced (must be... ...stakeholders to clear bottlenecks and secure reliable access to necessary... ...within an audit, risk management, or technology assurance environment...Contract workInternship2 days per week1 day per week
$80k per year
...around the world. Job description As the National Wholesale Manager, you will lead Hamilton’s independent wholesale business across... ...partners. Develop territory plans, present business opportunities, and secure new accounts that support sustainable growth. Key Account...Full timeWork at office2 days per week3 days per week- ...We aren't looking for a traditional PR person. We need a Growth Specialist who lives and breathes the social media ecosystem. Your job is to... ...viral "DNA," onboard them using our proprietary data tools, and manage those high-value relationships with surgical precision. This is...Long term contractFull timeRemote work
$100k per year
...Support with renewals and subscription-related requests Maintain a strong understanding of e-commerce workflows, including order management and integrations Assist with special projects as needed About You Requirements ~1–3 years of experience in customer support...Full time$55k per year
...Business Development Operations Specialist - this role is based for applicants located in Canada SiteDocs, a GoCanvas company, is a leading provider of digital safety management software, trusted by thousands of teams to modernize and simplify workplace health and safety...Remote jobLong term contractFull time$65k per year
Are you a specialist Psychiatrist (MD, FRCPC or equivalent) in Canada, interested in leveraging... ...private psychiatric services online. Manage your schedule, focus on patient care, and... ...who need their expertise, all through a secure and seamless online experience. Key Responsibilities...Hourly payFull timePart timeSelf employmentPrivate practiceRemote workFlexible hours$50k - $55k per year
...Innovation Starts With You. Scheduling Manager Full time - Remote / Hybrid. Job Role: CGS is seeking an experienced Scheduling Manager to join our instructional delivery services team. The Scheduling Manager leads a team of Instructional Delivery Schedulers...Full timeInternshipRemote workWork from home- ...adventure. Join us in shaping healthier, more vibrant communities around the globe. The role you’ll play As a Field Account Manager, you’ll be the face of ClassPass in your region—building strong relationships with our most valuable partners and turning every touchpoint...Local areaWorldwideNight shift
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Security Specialist, Vulnerability Management. Be the first to apply!
- physical security specialist Canada
- security consultant Canada
- security analyst remote Canada
- security operations specialist Canada
- application security consultant Canada
- security analyst Canada
- physical security analyst Canada
- spécialiste en sécurité Canada
- conseiller en sécurité financière Canada
- spécialiste en sécurité informatique Canada

