Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Security Specialist, Vulnerability Management (Canada - Remote)

$60 - $90 per hour
Full-time

Axon-networks

Toronto, ON
  • Remote job


 



AXON Networks delivers a robust AI-driven, analytics-based orchestration platform and a wide portfolio of next-gen high-speed routers that leverage the newest Wi-Fi technologies. Together, these technologies give ISPs the ability to manage and troubleshoot their networks in real time, and to deliver an outstanding customer experience.

AXON Networks is a trusted strategic partner for its customers, helping them evaluate their current technologies and business models, and creating and executing strategies that enable them to innovate faster, accelerate their digital transformations, and strengthen their relationships with consumers.

AXON Networks is headquartered in Irvine, CA USA with Asia HQ in Singapore and also operating in Denmark, Spain and Vietnam.


The Security Specialist, Vulnerability Management will establish and operate a risk-based vulnerability management capability across the company’s cloud platform, applications, Kubernetes and container environments, network infrastructure, software supply chain, and cloud-managed customer-premises equipment (CPE), including broadband gateways, routers, ONTs and connected-home devices. This is a hands-on security engineering role for someone who can distinguish a scanner finding from a vulnerability that is relevant and exploitable in the company’s actual environment.  


The engineer will select and configure scanning approaches, validate findings, analyze CVEs, prioritize risk, coordinate remediation, verify closure and create the dashboards, evidence and operating standards needed for a repeatable program. The engineer will explain risk clearly to operational and engineering leaders and will not rely on severity scores alone.  


Role mandate  






  • Establish authoritative visibility into vulnerabilities across cloud, application, container, Kubernetes, network, endpoint, dependency, firmware and CPE asset classes.  





  • Determine whether findings and CVEs apply to the versions, configurations, exposure paths and controls actually present in the environment.  





  • Prioritize remediation using technical severity, known exploitation, likelihood, reachability, asset criticality, customer impact and compensating controls.  





  • Create a durable operating model for intake, validation, assignment, service levels, exceptions, rescanning, closure and executive reporting.  





  • Partner with Engineering, DevOps, NOC, Support, Product and Compliance to reduce measurable exposure without disrupting reliable customer service.  



What you will own  




Scanning strategy and coverage  






  • Inventory the attack surface and define coverage for internet-facing and internal assets, cloud services, hosts, network devices, containers, Kubernetes clusters, applications, APIs, source code, third-party dependencies, images, infrastructure as code and supported CPE/firmware.  





  • Design, configure and maintain authenticated and unauthenticated scans, agent-based assessments, cloud-native configuration checks, container and dependency scans, external attack-surface discovery and targeted validation tests.  





  • Establish safe scan windows, credentials, rate limits, exclusions and testing procedures so scans do not destabilize production, customer environments or large CPE fleets.  





  • Evaluate, select and administer appropriate capabilities from platforms such as Tenable Nessus , Qualys, Rapid7, Wiz, Orca, Prisma Cloud, Snyk , Veracode, Checkmarx , Trivy , Grype , Nuclei or equivalent tools; integrate results rather than requiring one product to solve every use case.  





  • Measure coverage, scan health, credential success, stale assets and blind spots; continuously improve asset-to-owner mapping and data quality.  



Finding validation and CVE analysis  






  • Review new and existing scan findings and determine whether each is a true positive, false positive, duplicate, accepted risk, mitigated condition or actionable vulnerability.  





  • Analyze CVE applicability using affected component and version, package provenance, CPE or firmware bill of materials, runtime reachability, configuration, network exposure, privileges, exploit prerequisites and existing controls.  





  • Reproduce or safely validate material findings when needed using vendor advisories, proof-of-concept analysis, logs, configuration evidence, package inspection and non-production testing.  






  • Document defensible disposition evidence and prevent unsupported suppression of findings or indefinite exception status.  





  • Monitor vulnerability intelligence and vendor advisories for cloud, Kubernetes, Linux, networking, broadband/CPE, open- source and commercial technologies used by the company.  



Risk-based prioritization and response  






  • Use CVSS as a severity input , not a standalone risk decision , and enrich prioritization with CISA Known Exploited Vulnerabilities, EPSS, exploit availability, exposure, reachability, asset criticality, tenant/customer impact and compensating controls.  





  • Define remediation and mitigation targets by risk tier; rapidly escalate actively exploited or internet-reachable vulnerabilities and coordinate emergency response when .  





  • Create clear remediation records with affected assets, evidence, owners, due dates, recommended actions, validation criteria and customer or operational considerations.  





  • Partner with Engineering and DevOps on patches, upgrades, configuration changes, image rebuilds, dependency updates, firmware releases and compensating controls; verify closure through rescans or equivalent evidence.  





  • Manage risk exceptions with documented rationale, accountable approval, compensating controls, expiration dates and scheduled reassessment.  



Cloud-to-CPE security context  






  • Understand the end-to-end service path from cloud control plane and APIs through messaging, device-management protocols and access networks to broadband gateways, routers, ONTs and connected-home devices.  





  • Assess vulnerabilities in the context of multi-tenant cloud services, remote device management, certificates and secrets, provisioning, telemetry, firmware delivery, administrative interfaces and fleet-scale exposure.  





  • Work with Engineering to identify affected device models, hardware revisions, firmware branches, software components and deployed cohorts; support safe remediation planning and rollout validation.  





  • Recognize the different evidence and remediation paths for cloud software, third-party dependencies, network appliances, embedded Linux and customer-deployed CPE.  



Program operations, automation and reporting  






  • Build integrations and automation for asset enrichment, deduplication, risk scoring, ticket creation, ownership routing, SLA tracking, notifications, rescans, exception expiry and evidence collection.  





  • Maintain dashboards for coverage, exploitable exposure, aging, remediation performance, repeat findings, exceptions, asset ownership and risk trends by service, customer, product and device cohort.  





  • Develop playbooks, standards and procedures for routine vulnerability handling, critical CVEs, zero-day response, scanner administration and tool outages.  





  • Provide concise reporting to technical owners and leaders, separating raw finding volume from material risk and clearly identifying decisions or overdue actions.  





  • Support audits and customer security inquiries with traceable evidence while protecting sensitive vulnerability and customer information.  



Required qualifications  








  • 5+ years of hands-on experience in vulnerability management, vulnerability assessment, security engineering, product security, cloud security or a closely related discipline.  





  • Demonstrated ownership of enterprise scanning and vulnerability-management workflows, including scanner configuration, authenticated scanning, coverage analysis, finding validation, false-positive handling, remediation tracking and rescanning.  





  • Strong CVE analysis skills and the ability to determine applicability and exploitability using versions, configurations, exposure, reachability, privileges, controls and business context.  





  • Experience with one or more enterprise vulnerability platforms and practical familiarity with complementary cloud, container, dependency, application and open-source scanning tools.  





  • Working knowledge of CVE/CWE, NVD, CVSS, CISA KEV, EPSS, vendor advisories, software bills of materials and risk-based prioritization.  





  • Hands-on knowledge of Linux, TCP/IP, DNS, TLS/PKI, identity and access controls, APIs, cloud infrastructure, containers and Kubernetes.  





  • Ability to read code, package manifests, container images, configurations, logs and network evidence sufficiently to validate findings and guide remediation.  





  • Scripting or programming ability in Python, Go, PowerShell, Bash or a comparable language, plus experience integrating security platforms with APIs, ticketing and dashboards.  





  • Strong written and verbal communication, including the ability to explain technical risk, uncertainty, tradeoffs and required decisions to engineers and operational leaders.  





  • Bachelor’s degree in cybersecurity, computer science, engineering or equivalent practical experience.  



Preferred qualifications  






  • Security experience with service providers, broadband operators, telecom equipment/software vendors, managed-network providers or large distributed device fleets.  





  • Experience assessing embedded Linux, firmware, broadband gateways, routers, ONTs, Wi-Fi/mesh systems or other CPE/IoT products.  





  • Familiarity with TR-069/CWMP, TR-369/USP, TR-181, ACS/USP controllers, device provisioning, telemetry, certificates and remote firmware lifecycle management.  





  • Experience with Google Cloud Platform, Kubernetes, Terraform, Helm, CI/CD and cloud-native security posture or workload-protection platforms.  





  • Experience with software composition analysis, SBOM/VEX, container/image scanning, secret scanning, SAST/DAST/API security testing and infrastructure-as-code scanning.  





  • Experience with coordinated vulnerability disclosure, penetration-test finding intake, zero-day response or product security incident response.  





  • Familiarity with NIST Cybersecurity Framework, NIST SP 800-40, CIS Controls, OWASP guidance, PCI DSS, SOC 2 or ISO 27001 control expectations.  





  • Relevant certifications such as Security+, CySA +, GSEC, GCIH, GPEN, CISSP, CCSP or vendor-specific vulnerability-management credentials; practical expertise is valued more than certification alone.  



Working expectations  








  • Work primarily during normal business hours with escalation availability for critical, actively exploited or zero-day vulnerabilities.  





  • Handle sensitive vulnerability, exploit and customer information with strict need-to-know access and evidence controls.  





  • Coordinate intrusive scans, validation tests and production-impacting work through approved change and maintenance processes.  





  • Challenge scanner results and remediation claims constructively while maintaining clear evidence , ownership and deadlines.  



 

Type: Contract

Compensation: CAD 60/hr - CAD 90/hr

 

Join AXON Networks!

At AXON Networks, we promote equal opportunities in all our recruitment processes, ensuring non-discrimination on the basis of gender, age, origin, disability, or any other personal circumstances. We assess talent based on objective criteria and foster an inclusive and diverse working environment.

Vacancy posted 16 hours ago
Similar jobs that could be interesting for youBased on the Security Specialist, Vulnerability Management (Canada - Remote) in Toronto, ON vacancy
  • $165k - $200k per year

     ...Director of IT Security — Job Description Directive Consulting is the leading...  ...strategy across our fully remote workforce operating in the United States, Canada, Mexico and the United Kingdom....  ...industry best practices. Risk Management and Threat Assessments: Conduct... 
    Remote job
    Full time
    Work at office
    Home office

    Directive Corporation

    Toronto, ON
    23 hours ago
  •  ...We are seeking a cybersecurity specialist to develop, standardize, and operationalize enterprise vulnerability hardening standards across infrastructure, cloud...  ...cybersecurity, with focus on: ~ Vulnerability Management / Hardening / Secure Configuration Strong experience... 
    Suggested

    Integriti Group Inc.

    Toronto, ON
    10 days ago
  • $130k - $145k per year

     ...health data platform and data management solutions, which are used in over...  ...to SMILE! The Cloud Security Engineer is responsible for designing...  ..., implement and maintain a secure and scalable infrastructure...  ...of the benefits we offer: * Remote Work Environment * Flexible... 
    Remote job
    Full time
    Flexible hours

    Smile Digital Health

    Toronto, ON
    23 hours ago
  •  ...Key Responsibilities: Own end-to-end vulnerability remediation operations. Lead...  ...through Microsoft Defender Vulnerability Management. Review exposure scores vulnerability...  ...Citrix Engineers. Coordinate with Security Infrastructure Application Owners and Customer... 
    Suggested
    Full time

    Astra North Infoteck Inc.

    Toronto, ON
    23 days ago
  • $100 - $150 per hour

     ...Contract Compensation: $100–$150/hour Location: Remote Duration: 2–3 week engagement Commitment: 20+...  ...POC exploit development to determine boundaries between security research and malicious intent. Provide ground-truth labels... 
    Remote work
    Hourly pay
    Weekly pay
    Full time
    Contract work
    For contractors
    Summer work

    Mercor

    Toronto, ON
    23 hours ago
  •  ...these technologies give ISPs the ability to manage and troubleshoot their networks in real...  ...DevOps, QA, Database Engineering, Product and Security.     Role mandate   ~ Build and...  ...with TR-069, TR-369 (USP), or similar remote device management protocols.   ~ Experience... 
    Remote job
    Full time
    Contract work

    Axon-networks

    Toronto, ON
    23 hours ago
  • $105k per year

    ** EventMobi is a remote-first company and this is a fully remote position. You may reside anywhere in Canada provided you are able to accommodate EST working hours.  WHY YOU SHOULD...  .... WHAT YOUR WORK WILL FOCUS ON: Manage a pipeline of existing customer business to... 
    Remote job
    Long term contract
    Full time
    Summer work
    Work from home

    Eventmobi

    Toronto, ON
    23 hours ago
  • $55 - $80 per hour

     ...technologies. Together, these technologies give ISPs the ability to manage and troubleshoot their networks in real time, and to deliver an...  ..., DevOps, Engineering, QA, and other teams for each activity. Secure resource commitments (primary + backup) and track coverage... 
    Remote job
    Full time
    Contract work
    Shift work
    Afternoon shift

    Axon-networks

    Toronto, ON
    23 hours ago
  • $81.6k - $115.2k per year

     ...Work Location: Toronto Ontario Canada Hours: 37.5 Line of Business: Technology Solutions...  ...This Role: As a Senior Information Security Analyst at TD Bank you will be a member of the Enterprise Vulnerability Management (EVM) Governance team and support the... 
    Full time
    Work from home

    TD Bank

    Toronto, ON
    23 days ago
  • $70 - $90 per hour

     ...Compensation: $70–$90/hour Location: Remote Role Responsibilities Analyze and review content for security vulnerabilities with a focus on pattern recognition and...  .... ~ Currently based in the U.S., Canada, UK, Australia, or New Zealand . ~ Ability... 
    Remote work
    Full time
    Contract work
    Summer work
    Flexible hours

    Mercor

    Toronto, ON
    23 hours ago
  • $100k - $125k per year

     ...innovative health data platform and data management solutions, which are used in over 20 countries...  ...features are technically feasible, secure, and aligns with agile methodology and long...  ...Some of the benefits we offer: * Remote Work Environment * Flexible Time Away From... 
    Remote job
    Long term contract
    Remplacement
    Full time
    Internship
    Flexible hours

    Smile Digital Health

    Toronto, ON
    23 hours ago
  • $114k - $164k per year

     ...®, seven years in a row! As a Senior Infrastructure Security Specialist , you will play a key role in protecting Kepler's corporate...  ...core infrastructure security capabilities, including vulnerability management, security monitoring and SIEM, endpoint security, infrastructure... 
    Remote work
    Full time
    Contract work
    Internship
    Work at office
    Relocation package

    Kepler Communications Inc.

    Toronto, ON
    23 hours ago
  •  ...being of Canadians. As a leading wealth management organization, we are committed to...  ...We’re looking for an experienced Security GRC Specialist to join our growing Security GRC team...  ...stay updated on emerging threats and vulnerabilities ~ Proactiveness, natural curiosity... 
    Full time
    Internship

    Aviso Wealth

    Toronto, ON
    23 hours ago
  • $65k - $80k per year

    ** EventMobi is a remote-first company and this is a fully remote position. You may reside anywhere in Canada provided you are able to accommodate Eastern time working hours....  ...technology trends. As an Event Success Manager at EventMobi, you’ll play a key role in empowering... 
    Remote job
    Long term contract
    Full time
    Summer work
    Work from home
    Worldwide
    Afternoon shift

    Eventmobi

    Toronto, ON
    23 hours ago
  •  ...is listed internally as Demand Generation Manager * About The Role We are looking to...  ...Work Environment Requirements As a remote-first company, you’ll have the ability to...  ...we have established businesses, including Canada, the UK, and Australia. For global locations... 
    Remote job
    Full time
    Work at office
    Home office

    Directive Corporation

    Toronto, ON
    23 hours ago
  • $60 - $95 per hour

     ...technologies give ISPs the ability to manage and troubleshoot their...  ...fragmented operational data into secure, maintainable capabilities...  ...audit logging, secure coding and vulnerability remediation.   ~ Create...  ...controllers, device telemetry and remote lifecycle management.   ~... 
    Remote job
    Contract work

    Axon-networks

    Toronto, ON
    4 hours ago
  •  ...better working world for all. We are actively seeking a Cloud Security Manager to join our Cybersecurity team. You’ll work alongside...  ...and identity management, threat detection, incident response, vulnerability management, security governance, risk and compliance, security... 
    Long term contract
    Shift work
    Weekend work

    Ernst & Young

    Toronto, ON
    18 days ago
  •  ...Job Responsibility: Location: Toronto, Canada Thales people architect solutions that...  ...countries are controlled by our Traffic Management Systems. Together We deployed the first...  ...Transport family, here in Toronto! The Cyber Security Specialist ensures consistency of project... 
    Full time
    Work at office
    Worldwide

    Thales

    Toronto, ON
    3 days ago
  •  ...automation environment. What You’ll Do: Manage and mentor a team of Revenue Operations...  ...Work Environment Requirements As a remote-first company, you’ll have the ability to...  ...we have established businesses, including Canada, Mexico, and the UK. For global locations,... 
    Remote job
    Full time
    Work at office
    Work from home
    Home office

    Directive Corporation

    Toronto, ON
    23 hours ago
  • $110k - $150k per year

     ...you! We are looking for a Security Engineer to join our IT Team...  ...-wide information security management program to ensure information...  ...Manage day-to-day threat and vulnerability management, including detection...  ....   Work Your Way   • Remote-first setup for added... 
    Remote job
    Full time
    Work at office
    Home office
    Flexible hours
    Weekend work

    Zensurance

    Toronto, ON
    23 hours ago
  •  ...The Sr. Security Specialist will support and deliver on multiple initiatives related to Security...  ...processes development and security risk management procedures. Must haves:...  ...understanding of typical security threats, vulnerabilities and safeguards relevant to IT systems.... 
    Full time

    Maarut Inc

    Toronto, ON
    23 hours ago
  •  ...potential attack vectors and security gaps. Reviewing system architecture...  ...In-depth knowledge of risk management frameworks (e.g., ISO 31000,...  ...and prioritizing threats and vulnerabilities across physical, cyber, and...  ...of attack vectors to inform secure design decisions and guide... 
    Full time

    Maarut Inc

    Toronto, ON
    23 hours ago
  •  ...The Security Specialist for Threat Risk Assessment, Threat Modelling, Vulnerability Assessment, Risk Identification will develop new workflows and contribute to the growth and maturity of the Security Risk Management and Information Security Office growth and maturity... 
    Full time
    Work at office

    Maarut Inc

    Toronto, ON
    23 hours ago
  • $80 - $160 per hour

     ...Position: Real Estate / Property Professionals Type: Contract Compensation: $80–$160/hour Location: Remote Role Responsibilities Review and assess domain-specific documents to ensure quality and accuracy. Provide structured... 
    Remote work
    Full time
    Contract work
    Summer work

    Mercor

    Toronto, ON
    23 hours ago
  • $70 - $90 per hour

     ...'Angelo , Larry Summers , and Jack Dorsey . Position: Wealth Management and Asset Management Specialist Type: Contract Compensation: $70–$90/hour Location: Remote Role Responsibilities Review and evaluate AI-generated outputs... 
    Remote work
    Full time
    Contract work
    Summer work
    Work at office

    Mercor

    Toronto, ON
    23 hours ago
  • $80 - $120 per hour

     ...Angelo , Larry Summers , and Jack Dorsey . Position: Procurement / vendor management Evaluator Type: Contract Compensation: $80–$120/hour Location: Remote Role Responsibilities Evaluate AI-generated artifacts against domain-... 
    Remote work
    Full time
    Contract work
    Summer work
    Work at office

    Mercor

    Toronto, ON
    23 hours ago
  •  ...employees and contractors across the US and Canada, and we need someone who keeps our...  ...Role We're hiring a part-time Payroll Specialist to own payroll operations for our Canadian...  ...~ Comfortable working independently in a remote team and walking others through your process... 
    Remote job
    Hourly pay
    Full time
    Contract work
    Part time
    For contractors
    Flexible hours

    Heymilo

    Toronto, ON
    23 hours ago
  • $101.15k - $130.9k per year

     ...Function: The Senior Cybersecurity Specialist, GRC Risk Management is a senior advisor responsible for...  ..., technology, compliance, and security architecture stakeholders to identify...  ...standards, as well as the threat and vulnerability landscape for Industrial Control Systems... 

    Hydro One Networks Inc

    Toronto, ON
    6 days ago
  •  ...Description To qualify for this role, you must currently reside in Ontario, Canada. We are looking for a data administrator/specialist that can help our team of data scientists and engineers manage, clean and curate data from a variety of sources. Your day to day job can... 
    Remote work
    Full time
    Work at office

    Ample Insight

    Toronto, ON
    23 hours ago
  •  ...transform how people save, spend, and manage their money. Today, our...  ...a growing portfolio of specialist financial and software businesses...  ...Analysts to join our growing cyber security function. This role will be...  ...visa sponsorship for any role in Canada at this moment in time.... 
    Full time
    Worldwide
    Visa sponsorship
    Work visa
    Flexible hours

    Starling Bank

    Toronto, ON
    23 hours ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Security Specialist, Vulnerability Management (Canada - Remote). Be the first to apply!