JobTarget Logo

Security Specialist, Vulnerability Management in Canada Creek, Nova Scotia at Jobgether

NewJob Function: Information Technology
Jobgether
Canada Creek, Nova Scotia, B0P 1V0, Canada
Posted on
New job! Apply early to increase your chances of getting hired.

Explore Related Opportunities

Job Description

Security Specialist, Vulnerability Management

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Security Specialist, Vulnerability Management based in Canada.

This fully remote role offers the opportunity to build and operate a comprehensive, risk-based vulnerability management program across a complex technology environment. You will help protect cloud platforms, applications, Kubernetes and container environments, network infrastructure, software supply chains, and connected customer devices. The role is highly hands-on, requiring the ability to distinguish meaningful, exploitable vulnerabilities from scanner noise and prioritize remediation based on real-world risk. You will own the vulnerability lifecycle from discovery and validation through remediation, rescanning, reporting, and risk acceptance. Working closely with Engineering, DevOps, NOC, Product, Support, and Compliance teams, you will help reduce measurable security exposure without compromising service reliability. This is an excellent opportunity for a security engineer who combines strong technical depth with sound judgment, automation skills, and the ability to communicate risk clearly.

Accountabilities:
  • Establish comprehensive visibility across cloud, application, container, Kubernetes, network, endpoint, dependency, firmware, and customer-premises equipment environments, covering both internal and internet-facing assets.
  • Design, configure, and maintain authenticated and unauthenticated vulnerability scans, agent-based assessments, cloud-native checks, container and dependency scans, attack-surface discovery, and targeted validation activities.
  • Evaluate and administer vulnerability-management and security-testing platforms, integrating multiple tools to provide effective coverage rather than relying on a single technology.
  • Define safe scanning procedures, credentials, rate limits, exclusions, maintenance windows, and testing processes to minimize impact on production systems and customer environments.
  • Review and validate vulnerability findings, distinguishing true positives, false positives, duplicates, accepted risks, mitigated conditions, and actionable vulnerabilities.
  • Analyze CVEs using affected versions, configurations, package provenance, firmware or software inventories, runtime reachability, network exposure, privileges, exploit prerequisites, and existing security controls.
  • Prioritize remediation using technical severity, known exploitation, exploit availability, exposure, reachability, asset criticality, customer impact, and compensating controls.
  • Establish remediation targets by risk level, escalate actively exploited or internet-facing vulnerabilities, and coordinate emergency response when necessary.
  • Partner with Engineering and DevOps teams on patches, upgrades, configuration changes, dependency updates, container rebuilds, firmware releases, and compensating controls, while verifying remediation through rescans or equivalent evidence.
  • Manage vulnerability exceptions with documented rationale, appropriate approvals, compensating controls, expiration dates, and scheduled reassessments.
  • Assess security risks across the complete cloud-to-device environment, including APIs, device-management protocols, access networks, gateways, routers, ONTs, and connected-home devices.
  • Identify affected device models, hardware revisions, firmware branches, software components, and deployed customer cohorts, supporting safe remediation planning and rollout validation.
  • Build automation and integrations for asset enrichment, deduplication, risk scoring, ticket creation, ownership routing, SLA tracking, notifications, rescanning, exception management, and evidence collection.
  • Maintain dashboards and reporting covering vulnerability coverage, exploitable exposure, aging, remediation performance, repeat findings, exceptions, ownership, and risk trends.
  • Develop operating standards, playbooks, and procedures for vulnerability handling, critical CVEs, zero-day response, scanner administration, and tool outages.
  • Provide clear reporting to technical and executive stakeholders, distinguishing raw vulnerability volumes from material business risk and highlighting overdue actions or required decisions.
  • Support audits and customer security inquiries with traceable evidence while maintaining strict controls over sensitive vulnerability and customer information.
Requirements
  • 5+ years of hands-on experience in vulnerability management, vulnerability assessment, security engineering, product security, cloud security, or a closely related discipline.
  • Demonstrated experience owning enterprise vulnerability-management workflows, including scanner configuration, authenticated scanning, coverage analysis, finding validation, false-positive management, remediation tracking, and rescanning.
  • Strong CVE analysis capabilities, with the ability to assess applicability and exploitability based on versions, configurations, exposure, reachability, privileges, controls, and business context.
  • Experience with enterprise vulnerability platforms and practical familiarity with complementary cloud, container, dependency, application, and open-source security scanning tools.
  • Working knowledge of CVE/CWE, NVD, CVSS, CISA Known Exploited Vulnerabilities, EPSS, vendor advisories, software bills of materials, and risk-based prioritization.
  • Hands-on understanding of Linux, TCP/IP, DNS, TLS/PKI, identity and access controls, APIs, cloud infrastructure, containers, and Kubernetes.
  • Ability to review code, package manifests, container images, configurations, logs, and network evidence to validate findings and guide remediation.
  • Scripting or programming experience with Python, Go, PowerShell, Bash, or a comparable language, as well as experience integrating security platforms with APIs, ticketing systems, and dashboards.
  • Strong written and verbal communication skills, with the ability to explain technical risk, uncertainty, trade-offs, and remediation decisions to engineers, operational teams, and leadership.
  • Bachelor's degree in cybersecurity, computer science, engineering, or equivalent practical experience.
  • Experience with service providers, broadband operators, telecommunications technology, managed networks, or large distributed device fleets is an asset.
  • Familiarity with embedded Linux, firmware, broadband gateways, routers, ONTs, Wi-Fi/mesh systems, IoT, or other customer-premises equipment is an advantage.
  • Knowledge of TR-069/CWMP, TR-369/USP, TR-181, device provisioning, telemetry, certificates, and remote firmware lifecycle management is considered an asset.
  • Experience with Google Cloud Platform, Kubernetes, Terraform, Helm, CI/CD, and cloud-native security posture or workload-protection platforms is preferred.
  • Experience with software composition analysis, SBOM/VEX, container and image scanning, secret scanning, SAST/DAST, API security testing, or infrastructure-as-code scanning is valuable.
  • Familiarity with coordinated vulnerability disclosure, penetration-test findings, zero-day response, or product security incident response is a plus.
  • Knowledge of security frameworks and standards such as NIST Cybersecurity Framework, NIST SP 800-40, CIS Controls, OWASP, PCI DSS, SOC 2, or ISO 27001 is advantageous.
  • Relevant certifications such as Security+, CySA+, GSEC, GCIH, GPEN, CISSP, CCSP, or vendor-specific vulnerability-management credentials are welcome, although practical expertise is valued more highly than certification alone.
  • Strong ownership, analytical thinking, prioritization, and problem-solving abilities, with the confidence to challenge scanner results and remediation claims constructively while maintaining clear evidence, accountability, and deadlines.
  • Availability to work primarily during normal business hours, with escalation availability for critical, actively exploited, or zero-day vulnerabilities.
  • Ability to manage sensitive vulnerability, exploit, and customer information according to strict need-to-know and evidence-control requirements.
Benefits
  • Contract position with an hourly compensation range of CAD $60–$90 per hour, depending on experience and expertise.
  • Fully remote position available across Canada.
  • Opportunity to work on a broad and technically complex security environment spanning cloud, applications, Kubernetes, networking, software supply chains, firmware, and connected devices.
  • High-impact role with significant ownership in establishing and maturing a company-wide vulnerability management capability.
  • Cross-functional collaboration with engineering, DevOps, operations, product, support, and compliance teams.
  • Opportunity to work with modern security technologies and vulnerability-management platforms across multiple security domains.
  • Inclusive and diverse working environment with a commitment to equal opportunity and objective, skills-based recruitment.
How Jobgether works:
We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team.
We appreciate your interest and wish you the best!
Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.
#LI-CL1

Job Location

Canada Creek, Nova Scotia, B0P 1V0, Canada

Frequently asked questions about this position

Similar Jobs In Canada Creek, Nova Scotia

New

Infosec / Compliance Specialist

Jobgether
Canada Creek, Nova Scotia
New

Senior M365 Messaging Specialist

Jobgether
Canada Creek, Nova Scotia
New

AI Security & DevOps Engineer

Jobgether
Canada Creek, Nova Scotia
New

Internal Auditor

Jobgether
Canada Creek, Nova Scotia
New

Presales Security Expert Mid-Market

Jobgether
Canada Creek, Nova Scotia
Continue to apply
Enter your email to continue. You’ll be redirected to the employer’s application.
By clicking Continue, you understand and agree to JobTarget's Terms of Use and Privacy Policy.