CAE Logo

CAE

Vulnerability Management Analyst

Posted 20 Days Ago
Be an Early Applicant
5 Locations
Senior level
5 Locations
Senior level
As a Vulnerability Management Analyst, you will manage vulnerability remediation, conduct assessments, troubleshoot tools, and collaborate with teams while ensuring compliance with security frameworks.
The summary above was generated by AI

About This Role

                                                                                                         

Your main role and responsibilities

  • Be an individual contributor and a great team player with a mindset to improve and support the business.
  • Co-ordinate and manage timely remediation of security vulnerabilities across various technologies.
  • Identify, resolve, and document any false positive findings in vulnerability assessment results.
  • Have a good hands-on knowledge with Rapid7 architecture, scan engines, collector servers, agents, query builder, goals, and projects.
  • Collaborate with application teams and business unit owners to submit risk letters to comply with the organization's IT Security and Risk Management Framework.
  • Perform weekly/monthly and ad-hoc vulnerability assessments for servers, user systems, network assets, public-facing assets and databases using Rapid7, Burp Suite, SonarSource, Qualys, or Mend.
  • Manage scan configurations, including asset grouping and appropriate authentication; update scan templates; update scan engine pool; and schedule scans and reports.
  • Manage and troubleshoot vulnerability management tools.
  • Monitor overall vulnerability scan status, engine health check, report generation and ensure successful scan completion with proper authentication.
  • Troubleshoot scans for any missing assets and assets scanned with improper authentication or authentication failure.
  • Open support case with scanning tools vendor for appropriate support.
  • Demonstrate good hands-on working experience with DAST, SAST & SCA tools.
  • Track vulnerability remediation via ticketing system and perform validation by ad hoc scans.
  • Coordinate with the core network, endpoint teams and server teams to discuss patches that are not applied for a longer time, target patch level, CVEs covered by the corresponding patches.
  • Be knowledgeable of the Common Vulnerability Scoring System (CVSS) vulnerability assessment method, operation concepts and corrective updates.
  • Have good knowledge of web application vulnerabilities, assessment tools and methodologies.
  • Have a minimum of 3 years of hands-on experience working with above said vulnerability tools and 5 to 8 years of experience in the information security domain.
  • CEH, Rapid7 Certified Administrator (Mandatory), Qualys Certification (Mandatory), Security+, ITIL or other security certifications are required.
  • Job offer is based on the positive screening & interview along with the positive background & reference check.
  • This position is only open to candidates who are physically present in Canada at the time of application and are Canadian citizens or permanent residents.
  • This job is not open to candidates on a Work Visa/Work Permit.

Position Type                       

Regular

CAE thanks all applicants for their interest. However, only those whose background and experience match the requirements of the role will be contacted.

Equal Opportunity Employer 

CAE is an equal-opportunity employer committed to diversity, equity, and inclusion. As "One CAE," we take affirmative action to ensure equal opportunity for all applicants regardless of race, nationality, colour, religion, sex, gender identity and expression, sexual orientation, disability, neurodiversity, Veteran status, age, or other legally protected characteristics.  

 

If you don't see yourself fully reflected in every job requirement listed in the job posting, we still encourage you to reach out and apply. At CAE, everyone is welcome to contribute to our success. If reasonable accommodation is needed to participate in the job application or interview process, please get in touch with us at [email protected].

Top Skills

Burp Suite
Common Vulnerability Scoring System (Cvss)
Mend
Qualys
Rapid7
Sonarsource
HQ

CAE Montréal, Québec, CAN Office

Montréal, Quebec, Canada

Similar Jobs

3 Days Ago
32 Locations
Mid level
Mid level
Fintech • Payments • Financial Services
The Vulnerability Management Analyst will oversee penetration testing, coordinate remediation efforts, conduct scans, and prepare security reports to improve security processes.
Top Skills: CveCvssCweCybersecurityNessusNvdOwaspQualysRapid7 Insight VmVulnerability Management
11 Days Ago
Remote
4 Locations
Mid level
Mid level
Cloud • HR Tech • Information Technology
The Vulnerability Management Analyst identifies and manages security vulnerabilities, conducts scans, analyzes risks, collaborates with teams for remediation, and assesses security posture.
Top Skills: AWSAzureEdrGCPPowershellPythonQualysSIEMTenable Nessus
18 Days Ago
Mississauga, ON, CAN
Senior level
Senior level
Healthtech • Biotech • Pharmaceutical
The Cybersecurity Analyst will assess and manage vulnerabilities in web applications, ensuring network and user safety while collaborating with various teams on security issues.
Top Skills: JavaScriptPowershellPythonServicenowSIEMSplunk SplTenableVulnerability Scanning Tools

What you need to know about the Montreal Tech Scene

With roots dating back to 1642, Montreal is often recognized for its French-inspired architecture and cobblestone streets lined with traditional shops and cafés. But what truly sets the city apart is how it blends its rich tradition with a modern edge, reflected in its evolving skyline and fast-growing tech industry. According to economic promotion agency Montréal International, the city ranks among the top in North America to invest in artificial intelligence, making it le spot idéal for job seekers who want the best of both worlds.

Key Facts About Montreal Tech

  • Number of Tech Workers: 255,000+ (2024, Tourisme Montréal)
  • Major Tech Employers: SAP, Google, Microsoft, Cisco
  • Key Industries: Artificial intelligence, machine learning, cybersecurity, cloud computing, web development
  • Funding Landscape: $1.47 billion in venture capital funding in 2024 (BetaKit)
  • Notable Investors: CIBC Innovation Banking, BDC Capital, Investissement Québec, Fonds de solidarité FTQ
  • Research Centers and Universities: McGill University, Université de Montréal, Concordia University, Mila Quebec, ÉTS Montréal

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account