Security Specialist, Vulnerability Management
Vulnerability ManagementCloud SecurityKubernetesPythonGoPowerShellBashCVE analysisNetwork Securitysecurity frameworks
About the Role
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Security Specialist, Vulnerability Management based in Canada. This fully remote role offers the opportunity to build and operate a comprehensive, risk-based vulnerability management program across a complex technology environment. You will help protect cloud platforms, applications, Kubernetes and container environments, network infrastructure, software supply chains, and connected customer devices. The role is highly hands-on, requiring the ability to distinguish meaningful, exploitable vulnerabilities from scanner noise and prioritize remediation based on real-world risk. You will own the vulnerability lifecycle from discovery and validation through remediation, rescanning, reporting, and risk acceptance. Working closely with Engineering, DevOps, NOC, Product, Support, and Compliance teams, you will help reduce measurable security exposure without compromising service reliability. This is an excellent opportunity for a security engineer who combines strong technical depth with sound judgment, automation skills, and the ability to communicate risk clearly. This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Security Specialist, Vulnerability Management based in Canada. This fully remote role offers the opportunity to build and operate a comprehensive, risk-based vulnerability management program across a complex technology environment. You will help protect cloud platforms, applications, Kubernetes and container environments, network infrastructure, software supply chains, and connected customer devices. The role is highly hands-on, requiring the ability to distinguish meaningful, exploitable vulnerabilities from scanner noise and prioritize remediation based on real-world risk. You will own the vulnerability lifecycle from discovery and validation through remediation, rescanning, reporting, and risk acceptance. Working closely with Engineering, DevOps, NOC, Product, Support, and Compliance teams, you will help reduce measurable security exposure without compromising service reliability. This is an excellent opportunity for a security engineer who combines strong technical depth with sound judgment, automation skills, and the ability to communicate risk clearly. Accountabilities: Establish comprehensive visibility across cloud, application, container, Kubernetes, network, endpoint, dependency, firmware, and customer-premises equipment environments, covering both internal and internet-facing assets. Design, configure, and maintain authenticated and unauthenticated vulnerability scans, agent-based assessments, cloud-native checks, container and dependency scans, attack-surface discovery, and targeted validation activities. Evaluate and administer vulnerability-management and security-testing platforms, integrating multiple tools to provide effective coverage rather than relying on a single technology. Define safe scanning procedures, credentials, rate limits, exclusions, maintenance windows, and testing processes to minimize impact on production systems and customer environments. Review and validate vulnerability findings, distinguishing true positives, false positives, duplicates, accepted risks, mitigated conditions, and actionable vulnerabilities. Analyze CVEs using affected versions, configurations, package provenance, firmware or software inventories, runtime reachability, network exposure, privileges, exploit prerequisites, and existing security controls. Prioritize remediation using technical severity, known exploitation, exploit availability, exposure, reachability, asset criticality, customer impact, and compensating controls. Establish remediation targets by risk level, escalate actively exploited or internet-facing vulnerabilities, and coordinate emergency response when necessary. Partner with Engineering and DevOps teams on patches, upgrades, configuration changes, dependency updates, container rebuilds, firmware releases, and compensating controls, while verifying remediation through rescans or equivalent evidence. Manage vulnerability exceptions with documented rationale, appropriate approvals, compensating controls, expiration dates, and scheduled reassessments. Assess security risks across the complete cloud-to-device environment, including APIs, device-management protocols, access networks, gateways, routers, ONTs, and connected-home devices. Identify affected device models, hardware revisions, firmware branches, software components, and deployed customer cohorts, supporting safe remediation planning and rollout validation. Build automation and integrations for asset enrichment, deduplication, risk scoring, ticket creation, ownership routing, SLA tracking, notifications, rescanning, exception management, and evidence collection. Maintain dashboards and reporting covering vulnerability coverage, exploitable exposure, aging, remediation performance, repeat findings, exceptions, ownership, and risk trends. Develop operating standards, playbooks, and procedures for vulnerability handling, critical CVEs, zero-day response, scanner administration, and tool outages. Provide clear reporting to technical and executive stakeholders, distinguishing raw vulnerability volumes from material business risk and highlighting overdue actions or required decisions. Support audits and customer security inquiries with traceable evidence while maintaining strict controls over sensitive vulnerability and customer information. Requirements 5+ years of hands-on experience in vulnerability management, vulnerability assessment, security engineering, product security, cloud security, or a closely related discipline. Demonstrated experience owning enterprise vulnerability-management workflows, including scanner configuration, authenticated scanning, coverage analysis, finding validation, false-positive management, remediation tracking, and rescanning. Strong CVE analysis capabilities, with the ability to assess applicability and exploitability based on versions, configurations, exposure, reachability, privileges, controls, and business context. Experience with enterprise vulnerability platforms and practical familiarity with complementary cloud, container, dependency, application, and open-source security scanning tools. Working knowledge of CVE/CWE, NVD, CVSS, CISA Known Exploited Vulnerabilities, EPSS, vendor advisories, software bills of materials, and risk-based prioritization. Hands-on understanding of Linux, TCP/IP, DNS, TLS/PKI, identity and access controls, APIs, cloud infrastructure, containers, and Kubernetes. Ability to review code, package manifests, container images, configurations, logs, and network evidence to validate findings and guide remediation. Scripting or programming experience with Python, Go, PowerShell, Bash, or a comparable language, as well as experience integrating security platforms with APIs, ticketing systems, and dashboards. Strong written and verbal communication skills, with the ability to explain technical risk, uncertainty, trade-offs, and remediation decisions to engineers, operational teams, and leadership. Bachelor's degree in cybersecurity, computer science, engineering, or equivalent practical experience. Experience with service providers, broadband operators, telecommunications technology, managed networks, or large distributed device fleets is an asset. Familiarity with embedded Linux, firmware, broadband gateways, routers, ONTs, Wi-Fi/mesh systems, IoT, or other customer-premises equipment is an advantage. Knowledge of TR-069/CWMP, TR-369/USP, TR-181, device provisioning, telemetry, certificates, and remote firmware lifecycle management is considered an asset. Experience with Google Cloud Platform, Kubernetes, Terraform, Helm, CI/CD, and cloud-native security posture or workload-protection platforms is preferred. Experience with software composition analysis, SBOM/VEX, container and image scanning, secret scanning, SAST/DAST, API security testing, or infrastructure-as-code scanning is valuable. Familiarity with coordinated vulnerability disclosure, penetration-test findings, zero-day response, or product security incident response is a plus. Knowledge of security frameworks and standards such as NIST Cybersecurity Framework, NIST SP 800-40, CIS Controls, OWASP, PCI DSS, SOC 2, or ISO 27001 is advantageous. Relevant certifications such as Security+, CySA+, GSEC, GCIH, GPEN, CISSP, CCSP, or vendor-specific vulnerability-management credentials are welcome, although practical expertise is valued more highly than certification alone. Strong ownership, analytical thinking, prioritization, and problem-solving abilities, with the confidence to challenge scanner results and remediation claims constructively while maintaining clear evidence, accountability, and deadlines. Availability to work primarily during normal business hours, with escalation availability for critical, actively exploited, or zero-day vulnerabilities. Ability to manage sensitive vulnerability, exploit, and customer information according to strict need-to-know and evidence-control requirements. Benefits Contract position with an hourly compensation range of CAD $60–$90 per hour , depending on experience and expertise. Fully remote position available across Canada. Opportunity to work on a broad and technically complex security environment spanning cloud, applications, Kubernetes, networking, software supply chains, firmware, and connected devices. High-impact role with significant ownership in establishing and maturing a company-wide vulnerability management capability. Cross-functional collaboration with engineering, DevOps, operations, product, support, and compliance teams. Opportunity to work with modern security technologies and vulnerability-management platforms across multiple security domains. Inclusive and diverse working environment with a commitment to equal opportunity and objective, skills-based recruitment. How Jobgether works: We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team. We appreciate your interest and wish you the best! Why Apply Through Jobgether? Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time. #LI-CL1
You'll be redirected to Jobgether's application page
Job Details
Salary
$60K–$90K
Location
Canada
Job type
Full-time
Category
Security Engineering
Experience
5+ years
Posted
Today
Job Highlights
- $60K–$90K salary
- 5+ years level role
- 100% Remote — open to candidates in Canada
About Jobgether
This job is hosted by Jobgether. Clicking Apply opens their site.
Remote Work Style
Mixed
Mix of flexible and scheduled meetings
Your Match
See how well your skills line up with this role, and what you're missing.
AI Cover Letter
Generate a cover letter tailored to this job from your profile.