Vulnerability Management Analyst

Posted 10 Days Ago
Be an Early Applicant
Montréal, QC
Senior level
Aerospace
The Role
Responsible for coordinating and managing the timely remediation of security vulnerabilities across various technologies using vulnerability assessment tools such as Rapid7, Burp Suite, SonarSource, Qualys, and Mend. Must have a minimum of 5 years of hands-on experience in the information security domain.
Summary Generated by Built In

About This Role

Your main role and responsibilities

  • Be an individual contributor and a great team player with a mindset to improve and support the business.
  • Co-ordinate and manage timely remediation of security vulnerabilities across various technologies.
  • Identify, resolve, and document any false positive findings in vulnerability assessment results.
  • Have a good hands-on knowledge with Rapid7 architecture, scan engines, collector servers, agents, query builder, goals, and projects.
  • Collaborate with application teams and business unit owners to submit risk letters to comply with the organization's IT Security and Risk Management Framework.
  • Perform weekly/monthly and ad-hoc vulnerability assessments for servers, user systems, network assets, public-facing assets and databases using Rapid7, Burp Suite, SonarSource, Qualys, or Mend.
  • Manage scan configurations, including asset grouping and appropriate authentication; update scan templates; update scan engine pool; and schedule scans and reports.
  • Manage and troubleshoot vulnerability management tools.
  • Monitor overall vulnerability scan status, engine health check, report generation and ensure successful scan completion with proper authentication.
  • Troubleshoot scans for any missing assets and assets scanned with improper authentication or authentication failure.
  • Open support case with scanning tools vendor for appropriate support.
  • Demonstrate good hands-on working experience with DAST, SAST & SCA tools.
  • Track vulnerability remediation via ticketing system and perform validation by ad hoc scans.
  • Coordinate with the core network, endpoint teams and server teams to discuss patches that are not applied for a longer time, target patch level, CVEs covered by the corresponding patches.
  • Be knowledgeable of the Common Vulnerability Scoring System (CVSS) vulnerability assessment method, operation concepts and corrective updates.
  • Have good knowledge of web application vulnerabilities, assessment tools and methodologies.
  • Have a minimum of 3 years of hands-on experience working with above said vulnerability tools and 5 to 8 years of experience in the information security domain.
  • CEH, Rapid7 Certified Administrator (Mandatory), Qualys Certification (Mandatory), Security+, ITIL or other security certifications are required.
  • Job offer is based on the positive screening & interview along with the positive background & reference check.
  • This position is only open to candidates who are physically present in Canada at the time of application and are Canadian citizens or permanent residents.
  • This job is not open to candidates on a Work Visa/Work Permit.

Position Type

Regular

CAE thanks all applicants for their interest. However, only those whose background and experience match the requirements of the role will be contacted.

Equal Opportunity Employer 

CAE is an equal-opportunity employer committed to diversity, equity, and inclusion. As "One CAE," we take affirmative action to ensure equal opportunity for all applicants regardless of race, nationality, colour, religion, sex, gender identity and expression, sexual orientation, disability, neurodiversity, Veteran status, age, or other legally protected characteristics.

 

If you don't see yourself fully reflected in every job requirement listed in the job posting, we still encourage you to reach out and apply. At CAE, everyone is welcome to contribute to our success. If reasonable accommodation is needed to participate in the job application or interview process, please get in touch with us at [email protected].

Top Skills

Burp Suite
Mend
Qualys
Rapid7
Sonarsource
The Company
HQ: Montreal, Quebec
10,806 Employees
On-site Workplace
Year Founded: 1947

What We Do

CAE is a high technology company, at the leading edge of digital immersion, providing solutions to make the world a safer place. Backed by a record of 75 years of industry firsts, we continue to reimagine the customer experience and revolutionize training and operational support solutions in civil aviation, defense and security, and healthcare. We are the partner of choice to customers worldwide who operate in complex, high-stakes and largely regulated environments, where successful outcomes are critical. Testament to our customers’ ongoing needs for our solutions, over 60 percent of CAE’s revenue is recurring in nature. We have the broadest global presence in our industry, with approximately 13,000 employees, 180 sites and training locations in over 35 countries

Similar Jobs

Pfizer Logo Pfizer

Analytics Manager - Solution and Service Management​

Artificial Intelligence • Healthtech • Machine Learning • Natural Language Processing • Biotech • Pharmaceutical
Hybrid
Kirkland, QC, CAN
121990 Employees

ServiceNow Logo ServiceNow

Senior Applied Research Scientist LLM Evaluation

Artificial Intelligence • Cloud • HR Tech • Information Technology • Productivity • Software • Automation
Hybrid
Montréal, QC, CAN
26000 Employees

ServiceNow Logo ServiceNow

Manager, Research Scientist Management

Artificial Intelligence • Cloud • HR Tech • Information Technology • Productivity • Software • Automation
Hybrid
Montréal, QC, CAN
26000 Employees

ServiceNow Logo ServiceNow

Staff Applied Research Scientist

Artificial Intelligence • Cloud • HR Tech • Information Technology • Productivity • Software • Automation
Hybrid
Montréal, QC, CAN
26000 Employees

Similar Companies Hiring

EchoStar Thumbnail
Retail • News + Entertainment • Mobile • Information Technology • Digital Media • Cloud • Aerospace
Englewood, CO
14500 Employees
York Space Systems Thumbnail
Manufacturing • Defense • Cybersecurity • Aerospace
Greenwood Village , CO
Doodle Labs Thumbnail
Wearables • Robotics • Internet of Things • Hardware • Automation • App development • Aerospace
Los Angeles, CA
50 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account