Retour à la recherche
Logo de Canada Mortgage and Housing Corporation (CMHC) Société canadienne d'hypothèques et de logement(SCHL)

Specialist, Enterprise Vulnerability Management

Offre en anglais
  • Ottawa, ON
  • Hybride
  • Publié 11 sept. 2026
  • 1 poste

86 817 $–108 521 $ / année

Ouvre un site externe

Connectez-vous pour enregistrer ce poste
Type d’emploi
Temps plein
Niveau d’expérience
Expérimenté · 5+ ans
Formation minimale
Diplôme professionnel
Postuler avant le
11 nov. 2026
Langue de l’offre
anglais
Heures de travail
40 heures par semaine

Résumé du poste

The specialist will operationalize vulnerability management standards and risk methodologies to identify, assess, and remediate security weaknesses across infrastructure and cloud environments. They are responsible for maintaining data integrity, coordinating remediation efforts with technical teams, and providing reports to support security oversight.

Détails du poste

Job Requisition ID: 12428 Position Status: Permanent Full Time Position Type: Hybrid Office Location: Montreal (QC); Ottawa (ON) Travel Requirement: Limited Language Designation: Bilingual Language Skill Levels (Read/Write/Speak): BBB Security Requirement: Secret Salary: Our salaries generally range from $ 86816.59 to $ 108520.74 and are based on qualifications and experience. About CMHC The work you do and the work we do together matters. We come to work every day with a common purpose: to contribute to a well-functioning housing system. At CMHC, we hold ourselves accountable for our results and support our colleagues in their achievements. We thrive on collaboration, connecting across CMHC and involving the right people to get our work done. Our leadership style is guided by trust, where our leaders favour an adaptive approach based on the needs of their teams. Join us and be part of a team that's committed to making a real difference and be part of something meaningful. What’s in it for you We’ve got the purpose, the people and the perks you need for a fulfilling career. Here’s the comprehensive and generous benefits you get when you’re a permanent employee: Annual Paid vacation. Annual individual performance incentive. Defined benefit pension plan. Comprehensive group insurance plan to support your well-being from day one. Support towards your personal and professional growth with training, mentorship and more. An inclusive workplace culture and environment. Members of the following employment equity deserving groups will be prioritized for this job: Indigenous Peoples About the role Join the Security team, in the Specialist, Enterprise Vulnerability Management position. You will provide specialized expertise to apply and operationalize established vulnerability management standards, application security practices, risk methodologies, and threat intelligence to determine appropriate remediation priorities and control actions within established frameworks and defined operating procedures. Accountable for the consistent operational execution and data integrity of the enterprise vulnerability management program across infrastructure, applications, cloud environments, APIs, and software delivery platforms. The role ensures vulnerabilities are identified, assessed, prioritized, tracked, communicated, remediated, and escalated in accordance with established security standards, risk methodologies, and service expectations. The position directly contributes to reducing technology risk by enabling the timely identification, assessment, and remediation of vulnerabilities and by providing reliable vulnerability data to support risk management, compliance, and security oversight. What you'll do: Identify, analyze, and assess vulnerabilities across infrastructure, cloud environments, applications, APIs, containers, and related technologies using security scanning and testing tools. Validate findings through risk assessments by eliminating false positives and determining exploitability, business impact, and overall risk. Classify, prioritize, and maintain accurate vulnerability records using approved risk-rating methodologies, threat intelligence, OWASP guidance, supporting evidence, and remediation tracking. Coordinate remediation efforts with infrastructure, development, architecture, cloud, and technology teams, providing guidance on security controls, secure coding practices, and treatment options. Monitor remediation progress, validate fixes, drive follow-up actions, and escalate overdue, high-risk, or unresolved vulnerabilities through to closure or formal risk acceptance. Support the integration of vulnerability management practices into Agile, DevOps, and DevSecOps workflows while ensuring consistent execution of enterprise standards. Develop and maintain reports, dashboards, metrics, and audit-ready vulnerability data to support risk management, compliance, security investigations, assurance, and oversight activities. Drive continuous improvement by identifying recurring security weaknesses, recommending process and tool enhancements, staying informed on emerging threats, and influencing stakeholders to strengthen security practices and reduce organizational risk exposure. What you should have: An undergraduate degree in Information Technology, Cybersecurity, Computer Science, Software Engineering, Computer Engineering, or a related field, or equivalent experience. A minimum 5 years of experience in information security, vulnerability management, application security, infrastructure security, DevSecOps, or related technology disciplines. A security certification completed or in progress (e.g., Security+, CEH, CSSLP, ISC2 CC, GWAPT, or equivalent) with practical experience supporting cybersecurity and vulnerability management activities. Experience using vulnerability scanning, application security testing, and remediation management tools to identify, assess, and track security weaknesses. A strong understanding of the full vulnerability management lifecycle, including identification, assessment, prioritization, remediation, and validation of vulnerabilities. Knowledge of infrastructure security, cloud security, application security, OWASP Top 10 risks, and common cybersecurity threats and controls. An understanding of Secure Software Development Lifecycle (SSDLC) practices and modern delivery frameworks, including Agile, DevOps, and DevSecOps. Strong analytical, communication, documentation, stakeholder engagement, risk assessment, data management, and issue escalation skills, with the ability to identify recurring vulnerability trends and address systemic risks. Posting closing date: Note, the competition will remain active until filled. Our commitment to diversity, equity, and inclusion We’re committed to employment equity and encourage women, Indigenous Peoples, persons with disabilities, veterans and persons of all races, ethnicities, religions, abilities, sexual orientations, and gender identities and expressions to apply. We also welcome applications from non-Canadians who are eligible to work in Canada. CMHC is an inclusive workplace where diversity of thought – and of people – are recognized, valued, and considered essential to achieving our mission. Learn more about our commitment to diversity and inclusion What happens after you apply We know that applying for a new job can be both exciting and daunting, and we appreciate your effort. Learn more about our hiring process. If you are selected for an interview or testing, please advise us if you require an accommodation. If you applied before and you were not successful don’t worry – we're always posting new positions, so don’t hesitate to give it another shot. We’re excited to see what you bring to the table this time around!

Ce que vous ferez

The specialist will operationalize vulnerability management standards and risk methodologies to identify, assess, and remediate security weaknesses across infrastructure and cloud environments. They are responsible for maintaining data integrity, coordinating remediation efforts with technical teams, and providing reports to support security oversight.

Exigences

Candidates must possess an undergraduate degree in a relevant field and at least 5 years of experience in information security or vulnerability management. A relevant security certification is required, along with strong knowledge of SSDLC, cloud security, and modern delivery frameworks.

Avantages

• Annual paid vacation • Annual individual performance incentive • Defined benefit pension plan • Comprehensive group insurance plan • Training and mentorship support

Compétences indiquées

  • Analyse de données · Souhaitée
  • Compliance · Souhaitée

Autres compétences pertinentes

Relevées dans la description du poste. Confirmez les exigences importantes ci-dessus.

  • Vulnerability management
  • Application security
  • Risk assessment
  • Threat intelligence
  • Infrastructure security
  • Cloud security
  • DevSecOps
  • OWASP Top 10
  • Security scanning
  • Secure coding practices
  • Data analysis
  • Stakeholder engagement
  • Incident escalation
  • Compliance
  • Agile methodologies
  • Cloud Security Applications
  • Security Investigations
  • Application Security Testing
  • Employment Equity
  • Test Tools
  • Workplace Inclusivity
  • Cyber Threat Intelligence
  • Workflow Management
  • GIAC Web Application Penetration Tester
  • Infrastructure Security
  • Application Programming Interface (API)
  • Agile Methodology
  • Application Security
  • Auditing
  • Multilingualism
  • Business Continuity Planning
  • Dashboard
  • Management
  • Certified Ethical Hacker
  • Communication
  • Computer Science
  • CompTIA Security+
  • Computer Engineering
  • Information Technology
  • Continuous Improvement Process
  • Security Controls
  • Cyber Security
  • Data Integrity
  • Data Management
  • Software Development Life Cycle
  • DevOps
  • GIAC Certifications
  • Leadership
  • Risk Management
  • Mentorship

Domaines d’emploi

  • Security & Safety
  • Technology
  • Software
  • Government & Public Sector
  • Vulnerability Management Engineer
  • Vulnerability Analyst / Penetration Tester
  • Database and Network Professionals Not Elsewhere Classified
  • Penetration Testers
  • Computer Occupations, All Other

D’autres postes auxquels postuler directement

Des possibilités semblables publiées par des employeurs qui recrutent sur Jobs.ca, sans formulaire externe.

Voir tous les postes à candidature simplifiée