Your main role and responsibilities
- Be an individual contributor and a great team player with a mindset to improve and support the business.
- Coordinate and manage timely remediation of security vulnerabilities across various technologies.
- Identify, resolve, and document false positive findings in vulnerability assessment results.
- Have hands-on knowledge of Rapid7 architecture, scan engines, collector servers, agents, query builder, goals, and projects.
- Collaborate with application teams and business unit owners to submit risk letters to comply with the organization's IT Security and Risk Management Framework.
- Perform weekly, monthly, and ad-hoc vulnerability assessments for servers, user systems, network assets, public-facing assets, and databases using Rapid7, Burp Suite, SonarSource, Qualys, or Mend.
- Manage scan configurations, including asset grouping, authentication, scan templates, engine pool, scheduling scans, and reports.
- Manage and troubleshoot vulnerability management tools.
- Monitor overall vulnerability scan status, engine health, report generation, and ensure successful scan completion with proper authentication.
- Troubleshoot scans for missing assets or authentication issues.
- Open support cases with scanning tools vendors when needed.
- Demonstrate experience with DAST, SAST, and SCA tools.
- Track vulnerability remediation via ticketing systems and validate with ad-hoc scans.
- Coordinate with network, endpoint, and server teams regarding patches and CVEs.
- Be knowledgeable of CVSS, vulnerability assessment methods, and corrective updates.
- Have good knowledge of web application vulnerabilities, assessment tools, and methodologies.
- Possess a minimum of 3 years of hands-on experience with vulnerability tools and 5-8 years in the information security domain.
- Hold certifications such as CEH, Rapid7 Certified Administrator, Qualys Certification, Security+, ITIL, or others.
- Employment is contingent upon positive screening, interview, background, and reference checks.
- This position is only open to candidates physically present in Canada who are Canadian citizens or permanent residents; it is not open to work visa holders.