Turn this role into an interview — a resume and cover letter built around what this employer wants.
Bilinguallink seeks a Vulnerability Management Specialist focused on Application Security to manage vulnerabilities across the SDLC using SAST, DAST, and SCA tools. The role emphasizes risk-based prioritization, remediation tracking, and posture visibility through ASPM platforms.
Responsibilities include coordinating with IT, cloud, DevOps, and product teams to remediate findings, report progress, and maintain dashboards and SLAs across enterprise-scale programs.
Location: Remote (Canada)
Employment Type: Contract
Work Authorization: Open Work Permit (OWP), PR, Canadian Citizen only
Regarding skills for appsec. We need below hands-on experience and not only tool based.
Ability to assess vulnerabilities based on risk, not just severity—considering CVSS scores, exploitability, asset criticality, business impact, and threat intelligence to prioritize remediation effectively.
Hands-on expertise with vulnerability scanning tools (e.g., Nessus, Qualys, Rapid7, OpenVAS) and the ability to interpret scan results accurately, reduce false positives, and tune scans for different environments.
Strong coordination skills to drive timely patching and mitigation—working with IT, cloud, DevOps, and application teams to remediate vulnerabilities while minimizing operational and business disruption.
Ability to translate technical vulnerability data into clear, actionable reports for different audiences (engineers, management, auditors), including dashboards, trends, SLAs, and risk narratives.
Knowledge of security frameworks and standards and the skill to embed vulnerability management into continuous security processes, audits, and metrics-driven improvement.
The Vulnerability Management Specialist – Application Security is responsible for end to end management of application security vulnerabilities across the SDLC using SAST, DAST, and SCA tools, with a strong focus on risk based prioritization, remediation tracking, and posture visibility through ASPM platforms.
Strong hands on experience with:
Working knowledge of ASPM platforms and vulnerability aggregation.
Understanding of OWASP Top 10, secure coding practices, and application threat models.