Stand out for this role — generate a tailored resume and cover letter in about a minute.
Bilinguallink is seeking a Vulnerability Management Specialist – Application Security to lead end-to-end vulnerability management across the SDLC using SAST, DAST and SCA tools.
The role focuses on risk-based prioritization, remediation tracking, and posture visibility, collaborating with DevOps, IT and engineering teams in a remote Canada context.
Location: Remote (Canada)
Employment Type: Contract
Work Authorization: Open Work Permit (OWP), PR, Canadian Citizen only
Regarding skills for appsec. We need below hands-on experience and not only tool based.
Ability to assess vulnerabilities based on risk, not just severity—considering CVSS scores, exploitability, asset criticality, business impact, and threat intelligence to prioritize remediation effectively.
Hands-on expertise with vulnerability scanning tools (e.g., Nessus, Qualys, Rapid7, OpenVAS) and the ability to interpret scan results accurately, reduce false positives, and tune scans for different environments.
Strong coordination skills to drive timely patching and mitigation—working with IT, cloud, DevOps, and application teams to remediate vulnerabilities while minimizing operational and business disruption.
Ability to translate technical vulnerability data into clear, actionable reports for different audiences (engineers, management, auditors), including dashboards, trends, SLAs, and risk narratives.
Knowledge of security frameworks and standards and the skill to embed vulnerability management into continuous security processes, audits, and metrics-driven improvement.
The Vulnerability Management Specialist – Application Security is responsible for end to end management of application security vulnerabilities across the SDLC using SAST, DAST, and SCA tools, with a strong focus on risk based prioritization, remediation tracking, and posture visibility through ASPM platforms.
Strong hands on experience with:
Working knowledge of ASPM platforms and vulnerability aggregation.
Understanding of OWASP Top 10, secure coding practices, and application threat models.