Senior Analyst, Vulnerability Operations

Payments Canada

Ottawa

Hybrid

CAD 90,000 - 110,000

Full time

26 hours ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Hybrid work model
Competitive compensation
Health and dental benefits
Pension plan
Vacation and time off

Job summary

Payments Canada in Ottawa, Ontario, is seeking a Senior Analyst, Vulnerability Operations to lead and mature our cyber vulnerability management program across on‑prem and cloud environments. You will translate complex vulnerability data into strategic business risk insights for executive leadership.

The role requires strong technical leadership, collaboration with internal stakeholders and external partners, and the ability to evolve risk ranking with AI-focused threat modeling.

Qualifications

  • Requires a four-year degree or a relevant two-year diploma plus two years of additional experience.
  • Minimum of five years’ experience in IT support, system administration, or security operations.
  • Minimum of three years’ experience in vulnerability management.
  • Eligibility to obtain and maintain a Government of Canada Reliability Status Clearance.

Responsibilities

  • Research, analyze and translate vulnerability findings into risk narratives for leadership.
  • Monitor vulnerabilities across apps and infrastructure and prioritize remediation.
  • Evolve risk ranking by combining CVE/KEV scores with threat intelligence and AI risks.
  • Design automated workflows to ingest and filter large vulnerability data streams.
  • Provide guidance on vulnerability operations to internal stakeholders and external partners.
  • Lead cross-functional risk workshops and report on vulnerability posture to decision-makers.

Skills

Vulnerability management
Threat modeling
Executive storytelling
Security analytics
Cross-functional collaboration

Education

Bachelor's degree in a relevant field

Job description

Senior Analyst, Vulnerability Operations

Payments Canada, 800-350 Albert Street, Ottawa, Ontario, Canada

Job Description

Payments Canada is at the forefront of the Canadian payment ecosystem. Our purpose is to make payments easier, smarter and safer for all Canadians. Every day we are working diligently to ensure your payments are cleared and settled. In 2025 alone, our systems cleared approximately $103 trillion or $411.9 billion every business day! If you are passionate about payments and want to help ensure that these financial transactions in Canada are carried out safely and securely, working with us is for you!

Who we are

We are a public purpose, non-profit organization situated at the center of Canada’s payment ecosystem. We own and operate payment systems that process hundreds of billions of dollars’ worth of payment transactions every business day. We convene ecosystem participants to discuss their multiple and diverse interests and ideas and to navigate industry-level challenges. We adhere to a set of values that are our north star:

Our culture

With our people in mind, we have created a culture that fosters authenticity, collaboration, innovation and development. We empower one another, make meaningful contributions that not only impact the organization, but our country! We develop and nurture meaningful connections that drive innovation in our ecosystem. We are Payments Canada!

Do you want to make payments easier, smarter and saferfor Canada? Join us today!

You need to work here if
  • You love working with passionate, ambitious and collaborative colleagues.
  • You want to be challenged and lead unique initiatives.
  • You want to grow, develop and become a subject matter expert in your field.
  • You want your work to make an impact in your community and country.

Come and join us — where payments meet purpose!

What we are looking for

Reporting to the Director, Cyber Security & Operations, the Senior Analyst, Vulnerability Operations plays a vital, strategic role in safeguarding Payments Canada's modern infrastructure. The main responsibility of the Senior Analyst, Vulnerability Operations is to lead and mature the cyber vulnerability management program. This is not a siloed, backend technical role; it requires a highly personable technical leader who can translate complex vulnerability data (including CVEs, KEVs, and AI-specific exploits) into strategic business risks. The ideal candidate balances deep technical acumen with exceptional thought leadership to guide both internal teams and external financial sector partners.

The core mission of this role is to lead, scale, and mature our cyber vulnerability management program from traditional infrastructure monitoring to an agile framework capable of defending against threats in an AI world. Specifically, the incumbent will be responsible for managing vulnerabilities across applications, as well as on premise and cloud-based infrastructure.

Responsibilities of the position includes but is not limited to the following:

Research, Analysis & Thought Leadership
  • Conduct in-depth vulnerability research and analysis.
  • Produce timely, consolidated, multi-source vulnerability intelligence reports (e.g., vulnerability assessments, briefings,).
  • Conduct deep-dive research into emerging vulnerability trends, specifically focusing on the intersection of cybersecurity and Frontier AI (e.g., adversarial machine learning, LLM vulnerabilities, and AI supply chain risks).
  • Translate highly technical vulnerability findings into clear, risk-quantified business narratives for executive leadership and board-level consumption.
Vulnerability Management & Operations
  • Monitor vulnerabilities through a variety of tools and sources and rank them according to relevance to Payments Canada.
  • Collaborate with internal stakeholders to define vulnerability operations requirements.
  • Own, design, and mature the end-to-end vulnerability management lifecycle, evaluating and optimizing SLAs for remediation across corporate and payment systems.
  • Evolve traditional risk-ranking methodologies by combining CVE and KEV scores with real-world threat intelligence and AI-specific threat modeling (e.g., MITRE ATLAS).
  • Establish automated workflows and monitoring plans to ingest, filter, and prioritize massive data streams of threat and vulnerability data efficiently.
  • Report any imminent vulnerabilities to the organization in a timely manner.
  • Coordinate the response, including reporting, on vulnerabilities to multiple levels of stakeholders.
Engagement with the Organization & External partners
  • Provide cyber-focused guidance and vulnerability operations support to internal stakeholders.
  • Facilitate regular, cross-functional risk alignment workshops to help product owners understand the security posture of their applications.
  • Disseminate reports to inform decision makers about the cyber vulnerability position of the organization. Collaborate with external teams in the Financial and Critical Infrastructure sectors.
  • Maintain relationships with external partners who are involved in cyber planning or information sharing groups.
  • Provide subject-matter expertise and support to planning/developmental working groups as appropriate.
Continuous improvement of Security Practices & Processes
  • Construct vulnerability monitoring plans and matrices using established guidance and procedures.
  • Regularly audit and adapt the vulnerability monitoring cadence to proactively meet shifting organizational priorities and regulatory demands.
  • Gather and analyze feedback from internal stakeholders to continually improve the efficiency, accuracy, and actionability of vulnerability reporting.
  • Champion automation across the collection and processing pipelines to reduce alert fatigue.
  • Adjust the monitoring plan to address identified issues/challenges and to align with organizational requirements.
  • Proficiency in expressing technical discoveries through creation of reports, briefing notes that are both succinct and comprehensible.
  • Experience in advanced threat modeling frameworks (e.g., STRIDE, PASTA) expanded to account for systemic AI risks.
  • Advanced proficiency in threat infrastructure tools and analytic methodologies to chart complex threat campaigns.
  • Knowledge of enterprise IT networks, cybersecurity ecosystems, and roles and responsibilities.
  • Knowledge of common computer/network infections (virus, Trojan, etc.) and methods of infection (ports, attachments, etc.)
  • Knowledge of security capabilities and how those affect exploitation and reduce vulnerability.
  • Knowledge of criteria for evaluating collection products.
  • Knowledge of best practices for automation to support the collection and processing of large amounts of threat data/information.
  • Skilled in using multiple analytic tools, databases, and techniques (e.g., Analyst’s Notebook, A-Space, Anchory, M3, divergent/convergent thinking, link charts, matrices, etc.).
  • Skilled in writing, reviewing and editing cyber-related products.
  • Skilled at articulating a needs statement/requirement and integrating new and emerging collection capabilities, accesses and/or processes into the monitoring and reporting plan.
  • Skilled at preparing and delivering reports, presentations, and briefings, including the use of visual aids or presentation technology.
  • Skilled in identifying monitoring and reporting gaps.
  • Proficiency in expressing technical discoveries through creation of reports, briefing notes that are both succinct and comprehensible.
  • Skilled in using critical thinking and an investigative mindset for research and analysis.
  • Demonstrates strong communication, team work, emotional intelligence and business acumen.
  • Strong curiosity and drive for solving problems.
What you need to be successful
  • Requires a four (4) year degree, or a relevant two (2) year diploma or equivalent combined with two (2) years of additional experience.
  • Minimum of five (5) years’ experience in IT support, system administration, or security operations is considered good to have.
  • Minimum of three (3) years’ experience in vulnerability management.
  • Eligibility to obtain and maintain a Government of Canada Reliability Status Clearance and can successfully complete enhanced background checks that may be carried out by Payments Canada.
  • Ability to work outside of regular working hours based on operational requirements.
  • Willing to travel periodic to meet with external partners or attend industry events and conferences.
You will really stand out with
  • Industry certification (CISSP, GCTI, CTIA) is considered an asset.
  • Experience as CTI Analyst, SOC Analyst, or Vulnerability Management Analyst is preferred and considered an asset.
Salary range
  • Our target starting rate for this role is$ 100,300 with flexibility based on your experience and qualifications. The full salary range and benefits package are detailed below.

Please submit your application by September 18, 2026.

What's in it for you?
  • Flexible, hybrid (remote/office) environment.
  • Competitive compensation package, including annual variable bonus and defined contribution pension plan with employer matching percentage (if eligible).
  • Comprehensive health and dental benefit coverage, including mental health coverage, life insurance and a health spending account for you and your dependents (Permanent and temporary employees with contracts 12 months and over).
  • Paid time off: minimum four weeks paid vacation, sick and personal days, December holiday shutdown and cultural holiday observance days.
  • 26 weeks of paid maternity and parental leave top-up (if eligible)
  • Rewards and recognition program.
  • Access to office gym facilities.
  • Internal and external professional development opportunities.

At Payments Canada, we are dedicated to fair, transparent and inclusive hiring. We are an equal opportunity employer and value diversity at our company. Our recruitment process uses automated tools, but not generative AI, to objectively screen and evaluate applications and confirm that a candidate’s qualifications meet job requirements.

It is important to remember that these tools support, but do not replace, human decision-making. Our trained recruitment professionals and hiring managers always make the final hiring decisions.

Our diversity, inclusion and equity commitment

At Payments Canada, we are committed to making everyone feel they can be themselves and thrive at work. We will continue to build on a foundation of respect and appreciation for diversity in all forms and collectively create an inclusive and equitable culture where our differences are valued.

We are committed to employment equity and actively encourage applications from women, Aboriginal people, persons with disabilities and visible minorities. If selected for an interview, please advise us if you require special accommodation by emailing hrinfo@payments.ca .

We thank all applicants for their interest in this opportunity. Preference will be given to Canadian citizens and permanent residents. Only selected candidates will be contacted for an interview.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Analyst, Vulnerability Operations
Senior Analyst, Vulnerability Operations

Socket.dev • Ottawa

Hybrid
CAD 90,000 - 110,000
Hybrid work environment
Health & dental coverage
Employer-matching pension
Security Analyst (14 month Term)
Security Analyst (14 month Term)

Payments Canada • Ottawa

Hybrid
CAD 83,000 - 96,000
Flexible hybrid work environment
Comprehensive health and dental coverage
Paid time off and rewards program
+1
Security Compliance Analyst
Security Compliance Analyst

Payments Canada • Toronto

Hybrid
CAD 71,000 - 96,000
Hybrid work environment
Health and dental benefits
Paid time off and parental leave
+1
Security Compliance Analyst
Security Compliance Analyst

Payments Canada • Ottawa

Hybrid
CAD 83,000 - 95,000
Health and dental benefits
Flexible hybrid work environment
Paid vacation & personal days
+2
Senior Product Analyst, Emerging Payment Products
Senior Product Analyst, Emerging Payment Products

Payments Canada • Toronto

Hybrid
CAD 90,000 - 110,000
Health and dental benefits
Paid time off
Professional development opportunities
+1
Fraud Operations Analyst
Fraud Operations Analyst

Payments Canada • Toronto

Hybrid
CAD 75,000 - 92,000
Flexible, hybrid work environment
Professional development opportunities
Competitive compensation and pension
Senior Auditor, Internal Audit
Senior Auditor, Internal Audit

Payments Canada • Ottawa

Hybrid
CAD 88,000 - 148,000
Competitive compensation package
Comprehensive health and dental benefit coverage
Paid time off: minimum four weeks paid vacation
+2
Director, Product Enablement: Governance and Go To Market Oversight
Director, Product Enablement: Governance and Go To Market Oversight

Payments Canada • Ottawa

Hybrid
CAD 129,000 - 158,000
Flexible hybrid work
Competitive compensation with bonus
Health & dental benefits
+4
Product Manager, Core Payments Product
Product Manager, Core Payments Product

Payments Canada • Toronto

Hybrid
CAD 120,000 - 150,000
Hybrid work environment
Competitive compensation with annual,
Health, dental and life insurance
+2
Senior Information Security Analyst
Senior Information Security Analyst

Kaizen Lab Inc. • Calgary

Hybrid
CAD 100,000 - 140,000
Health Spending Account
Pension plan with employer contrib.
Professional development opportunities
+5