Senior Vulnerability Manager

CoFoMo Inc.

Montreal (administrative region)

Hybrid

CAD 120,000 - 170,000

Full time

3 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

Hybrid work model

Job summary

COFOMO is seeking a Senior Vulnerability Manager in Montreal to lead enterprise-wide vulnerability management across on-premises, cloud, and hybrid environments. You will coordinate remediation with cross-functional teams and oversee tooling and risk-based prioritization.

You should have 5+ years in cybersecurity with 3+ in vulnerability management, hands-on experience with Tenable/Qualys/Rapid7, and knowledge of NIST/ISO controls.

Qualifications

  • Bachelor's degree in cybersecurity or related field; 5+ years in cybersecurity incl. 3+ in vulnerability management.
  • Experience with vulnerability management platforms (Tenable, Qualys, Rapid7) and risk-based prioritization methodologies.
  • Familiarity with Windows, Linux, networking, cloud and containerized environments; strong communication skills.

Responsibilities

  • Lead enterprise-wide vulnerability management across on-prem, cloud, and hybrid environments.
  • Perform vulnerability assessments and analyze results from security platforms.
  • Validate, prioritize, and classify vulnerabilities based on risk and impact; coordinate remediation with teams.

Skills

Vulnerability management
Cybersecurity
Risk assessment
Communication
Analytical thinking

Education

Bachelor's degree in cybersecurity or related field

Tools

Tenable
Qualys
Rapid7
Cloud security platforms (Azure/AWS/GCP)

Job description

# Senior Vulnerability ManagerMontrealHybridCybersecurity and Identity ManagementApplyWith over 30 years of recognized expertise, COFOMO is now a leading Canadian consulting firm specializing in digital and artificial intelligence. Supported by more than 3,000 experts, 10 Centers of Excellence, and 4 offices across the country, we are uniquely positioned to successfully guide our clients through their transformations. Both strategic and tactical, we help organizations across a wide range of industries thrive in today’s rapidly evolving world.## Our promiseHelp our clients succeed and maximize the impact of their transformation initiatives, turning them into powerful drivers of growth and innovation.## Job description**Here's a brief overview of the tasks and responsibilities you'll have :** • Lead enterprise-wide vulnerability management activities across on-premises, cloud, and hybrid environments; • Perform vulnerability assessments and analyze results from different security platforms; • Validate, prioritize, and classify vulnerabilities based on risk level, exploitability, business impact, and threat intelligence; • Collaborate with infrastructure, application development, cloud and operations teams to coordinate remediation activities; • Track the progress of patches according to established service level agreements; • Develop risk-based vulnerability prioritization methodologies and processes; • Analyze emerging threats and assess exposure to newly disclosed vulnerabilities as well as zero-day vulnerabilities; • Produce reports, dashboards and performance indicators related to vulnerability management for operational and executive stakeholders; • Support security audits, regulatory compliance requirements, and risk assessments; • Maintain and optimize vulnerability scanning tools and their integrations; • Support junior analysts and security team members by providing technical advice; • Contribute to continuous improvement, process automation, and vulnerability management program maturity. **The profile you are looking for is as follows:** • Bachelor's degree in cybersecurity, information technology, computer science or a related field, or equivalent experience; • Have more than five (5) years of experience in cybersecurity, including at least three years in vulnerability management; • Proficient in vulnerability management platforms such as Tenable, Qualys, Rapid7 or similar solutions; • Be familiar with vulnerability prioritization frameworks and methodologies, including CVSS, EPSS, and KEV catalogs; • Experience with Windows, Linux, networking, cloud and containerized environments; • Master security standards such as NIST CSF, CIS Controls, ISO 27001 or PCI DSS; • Demonstrate experience in managing remediation programs and working with multidisciplinary stakeholders; • Possess strong analytical, problem-solving and risk assessment skills; • Demonstrate excellent written and verbal communication skills; • Present technical results to technical and management audiences; • Hold CISSP, GSEC, CISM, GIAC, CRISC or other relevant security certifications (an asset); • Knowledge of Microsoft Azure, AWS or Google Cloud Platform cloud security platforms (an asset); • Knowledge of SAP (an asset); • Understand threat intelligence concepts and techniques used by malicious actors (an asset); • Knowledge of attack surface management and exposure management programs (an asset); • Experience in automation and scripting with Python, PowerShell or similar languages (an asset); • Proficient in DevSecOps principles, continuous integration and continuous deployment pipelines, and application security practices (an asset); • Experience with EDR/XDR platforms, SIEM solutions, and security operations centers (an asset); • Understand penetration testing methodologies and vulnerability validation techniques (an asset); • Experience in highly regulated industries such as financial services, healthcare, or critical infrastructure (an asset); • This position requires fluency in French and English for daily tasks, understanding documentation, and professional communication with customers, suppliers, and colleagues across Canada. French and English language skills are essential, both oral and written.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior DevOps Developer
Senior DevOps Developer

CoFoMo Inc. • Montreal (administrative region)

Hybrid
CAD 110,000 - 170,000
Gestionnaire principal des vulnérabilités
Gestionnaire principal des vulnérabilités

CoFoMo Inc. • Montreal (administrative region)

On-site
CAD 100,000 - 150,000
Email Tool Administrator
Email Tool Administrator

CoFoMo Inc. • Montreal (administrative region)

Hybrid
CAD 65,000 - 100,000
Cyber Security Consultant
Cyber Security Consultant

Hamilton Barnes ? • Montreal

On-site
CAD 70,000 - 110,000
Yearly Bonus
Medical and Dental
Very Generous Annual Leave
+2
Vulnerability Management Security Engineer
Vulnerability Management Security Engineer

Astra-North Infoteck Inc. ~ Conquering today’s challenges, achieving tomorrow’s vision! • Montreal (administrative region)

Hybrid
CAD 90,000 - 120,000
.NET Organic Architecture Consultant
.NET Organic Architecture Consultant

CoFoMo Inc. • Montreal (administrative region)

Hybrid
CAD 110,000 - 160,000
Application production support
Application production support

CoFoMo Inc. • Montreal (administrative region)

Hybrid
CAD 85,000 - 110,000
Senior Network Administrator
Senior Network Administrator

CoFoMo Inc. • Montreal (administrative region)

Hybrid
CAD 85,000 - 120,000
Hybrid work environment
Wellness program
Telemedicine access
+1
Security Engineering
Security Engineering

Pacer Group • Montreal (administrative region)

Hybrid
CAD 115,000 - 135,000
Backend Developer
Backend Developer

CoFoMo Inc. • Montreal (administrative region)

Hybrid
CAD 90,000 - 120,000