Specialist, Enterprise Vulnerability Management

Canada Mortgage and Housing Corporation (CMHC) Société canadienne d'hypothèques et de logement(SCHL)

Ottawa

Hybrid

CAD 87,000 - 109,000

Full time

6 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Paid vacation
Performance incentive
Pension plan
Insurance coverage
Professional growth
Inclusive culture

Job summary

CMHC is seeking a Specialist, Enterprise Vulnerability Management to join the Security team. You will apply vulnerability management standards, risk methodologies, and threat intelligence to determine remediation priorities and actions.

You will oversee the enterprise vulnerability management program across infrastructure, cloud, applications, APIs, and software delivery platforms, ensuring timely identification, assessment, remediation, and escalation in line with security standards.

Qualifications

  • An undergraduate degree in IT, cybersecurity, Computer Science, Software Engineering, Computer Engineering, or related field, or equivalent experience.
  • A minimum 5 years of experience in information security, vulnerability management, application security, infrastructure security, DevSecOps, or related technology disciplines.
  • A security certification (e.g., Security+, CEH, CSSLP, ISC2 CC, GWAPT) or in progress.
  • Experience using vulnerability scanning, application security testing, and remediation management tools.
  • Understanding of the full vulnerability management lifecycle (identification to validation).

Responsibilities

  • Identify, analyze, and assess vulnerabilities across infrastructure, cloud environments, applications, APIs, containers, and related technologies.
  • Validate findings through risk assessments, eliminating false positives and determining exploitability and impact.
  • Classify, prioritize, and maintain accurate vulnerability records with risk ratings and remediation tracking.
  • Coordinate remediation with infrastructure, development, architecture, cloud, and technology teams, providing guidance on controls and secure coding.
  • Monitor remediation progress, validate fixes, escalate overdue or high-risk items to closure.
  • Support integration of vulnerability management into Agile, DevOps, and DevSecOps workflows.
  • Develop reports, dashboards, metrics for risk management, compliance, and oversight.
  • Drive continuous improvement by staying informed on emerging threats.

Skills

Information security
Vulnerability management
DevSecOps
Risk assessment

Education

Bachelor’s degree in IT or related field

Tools

Vulnerability scanning tools
Remediation management tools

Job description

Job Requisition ID: 12428

Position Status: Permanent Full Time

Position Type: Hybrid

Office Location: Montreal (QC); Ottawa (ON)

Travel Requirement: Limited

Language Designation: Bilingual

Language Skill Levels (Read/Write/Speak): BBB

Security Requirement: Secret

Salary: Our salaries generally range from $ 86816.59 to $ 108520.74 and are based on qualifications and experience.

About CMHC

The work you do and the work we do together matters. We come to work every day with a common purpose: to contribute to a well-functioning housing system.

At CMHC, we hold ourselves accountable for our results and support our colleagues in their achievements. We thrive on collaboration, connecting across CMHC and involving the right people to get our work done. Our leadership style is guided by trust, where our leaders favour an adaptive approach based on the needs of their teams.

Join us and be part of a team that's committed to making a real difference and be part of something meaningful.

Benefits
  • Annual Paid vacation.
  • Annual individual performance incentive.
  • Defined benefit pension plan.
  • Comprehensive group insurance plan to support your well-being from day one.
  • Support towards your personal and professional growth with training, mentorship and more.
  • An inclusive workplace culture and environment.

Members of the following employment equity deserving groups will be prioritized for this job: Indigenous Peoples

About The Role

Join the Security team, in the Specialist, Enterprise Vulnerability Management position. You will provide specialized expertise to apply and operationalize established vulnerability management standards, application security practices, risk methodologies, and threat intelligence to determine appropriate remediation priorities and control actions within established frameworks and defined operating procedures.

Accountable for the consistent operational execution and data integrity of the enterprise vulnerability management program across infrastructure, applications, cloud environments, APIs, and software delivery platforms. The role ensures vulnerabilities are identified, assessed, prioritized, tracked, communicated, remediated, and escalated in accordance with established security standards, risk methodologies, and service expectations.

The position directly contributes to reducing technology risk by enabling the timely identification, assessment, and remediation of vulnerabilities and by providing reliable vulnerability data to support risk management, compliance, and security oversight.

What You'll Do
  • Identify, analyze, and assess vulnerabilities across infrastructure, cloud environments, applications, APIs, containers, and related technologies using security scanning and testing tools.
  • Validate findings through risk assessments by eliminating false positives and determining exploitability, business impact, and overall risk.
  • Classify, prioritize, and maintain accurate vulnerability records using approved risk-rating methodologies, threat intelligence, OWASP guidance, supporting evidence, and remediation tracking.
  • Coordinate remediation efforts with infrastructure, development, architecture, cloud, and technology teams, providing guidance on security controls, secure coding practices, and treatment options.
  • Monitor remediation progress, validate fixes, drive follow-up actions, and elevate overdue, high-risk, or unresolved vulnerabilities through to closure or formal risk acceptance.
  • Support the integration of vulnerability management practices into Agile, DevOps, and DevSecOps workflows while ensuring consistent execution of enterprise standards.
  • Develop and maintain reports, dashboards, metrics, and audit-ready vulnerability data to support risk management, compliance, security investigations, assurance, and oversight activities.
  • Drive continuous improvement by identifying recurring security weaknesses, recommending process and tool enhancements, staying informed on emerging threats, and influencing stakeholders to strengthen security practices and reduce organizational risk exposure.
What You Should Have
  • An undergraduate degree in Information Technology, Cybersecurity, Computer Science, Software Engineering, Computer Engineering, or a related field, or equivalent experience.
  • A minimum 5 years of experience in information security, vulnerability management, application security, infrastructure security, DevSecOps, or related technology disciplines.
  • A security certification completed or in progress (e.g., Security+, CEH, CSSLP, ISC2 CC, GWAPT, or equivalent) with practical experience supporting cybersecurity and vulnerability management activities.
  • Experience using vulnerability scanning, application security testing, and remediation management tools to identify, assess, and track security weaknesses.
  • A strong understanding of the full vulnerability management lifecycle, including identification, assessment, prioritization, remediation, and validation of vulnerabilities.
  • Knowledge of infrastructure security, cloud security, application security, OWASP Top 10 risks, and common cybersecurity threats and controls.
  • An understanding of Secure Software Development Lifecycle (SSDLC) practices and modern delivery frameworks, including Agile, DevOps, and DevSecOps.
  • Strong analytical, communication, documentation, stakeholder engagement, risk assessment, data management, and issue escalation skills, with the ability to identify recurring vulnerability trends and address systemic risks.
Posting closing date

Note, the competition will remain active until filled.

Our commitment to diversity, equity, and inclusion

We’re committed to employment equity and encourage women, Indigenous Peoples, persons with disabilities, veterans and persons of all races, ethnicities, religions, abilities, sexual orientations, and gender identities and expressions to apply. We also welcome applications from non-Canadians who are eligible to work in Canada.

CMHC is an inclusive workplace where diversity of thought - and of people - are recognized, valued, and considered essential to achieving our mission.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Specialist, Enterprise Vulnerability Management
Specialist, Enterprise Vulnerability Management

Canada Mortgage and Housing Corporation • Ottawa

Hybrid
CAD 87,000 - 109,000
Annual Paid vacation
Performance incentive
Group insurance plan
+2
Senior Specialist, Security Applications (AppSecOps)
Senior Specialist, Security Applications (AppSecOps)

Canada Mortgage and Housing Corporation (CMHC) Société canadienne d'hypothèques et de logement(SCHL) • Ottawa

On-site
CAD 104,180 - 130,225
Defined benefit pension plan
Comprehensive group insurance plan
Support towards personal and professional growth
Specialist, Identity & Access Management
Specialist, Identity & Access Management

Canada Mortgage and Housing Corporation (CMHC) Société canadienne d'hypothèques et de logement(SCHL) • Ottawa

Hybrid
CAD 86,000 - 109,000
Annual Paid vacation
Annual individual performance incentive
Defined benefit pension plan
+3
Senior Specialist, Software Engineering (Full Stack Developer)
Senior Specialist, Software Engineering (Full Stack Developer)

Canada Mortgage and Housing Corporation (CMHC) Société canadienne d'hypothèques et de logement(SCHL) • Ottawa

On-site
CAD 104,000 - 130,000
Annual vacation
Performance incentive
Defined benefit pension
+1
Bilingual Advisor, Software Engineering
Bilingual Advisor, Software Engineering

Canada Mortgage and Housing Corporation (CMHC) Société canadienne d'hypothèques et de logement(SCHL) • Ottawa

On-site
CAD 129,175 - 161,469
Annual paid vacation
Performance incentive
Defined benefit pension
+4
Specialist, Identity & Access Management
Specialist, Identity & Access Management

Canada Mortgage and Housing Corporation • Ottawa

Hybrid
CAD 87,000 - 109,000
Annual paid vacation
Performance incentive
Insurance plan
+3
Specialist, Change Management
Specialist, Change Management

Socket.dev • Vancouver

Hybrid
CAD 87,000 - 109,000
Accrued vacation
Annual performance bonus
Training and mentorship
+1
Senior Specialist, Software Engineering (CI/CD & Automation Engineering)
Senior Specialist, Software Engineering (CI/CD & Automation Engineering)

Canada Mortgage and Housing Corporation (CMHC) Société canadienne d'hypothèques et de logement(SCHL) • Montreal (administrative region)

Hybrid
CAD 104,000 - 130,000
Annual paid vacation
Annual performance incentive
Defined benefit pension plan
+3
Bilingual Senior Specialist, IT Operations Monitoring & Service Insights
Bilingual Senior Specialist, IT Operations Monitoring & Service Insights

Canada Mortgage and Housing Corporation • Ottawa

Hybrid
CAD 104,000 - 130,000
Annual vacation
Performance incentive
Group insurance
+3
Bilingual Senior Manager, Data Operations
Bilingual Senior Manager, Data Operations

Canada Mortgage and Housing Corporation (CMHC) Société canadienne d'hypothèques et de logement(SCHL) • Ottawa

Hybrid
CAD 129,000 - 161,000
Annual vacation
Performance incentive
Defined benefit pension
+3