Specialist, Enterprise Vulnerability Management

Canada Mortgage and Housing Corporation

Ottawa

Hybrid

CAD 87,000 - 109,000

Full time

2 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Annual Paid vacation
Performance incentive
Group insurance plan
Training and mentorship
Inclusive workplace culture

Job summary

Canada Mortgage and Housing Corporation seeks a Specialist, Enterprise Vulnerability Management to lead risk-based remediation across infrastructure, cloud, and applications. You will apply vulnerability standards, risk methodologies, and threat intel to set priorities and drive secure delivery.

You will collaborate with cross-functional teams to ensure timely remediation, maintain data integrity, and report on risk metrics.

Qualifications

  • Undergraduate degree in IT, cybersecurity, CS, SE, CE, or related field.
  • 5+ years in information security, vulnerability management, or DevSecOps.
  • Security certification (e.g., Security+, CEH, CSSLP, ISC2 CC, GWAPT) or equivalent.
  • Experience using vulnerability scanning, app security testing, and remediation tools.
  • Understanding of the full vulnerability management lifecycle.
  • Knowledge of cloud, infrastructure, application security, and OWASP Top 10.
  • Understanding of SSDLC and Agile/DevOps/DevSecOps practices.
  • Strong analytical, communication, documentation, stakeholder engagement, risk assessment, data management, and escalation skills.

Responsibilities

  • Identify, analyze, and assess vulnerabilities across infra, cloud, apps, APIs, and containers.
  • Validate findings with risk assessments, eliminating false positives and assessing impact.
  • Classify, prioritize, and maintain vulnerability records using risk-rating methods and evidence.
  • Coordinate remediation with infrastructure, development, architecture, cloud teams; guide security controls.
  • Monitor remediation progress, verify fixes, escalate overdue or high-risk items to closure.
  • Support vulnerability mgmt in Agile, DevOps, and DevSecOps workflows.
  • Develop reports, dashboards, and audit-ready data for risk, compliance, and oversight.
  • Drive improvements by identifying recurring weaknesses and recommending tool/process changes.

Skills

Analytical skills
Communication skills
Documentation
Stakeholder engagement
Risk assessment
Data management
Issue escalation

Education

Undergraduate IT/Cybersecurity/CS/SE/CE degree

Tools

Vulnerability scanning tools
Remediation management tools
Application security testing tools

Job description

Select how often (in days) to receive an alert:

Specialist, Enterprise Vulnerability Management

Job Requisition ID: 12428

Position Status:Permanent Full Time

Position Type:Hybrid

Travel Requirement:Limited

Language Skill Levels (Read/Write/Speak):BBB

Security Requirement: Secret

Salary:Our salaries generally range from $86816.59to $108520.74and are based on qualifications and experience.

About CMHC

The work you do and the work we do together matters. We come to work every day with a common purpose: to contribute to a well-functioning housing system.

At CMHC, we hold ourselves accountable for our results and support our colleagues in their achievements. We thrive on collaboration, connecting across CMHC and involving the right people to get our work done. Our leadership style is guided by trust, where our leaders favour an adaptive approach based on the needs of their teams.

Join us and be part of a team that's committed to making a real difference and be part of something meaningful.

What’s in it for you

We’ve got the purpose, the people and the perks you need for a fulfilling career. Here’s the comprehensive and generous benefits you get when you’re a permanent employee:

  • Annual Paid vacation.
  • Annual individual performance incentive.
  • Comprehensive group insurance plan to support your well-being from day one.
  • Support towards your personal and professional growth with training, mentorship and more.
  • An inclusive workplace culture and environment.

Members of the following employment equity deserving groups will be prioritized for this job: Indigenous Peoples

About the role

Join the Security team, in the Specialist, Enterprise Vulnerability Management position. You will provide specialized expertise to apply and operationalize established vulnerability management standards, application security practices, risk methodologies, and threat intelligence to determine appropriate remediation priorities and control actions within established frameworks and defined operating procedures.

Accountable for the consistent operational execution and data integrity of the enterprise vulnerability management program across infrastructure, applications, cloud environments, APIs, and software delivery platforms. The role ensures vulnerabilities are identified, assessed, prioritized, tracked, communicated, remediated, and escalated in accordance with established security standards, risk methodologies, and service expectations.

The position directly contributes to reducing technology risk by enabling the timely identification, assessment, and remediation of vulnerabilities and by providing reliable vulnerability data to support risk management, compliance, and security oversight.

What you’ll do:
  • Identify, analyze, and assess vulnerabilities across infrastructure, cloud environments, applications, APIs, containers, and related technologies using security scanning and testing tools.
  • Validate findings through risk assessments by eliminating false positives and determining exploitability, business impact, and overall risk.
  • Classify, prioritize, and maintain accurate vulnerability records using approved risk-rating methodologies, threat intelligence, OWASP guidance, supporting evidence, and remediation tracking.
  • Coordinate remediation efforts with infrastructure, development, architecture, cloud, and technology teams, providing guidance on security controls, secure coding practices, and treatment options.
  • Monitor remediation progress, validate fixes, drive follow-up actions, and escape overdue, high-risk, or unresolved vulnerabilities through to closure or formal risk acceptance.
  • Support the integration of vulnerability management practices into Agile, DevOps, and DevSecOps workflows while ensuring consistent execution of enterprise standards.
  • Develop and maintain reports, dashboards, metrics, and audit-ready vulnerability data to support risk management, compliance, security investigations, assurance, and oversight activities.
  • Drive continuous improvement by identifying recurring security weaknesses, recommending process and tool enhancements, staying informed on emerging threats, and influencing stakeholders to strengthen security practices and reduce organizational risk exposure.
What you should have:
  • An undergraduate degree in Information Technology, Cybersecurity, Computer Science, Software Engineering, Computer Engineering, or a related field, or equivalent experience.
  • A minimum 5 years of experience in information security, vulnerability management, application security, infrastructure security, DevSecOps, or related technology disciplines.
  • A security certification completed or in progress (e.g., Security+, CEH, CSSLP, ISC2 CC, GWAPT, or equivalent) with practical experience supporting cybersecurity and vulnerability management activities.
  • Experience using vulnerability scanning, application security testing, and remediation management tools to identify, assess, and track security weaknesses.
  • A strong understanding of the full vulnerability management lifecycle, including identification, assessment, prioritization, remediation, and validation of vulnerabilities.
  • Knowledge of infrastructure security, cloud security, application security, OWASP Top 10 risks, and common cybersecurity threats and controls.
  • An understanding of Secure Software Development Lifecycle (SSDLC) practices and modern delivery frameworks, including Agile, DevOps, and DevSecOps.
  • Strong analytical, communication, documentation, stakeholder engagement, risk assessment, data management, and issue escalation skills, with the ability to identify recurring vulnerability trends and address systemic risks.

Posting closing date: Note, the competition will remain active until filled.

Our commitment to diversity, equity, and inclusion

We’re committed to employment equity and encourage women, Indigenous Peoples, persons with disabilities, veterans and persons of all races, ethnicities, religions, abilities, sexual orientations, and gender identities and expressions to apply. We also welcome applications from non-Canadians who are eligible to work in Canada.

CMHC is an inclusive workplace where diversity of thought – and of people – are recognized, valued, and considered essential to achieving our mission.

We know that applying for a new job can be both exciting and daunting, and we appreciate your effort. Learn more about our hiring process . If you are selected for an interview or testing, please advise us if you require an accommodation.

If you applied before and you were not successful don’t worry – we're always posting new positions, so don’t hesitate to give it another shot. We’re excited to see what you bring to the table this time around!

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Specialist, Enterprise Vulnerability Management
Specialist, Enterprise Vulnerability Management

Canada Mortgage and Housing Corporation (CMHC) Société canadienne d'hypothèques et de logement(SCHL) • Ottawa

Hybrid
CAD 87,000 - 109,000
Paid vacation
Performance incentive
Pension plan
+3
Senior Specialist, Security Applications (AppSecOps)
Senior Specialist, Security Applications (AppSecOps)

Canada Mortgage and Housing Corporation (CMHC) Société canadienne d'hypothèques et de logement(SCHL) • Ottawa

On-site
CAD 104,180 - 130,225
Defined benefit pension plan
Comprehensive group insurance plan
Support towards personal and professional growth
Specialist, Identity & Access Management
Specialist, Identity & Access Management

Canada Mortgage and Housing Corporation • Ottawa

Hybrid
CAD 87,000 - 109,000
Annual paid vacation
Performance incentive
Insurance plan
+3
Senior Specialist, Software Engineering (Full Stack Developer)
Senior Specialist, Software Engineering (Full Stack Developer)

Canada Mortgage and Housing Corporation (CMHC) Société canadienne d'hypothèques et de logement(SCHL) • Ottawa

On-site
CAD 104,000 - 130,000
Annual vacation
Performance incentive
Defined benefit pension
+1
Specialist, Identity & Access Management
Specialist, Identity & Access Management

Canada Mortgage and Housing Corporation (CMHC) Société canadienne d'hypothèques et de logement(SCHL) • Ottawa

Hybrid
CAD 86,000 - 109,000
Annual Paid vacation
Annual individual performance incentive
Defined benefit pension plan
+3
Bilingual Advisor, Software Engineering
Bilingual Advisor, Software Engineering

Canada Mortgage and Housing Corporation (CMHC) Société canadienne d'hypothèques et de logement(SCHL) • Ottawa

On-site
CAD 129,175 - 161,469
Annual paid vacation
Performance incentive
Defined benefit pension
+4
Principal, Software Engineering
Principal, Software Engineering

Canada Mortgage and Housing Corporation • Ottawa

Hybrid
CAD 129,000 - 161,000
Annual vacation
Performance incentive
Group insurance
+3
Bilingual Senior Specialist, IT Operations Monitoring & Service Insights
Bilingual Senior Specialist, IT Operations Monitoring & Service Insights

Canada Mortgage and Housing Corporation • Ottawa

Hybrid
CAD 104,000 - 130,000
Annual vacation
Performance incentive
Group insurance
+3
Specialist, Quantitative Analysis
Specialist, Quantitative Analysis

Canada Mortgage and Housing Corporation • Ottawa

On-site
CAD 87,000 - 109,000
Annual vacation
Performance incentive
Insurance plan
+3
Specialist, Quality Assurance
Specialist, Quality Assurance

Socket.dev • Vancouver

Hybrid
CAD 87,000 - 109,000
Accrued vacation
Performance bonus
Training and mentorship
+2