Talent.com
Aarorn Technologies
Remote Vulnerability Management Specialist Application SecurityAarorn Technologies • Saint-Basile-le-Grand, Quebec
Remote Vulnerability Management Specialist Application Security

Remote Vulnerability Management Specialist Application Security

Aarorn Technologies • Saint-Basile-le-Grand, Quebec
11 days ago
Job type
  • Full-time
  • Remote
Job description

Role: Vulnerability management (Remote, Canada)
Location: Remote (Canada)
Employment Type: Contract
Work Authorization: Open Work Permit (OWP), PR, Canadian Citizen only

Mandatory skills for vulnerability management we are looking for the candidate having below key skills:

Regarding skills for appsec. We need below hands-on experience and not only tool based.

AppSec:

Web Application Security

Mobile Application Security

API Security

SAST (Static Application Security Testing), SCA (Software Composition Analysis)

Vulnerability Management lifecycle

VM: Risk Assessment & Prioritization
Ability to assess vulnerabilities based on risk, not just severity—considering CVSS scores, exploitability, asset criticality, business impact, and threat intelligence to prioritize remediation effectively.

Vulnerability Scanning & Tool Proficiency
Hands-on expertise with vulnerability scanning tools (e.g., Nessus, Qualys, Rapid7, OpenVAS) and the ability to interpret scan results accurately, reduce false positives, and tune scans for different environments.

Patch & Remediation Management
Strong coordination skills to drive timely patching and mitigation—working with IT, cloud, DevOps, and application teams to remediate vulnerabilities while minimizing operational and business disruption.

Reporting & Stakeholder Communication
Ability to translate technical vulnerability data into clear, actionable reports for different audiences (engineers, management, auditors), including dashboards, trends, SLAs, and risk narratives.

Compliance & Continuous Improvement
Knowledge of security frameworks and standards and the skill to embed vulnerability management into continuous security processes, audits, and metrics-driven improvement.

Job Description:

"Summary

The Vulnerability Management Specialist – Application Security is responsible for end to end management of application security vulnerabilities across the SDLC using SAST, DAST, and SCA tools, with a strong focus on risk based prioritization, remediation tracking, and posture visibility through ASPM platforms.

Technical Skills

Strong hands on experience with:

• SAST (e.g., AppScan, Check Marx, GitHub Advanced Security)

• DAST tools and runtime testing approaches

• SCA / OSS security and dependency risk analysis

Working knowledge of ASPM platforms and vulnerability aggregation.

Understanding of OWASP Top 10, secure coding practices, and application threat models.

Soft Skills:

• Must be from global support background.

• Strong documentation, presentation, and communication skills

Experience

• 8-10 + years of experience in application security or vulnerability management roles.

• Experience supporting enterprise scale AppSec programs with multiple applications and teams.

Key -Responsibilities

• Interpret findings across SAST, SCA, Secrets, API and Mobile scanning (tools like GitHub Advanced Security, Traceable, etc)

• Hand-off findings to development teams for remediation

• Provide technical remediation assistance to product development teams

• Track and report remediation progress

• Facilitate extension requests for remediation timelines

• Collaborate across teams using JIRA for ticketing and dashboards

• Familiarity with RBVM/ASPM tools like ArmorCode, Seemplicity, Brinqa a plus.

• Should have good knowledge of information security areas as Vulnerability Management Lifecycle, hardening controls (CIST, NIST) etc.

• Good understanding of information security related fields, including security operations and administration

• Should possess good understanding of assets, threats and vulnerabilities and their correlation in an organization

• Good understanding of vulnerability reports from tools like Qualys/ Tenable etc.

• Hands on experience on vulnerability prioritization tool, RiskSense or Kenna would be a plus

• Strong practical knowledge of vulnerability remediation tracking across infrastructure, applications, and teams/ 3rd parties

• Knowledge on vulnerability exception management process

• Strong practical knowledge on presenting vulnerability remediation tracking updates to the management

• Hands on experience on vulnerability patching

• Should have a good customer handling skill

• Good to have Experience on vulnerability scanning tools Like Qualys and Tenable.

Create a job alert for this search

Remote Vulnerability Management Specialist Application Security • Saint-Basile-le-Grand, Quebec

Similar jobs

Senior Engineer – Security Engineering - C$93,600 - C$149,400 A Year - Remote

CienaBoucherville, Canada
Remote
Full-time

Develops and implements features for the Ciena Secure Signing Platform (CSSP), integrating security tools and contributing to its architectural evolution. Show more

 • Promoted

Machine Safety Specialist - Risk & Compliance Lead - $30 - $50 An Hour

Nexrun AutomatisationLa Prairie, Canada
Full-time

Implement and monitor equipment safety processes, conduct safety assessments, and develop risk reduction solutions. Show more

 • Promoted

Cyber Security Analyst - Soc & Incident Response (6-Month) - C$73,336 - C$110,004 A Year

A leading technology firmBoucherville, Canada
Full-time

Experienced Cyber Security Analyst needed in Ottawa to design controls, investigate incidents, and perform vulnerability assessments. Show more

 • Promoted

EHS Compliance Specialist La Prairie

Business Integra IncLa Prairie, QC, CA
Full-time

Become an EHS Compliance Specialist II with GEV in La Prairie, Quebec.This role requires fluency in French and English and 5 years of experience in industrial health and safety.Reporting directly t... Show more

 • Promoted

Senior Appsec Engineer – Hybrid (Greater Montreal)

Power FactorsBrossard, Canada
Full-time

Une entreprise de solutions logicielles recrute un Engineer en Application Security.Le candidat doit posséder une solide expérience en développement et en sécurité des applications, collaborer et d... Show more

 • Promoted

Physical Security Engineering Specialist

Stantec Consulting International Ltd.Longueuil, Quebec, Canada
Full-time

Enhance organizational safety as a Physical Security Engineering Specialist.Employ your engineering skills in developing and implementing state-of-the-art security systems for diverse projects.The ... Show more

 • Promoted

Configuration Specialist (Ivalua) - $60,000 - $110,000 A Year - Remote

CgiVarennes, Canada
Remote
Full-time

Configures and customizes the Ivalua platform by translating business requirements into technical specifications and documentation.Conducts testing, troubleshooting, and data migration, requiring S... Show more

 • Promoted

Senior Cloud Security Operations Engineer - C$89,968 - C$182,564 A Year

ThalesVarennes, Canada
Full-time

The Senior Cloud Security Operations Engineer will lead efforts to secure multi-cloud environments, monitor threats, respond to incidents, and ensure compliance with industry standards. Show more

 • Promoted

Electronics Team Leader – Security Systems

ADGA GroupJoliette, Lanaudière, Canada
Full-time

A Canadian defence technology firm is seeking an Electronics Technician Team Leader in Joliette, Canada.This role involves leading a team in the maintenance of advanced electronic security systems ... Show more

 • Promoted

Hybrid Cloud Security Engineer — Ottawa - C$78,627.8 - C$130,038.3 A Year

Thales GroupBoucherville, Canada
Full-time

Cloud Security Engineer needed to respond to incidents, provide guidance, and analyze security logs. Show more