Talent.com
Aarorn Technologies
Remote Vulnerability Management Specialist Application SecurityAarorn Technologies • Levis, Quebec
Remote Vulnerability Management Specialist Application Security

Remote Vulnerability Management Specialist Application Security

Aarorn Technologies • Levis, Quebec
Il y a plus de 30 jours
Type de contrat
  • Temps plein
  • Télétravail
Description de poste

Role: Vulnerability management (Remote, Canada)
Location: Remote (Canada)
Employment Type: Contract
Work Authorization: Open Work Permit (OWP), PR, Canadian Citizen only

Mandatory skills for vulnerability management we are looking for the candidate having below key skills:

Regarding skills for appsec. We need below hands-on experience and not only tool based.

AppSec:

Web Application Security

Mobile Application Security

API Security

SAST (Static Application Security Testing), SCA (Software Composition Analysis)

Vulnerability Management lifecycle

VM: Risk Assessment & Prioritization
Ability to assess vulnerabilities based on risk, not just severity—considering CVSS scores, exploitability, asset criticality, business impact, and threat intelligence to prioritize remediation effectively.

Vulnerability Scanning & Tool Proficiency
Hands-on expertise with vulnerability scanning tools (e.g., Nessus, Qualys, Rapid7, OpenVAS) and the ability to interpret scan results accurately, reduce false positives, and tune scans for different environments.

Patch & Remediation Management
Strong coordination skills to drive timely patching and mitigation—working with IT, cloud, DevOps, and application teams to remediate vulnerabilities while minimizing operational and business disruption.

Reporting & Stakeholder Communication
Ability to translate technical vulnerability data into clear, actionable reports for different audiences (engineers, management, auditors), including dashboards, trends, SLAs, and risk narratives.

Compliance & Continuous Improvement
Knowledge of security frameworks and standards and the skill to embed vulnerability management into continuous security processes, audits, and metrics-driven improvement.

Job Description:

"Summary

The Vulnerability Management Specialist – Application Security is responsible for end to end management of application security vulnerabilities across the SDLC using SAST, DAST, and SCA tools, with a strong focus on risk based prioritization, remediation tracking, and posture visibility through ASPM platforms.

Technical Skills

Strong hands on experience with:

• SAST (e.g., AppScan, Check Marx, GitHub Advanced Security)

• DAST tools and runtime testing approaches

• SCA / OSS security and dependency risk analysis

Working knowledge of ASPM platforms and vulnerability aggregation.

Understanding of OWASP Top 10, secure coding practices, and application threat models.

Soft Skills:

• Must be from global support background.

• Strong documentation, presentation, and communication skills

Experience

• 8-10 + years of experience in application security or vulnerability management roles.

• Experience supporting enterprise scale AppSec programs with multiple applications and teams.

Key -Responsibilities

• Interpret findings across SAST, SCA, Secrets, API and Mobile scanning (tools like GitHub Advanced Security, Traceable, etc)

• Hand-off findings to development teams for remediation

• Provide technical remediation assistance to product development teams

• Track and report remediation progress

• Facilitate extension requests for remediation timelines

• Collaborate across teams using JIRA for ticketing and dashboards

• Familiarity with RBVM/ASPM tools like ArmorCode, Seemplicity, Brinqa a plus.

• Should have good knowledge of information security areas as Vulnerability Management Lifecycle, hardening controls (CIST, NIST) etc.

• Good understanding of information security related fields, including security operations and administration

• Should possess good understanding of assets, threats and vulnerabilities and their correlation in an organization

• Good understanding of vulnerability reports from tools like Qualys/ Tenable etc.

• Hands on experience on vulnerability prioritization tool, RiskSense or Kenna would be a plus

• Strong practical knowledge of vulnerability remediation tracking across infrastructure, applications, and teams/ 3rd parties

• Knowledge on vulnerability exception management process

• Strong practical knowledge on presenting vulnerability remediation tracking updates to the management

• Hands on experience on vulnerability patching

• Should have a good customer handling skill

• Good to have Experience on vulnerability scanning tools Like Qualys and Tenable.

Créer une alerte emploi pour cette recherche

Remote Vulnerability Management Specialist Application Security • Levis, Quebec

Offres similaires

Remote Presales Engineer for Global Network Security

StealthWatchQuebec, Capitale-Nationale, CA
Télétravail
Temps plein

A leading technology firm is seeking a Presales Engineer to join their team.This role offers the chance to work remotely from anywhere in Canada and requires expertise in network and security techn... Voir plus

 • Offre sponsorisée

Remote DevSecOps Engineer: Secure Cloud & CI/CD Champion

JobgetherQuebec, Capitale-Nationale, CA
Télétravail
Temps plein

A technology company is seeking a DevSecOps Engineer to enhance security, reliability, and DevOps within cloud infrastructure.The role involves embedding security in CI/CD pipelines, automating rem... Voir plus

 • Offre sponsorisée

Cyber Security Support

Brainhunter Systems LtdQuebec, Capitale-Nationale, CA
Temps plein

How many paid working hours: 20 hrs/ week.Remote work with occasional site travel.Familiarity with the ECC Process as outlined in BP-PROC-01081 is an asset.Knowledge of Bruce Power’s Cyber Security... Voir plus

 • Offre sponsorisée

Senior Analyst, Security Compliance

P2PQuebec, Capitale-Nationale, CA
Temps plein

Our Krakenites are a world-class team with crypto conviction, united by our desire to discover and unlock the potential of crypto and blockchain technology.Kraken is a mission-focused company roote... Voir plus

 • Offre sponsorisée

Remote Security Architect - Cloud & App Security Lead

AGFA HealthCareQuebec, Capitale-Nationale, CA
Télétravail
Temps plein

A healthcare technology company is seeking an experienced Security Architect responsible for designing and implementing security within their architecture.The role involves collaborating with cross... Voir plus

 • Offre sponsorisée

Senior Threat Detection & Response Engineer

1PasswordQuebec, Capitale-Nationale, CA
Temps plein

A leading cybersecurity company in Canada seeks a Senior Security Engineer to enhance threat detection and response capabilities.You will design systems for threat detection, lead incident response... Voir plus

 • Offre sponsorisée

Analyste principal Sécurité des réseaux – Infonuagique Remote

Empire VieQuebec, Capitale-Nationale, CA
Télétravail
Temps plein

Une société d'assurance basée au Canada recherche un Analyste principal(e) en sécurité des réseaux pour rejoindre une équipe dynamique dédiée à la protection des infrastructures réseau.Le candidat ... Voir plus

 • Offre sponsorisée

Senior SecOps Engineer - Cloud Security & Automation

CohereQuebec, Capitale-Nationale, CA
Temps plein

A leading AI research company in Montreal is seeking a Senior Security Operations Engineer to enhance its cloud security efforts.You will manage security protocols, respond to incidents, and work o... Voir plus

 • Offre sponsorisée

Remote Security & DevOps Engineer for SaaS/IoT Cloud

KeycafeQuebec, Capitale-Nationale, CA
Télétravail
Temps plein

A leading technology firm in Canada is seeking a passionate Security & DevOps Engineer to enhance its cloud environments and ensure high security across its global IoT platform.You'll manage applic... Voir plus

 • Offre sponsorisée

Principal Security Analyst - Remote

CyderesQuebec, Capitale-Nationale, CA
Télétravail
Temps plein

Be among the first 25 applicants.Cyderes (Cyber Defense and Response) is a pure-play, full life-cycle cybersecurity services provider with award-winning managed security services, identity and acce... Voir plus

 • Offre sponsorisée

Remote Cloud Security Architect: DevSecOps & Risk Leader

Intuitive.aiQuebec, Capitale-Nationale, CA
Télétravail
Temps plein

A leading cybersecurity solutions company is seeking a Cybersecurity Specialist (GCP) to enhance their Cybersecurity Program.The role involves developing comprehensive security strategies in cloud ... Voir plus

 • Offre sponsorisée

Application Engineer - Security Tech Solutions (Remote)

SICK Sensor IntelligenceQuebec, Capitale-Nationale, CA
Télétravail

Sie entwickeln Applikationslösungen im Bereich Sicherheitstechnik.Bewerber benötigen ein Studium in Elektrotechnik und Erfahrung in der Elektrokonstruktion sowie gute Englischkenntnisse. Voir plus

 • Offre sponsorisée

Safety Specialist for Avionics Systems

ThalesQuebec, Capitale-Nationale, CA
Temps plein

Enhance flight safety with Thales in Montreal as a Safety Specialist.This full-time hybrid role concentrates on safety and reliability of avionics flight control systems.In this position, you will ... Voir plus

 • Offre sponsorisée

Remote Cyber Security Documentation & Governance Specialist

Brainhunter Systems LtdQuebec, Capitale-Nationale, CA
Télétravail
Temps plein

A leading consulting firm is looking for a Cyber Security Support Specialist in Bruce County, Canada.This primarily remote role involves developing technical documentation and supporting governance... Voir plus

 • Offre sponsorisée

REMOTE Protection & Controls Substation Engineer

JobotQuebec, Capitale-Nationale, CA
Télétravail
Temps plein

REMOTE Protection & Controls Substation Engineer.Be among the first 25 applicants.This range is provided by Jobot.Your actual pay will be based on your skills and experience — talk with your recrui... Voir plus

 • Offre sponsorisée

Security GRC Specialist — Remote-Ready & Metrics-Driven

Tecsys Inc.Quebec, Capitale-Nationale, CA
Télétravail
Temps plein

Join a forward-thinking company as a Security Governance, Risk, and Compliance Specialist, where your expertise will be pivotal in enhancing security measures and compliance frameworks.In this role... Voir plus

 • Offre sponsorisée

Senior Malware Protection Specialist (Trellix) – Remote

act digitalQuebec, Capitale-Nationale, CA
Télétravail
Temps plein

A consulting and technology expertise company is seeking an experienced Senior IT and Security Administrator specializing in Malware Protection technologies.The ideal candidate will have a strong b... Voir plus

 • Offre sponsorisée

IAM Governance Analyst (SailPoint) Remote

Nexus Systems Group Inc.Quebec, Capitale-Nationale, CA
Télétravail
Temps plein

A leading technology consulting firm is seeking an IT Security Analyst to support the IAM Governance team.The role involves overseeing access management and ensuring compliance with security measur... Voir plus

 • Offre sponsorisée

Senior Security Engineer Focused on Detection and Response Frameworks

1PasswordQuebec, Capitale-Nationale, CA
Temps plein

Join as a Senior Security Engineer to strengthen detection and incident response frameworks.Lead initiatives that optimize security measures and enhance organizational resilience in a remote enviro... Voir plus

 • Offre sponsorisée

Remote Domain Security Consultant - SASE & Zero Trust

Palo Alto NetworksQuebec, Capitale-Nationale, CA
Télétravail
Temps plein

A leading cybersecurity company is seeking a Domain Consultant in Vancouver to provide expertise in network security transformation.This role involves collaborating with sales teams and leading cus... Voir plus