Talent.com
Aarorn Technologies
Remote Vulnerability Management Specialist Application SecurityAarorn Technologies • Westmount, Quebec
Remote Vulnerability Management Specialist Application Security

Remote Vulnerability Management Specialist Application Security

Aarorn Technologies • Westmount, Quebec
30+ days ago
Job type
  • Full-time
  • Remote
Job description

Role: Vulnerability management (Remote, Canada)
Location: Remote (Canada)
Employment Type: Contract
Work Authorization: Open Work Permit (OWP), PR, Canadian Citizen only

Mandatory skills for vulnerability management we are looking for the candidate having below key skills:

Regarding skills for appsec. We need below hands-on experience and not only tool based.

AppSec:

Web Application Security

Mobile Application Security

API Security

SAST (Static Application Security Testing), SCA (Software Composition Analysis)

Vulnerability Management lifecycle

VM: Risk Assessment & Prioritization
Ability to assess vulnerabilities based on risk, not just severity—considering CVSS scores, exploitability, asset criticality, business impact, and threat intelligence to prioritize remediation effectively.

Vulnerability Scanning & Tool Proficiency
Hands-on expertise with vulnerability scanning tools (e.g., Nessus, Qualys, Rapid7, OpenVAS) and the ability to interpret scan results accurately, reduce false positives, and tune scans for different environments.

Patch & Remediation Management
Strong coordination skills to drive timely patching and mitigation—working with IT, cloud, DevOps, and application teams to remediate vulnerabilities while minimizing operational and business disruption.

Reporting & Stakeholder Communication
Ability to translate technical vulnerability data into clear, actionable reports for different audiences (engineers, management, auditors), including dashboards, trends, SLAs, and risk narratives.

Compliance & Continuous Improvement
Knowledge of security frameworks and standards and the skill to embed vulnerability management into continuous security processes, audits, and metrics-driven improvement.

Job Description:

"Summary

The Vulnerability Management Specialist – Application Security is responsible for end to end management of application security vulnerabilities across the SDLC using SAST, DAST, and SCA tools, with a strong focus on risk based prioritization, remediation tracking, and posture visibility through ASPM platforms.

Technical Skills

Strong hands on experience with:

• SAST (e.g., AppScan, Check Marx, GitHub Advanced Security)

• DAST tools and runtime testing approaches

• SCA / OSS security and dependency risk analysis

Working knowledge of ASPM platforms and vulnerability aggregation.

Understanding of OWASP Top 10, secure coding practices, and application threat models.

Soft Skills:

• Must be from global support background.

• Strong documentation, presentation, and communication skills

Experience

• 8-10 + years of experience in application security or vulnerability management roles.

• Experience supporting enterprise scale AppSec programs with multiple applications and teams.

Key -Responsibilities

• Interpret findings across SAST, SCA, Secrets, API and Mobile scanning (tools like GitHub Advanced Security, Traceable, etc)

• Hand-off findings to development teams for remediation

• Provide technical remediation assistance to product development teams

• Track and report remediation progress

• Facilitate extension requests for remediation timelines

• Collaborate across teams using JIRA for ticketing and dashboards

• Familiarity with RBVM/ASPM tools like ArmorCode, Seemplicity, Brinqa a plus.

• Should have good knowledge of information security areas as Vulnerability Management Lifecycle, hardening controls (CIST, NIST) etc.

• Good understanding of information security related fields, including security operations and administration

• Should possess good understanding of assets, threats and vulnerabilities and their correlation in an organization

• Good understanding of vulnerability reports from tools like Qualys/ Tenable etc.

• Hands on experience on vulnerability prioritization tool, RiskSense or Kenna would be a plus

• Strong practical knowledge of vulnerability remediation tracking across infrastructure, applications, and teams/ 3rd parties

• Knowledge on vulnerability exception management process

• Strong practical knowledge on presenting vulnerability remediation tracking updates to the management

• Hands on experience on vulnerability patching

• Should have a good customer handling skill

• Good to have Experience on vulnerability scanning tools Like Qualys and Tenable.

Create a job alert for this search

Remote Vulnerability Management Specialist Application Security • Westmount, Quebec

Similar jobs

Senior Malware Protection Specialist (Trellix) – Remote

act digitalMontreal (administrative region), QC, CA
Remote
Full-time

A consulting and technology expertise company is seeking an experienced Senior IT and Security Administrator specializing in Malware Protection technologies.The ideal candidate will have a strong b... Show more

 • Promoted

Remote Cyber Security Documentation & Governance Specialist

Brainhunter Systems LtdMontreal (administrative region), QC, CA
Remote
Full-time

A leading consulting firm is looking for a Cyber Security Support Specialist in Bruce County, Canada.This primarily remote role involves developing technical documentation and supporting governance... Show more

 • Promoted

Master Security Specialist Montreal,Quebec,Canada Product Development Posted 5 hours ago

Ericsson GmbHMontreal (administrative region), QC, CA
Full-time

Ericsson's Product Security Incident Response Team (PSIRT) serves as the global single point of contact for product security vulnerabilities, incident response, and security inquiries.The team stre... Show more

 • Promoted

Application Security Specialist.

EXFOMontreal
Full-time

EXFO develops smarter network test, monitoring, and analytics solutions for the world’s leading telecommunications service providers, network equipment manufacturers, and web-scale companies—and we... Show more

 • Promoted

Remote Security & DevOps Engineer for SaaS/IoT Cloud

KeycafeMontreal (administrative region), QC, CA
Remote
Full-time

A leading technology firm in Canada is seeking a passionate Security & DevOps Engineer to enhance its cloud environments and ensure high security across its global IoT platform.You'll manage applic... Show more

 • Promoted

Analyste principal Sécurité des réseaux – Infonuagique Remote

Empire VieMontreal (administrative region), QC, CA
Remote
Full-time

Une société d'assurance basée au Canada recherche un Analyste principal(e) en sécurité des réseaux pour rejoindre une équipe dynamique dédiée à la protection des infrastructures réseau.Le candidat ... Show more

 • Promoted

Technical PM – Application Security for Banking (Montreal)

Trigyn TechnologiesMontreal (administrative region), QC, CA
Full-time

A major IT solutions provider is seeking a Technical Project Manager for a contract position in Montreal.This role involves managing security testing engagements and liaising with various stakehold... Show more

 • Promoted

IAM Governance Analyst (SailPoint) Remote

Nexus Systems Group Inc.Montreal (administrative region), QC, CA
Remote
Full-time

A leading technology consulting firm is seeking an IT Security Analyst to support the IAM Governance team.The role involves overseeing access management and ensuring compliance with security measur... Show more

 • Promoted

Master Security Specialist

Ericssonmontreal (administrative region), qc, Canada
Full-time

Investigate, support, and/or lead the coordination of product security vulnerabilities, incidents, and urgent security situations in collaboration with Customer Security Directors, customer units, ... Show more

 • Promoted

Senior Security Analyst

MaintainXMontreal (administrative region), QC, CA
Full-time

We’re looking for a Security Analyst to support our security program across both regulated (FedRAMP) and non-regulated environments.This role focuses on security operations, vulnerability managemen... Show more

 • Promoted

REMOTE Protection & Controls Substation Engineer

JobotMontreal (administrative region), QC, CA
Remote
Full-time

REMOTE Protection & Controls Substation Engineer.Be among the first 25 applicants.This range is provided by Jobot.Your actual pay will be based on your skills and experience — talk with your recrui... Show more

 • Promoted

Fortinet Presales Security Specialist

FortinetMontreal (administrative region), QC, CA
Full-time

Join Fortinet as a Presales Security Specialist focused on mid-market customers.Your expertise in technical sales will play a vital role in securing client success.Fortinet is in search of a Presal... Show more

 • Promoted

Expert(e) en cybersécurité - Cyber Security Expert - Montréal

Equans Services Canada & USMontreal (administrative region), QC, CA
Full-time

We are seeking a skilled and proactive.This role requires a strong balance of hands‑on technical skills, project leadership, and excellent communication abilities.You will work alongside other team... Show more

 • Promoted

Montréal [Hybrid] - L3 CSIRT SOC Analyst

QUANTEAM - North America (RAINBOW PARTNERS Group)montreal (administrative region), qc, Canada
Full-time

As the founding entity of RAINBOW PARTNERS, Quanteam is a consulting firm specializing in Banking, Finance, and Financial Services.Guided by our core values of closeness, teamwork, diversity, and e... Show more

 • Promoted

Application Security Product Manager - Remote Position

Soho Square SolutionsMontreal (administrative region), QC, CA
Remote
Full-time

Be a key player as a remote Technical Product Manager with a focus on Application Security and Data platforms.Lead strategic product initiatives in a collaborative environment.This Technical Produc... Show more

 • Promoted

Remote Presales Engineer for Global Network Security

StealthWatchMontreal (administrative region), QC, CA
Remote
Full-time

A leading technology firm is seeking a Presales Engineer to join their team.This role offers the chance to work remotely from anywhere in Canada and requires expertise in network and security techn... Show more

 • Promoted

Remote Security GRC Specialist: Risk & Compliance

Tecsys Inc.Montreal (administrative region), QC, CA
Remote
Full-time

A leading technology company in Montreal is seeking a Security Governance, Risk and Compliance Specialist to enhance its security protocols.The role involves supporting security risk management, co... Show more

 • Promoted

Senior Security Engineer at Confluence Montreal

Confluencemontreal (administrative region), qc, Canada
Full-time

Shape the future of security at Confluence in Montreal as a Senior Security Engineer.Focus on vulnerability remediation and improve security practices across IT infrastructure.In this pivotal role,... Show more

 • Promoted

Security Engineer

LanceSoft, Inc.Montreal, Montreal (administrative region), CA
Full-time

Direct message the job poster from LanceSoft, Inc.Needs local as in-person is Mandate for the role.Privileged Access Management Senior Engineer to support implementation, enterprise rollout and ope... Show more

 • Promoted

Remote Security GRC Specialist: Risk & Compliance

TecsysMontreal (administrative region), QC, CA
Remote
Full-time

A leading supply chain solutions company in Montreal is seeking a Security Governance, Risk and Compliance specialist to enhance security practices and frameworks.The ideal candidate will work clos... Show more