Talent.com
Aarorn Technologies
Remote Vulnerability Management Specialist Application SecurityAarorn Technologies • Saint-Bruno-de-Montarville, Quebec
Remote Vulnerability Management Specialist Application Security

Remote Vulnerability Management Specialist Application Security

Aarorn Technologies • Saint-Bruno-de-Montarville, Quebec
30+ days ago
Job type
  • Full-time
  • Remote
Job description

Role: Vulnerability management (Remote, Canada)
Location: Remote (Canada)
Employment Type: Contract
Work Authorization: Open Work Permit (OWP), PR, Canadian Citizen only

Mandatory skills for vulnerability management we are looking for the candidate having below key skills:

Regarding skills for appsec. We need below hands-on experience and not only tool based.

AppSec:

Web Application Security

Mobile Application Security

API Security

SAST (Static Application Security Testing), SCA (Software Composition Analysis)

Vulnerability Management lifecycle

VM: Risk Assessment & Prioritization
Ability to assess vulnerabilities based on risk, not just severity—considering CVSS scores, exploitability, asset criticality, business impact, and threat intelligence to prioritize remediation effectively.

Vulnerability Scanning & Tool Proficiency
Hands-on expertise with vulnerability scanning tools (e.g., Nessus, Qualys, Rapid7, OpenVAS) and the ability to interpret scan results accurately, reduce false positives, and tune scans for different environments.

Patch & Remediation Management
Strong coordination skills to drive timely patching and mitigation—working with IT, cloud, DevOps, and application teams to remediate vulnerabilities while minimizing operational and business disruption.

Reporting & Stakeholder Communication
Ability to translate technical vulnerability data into clear, actionable reports for different audiences (engineers, management, auditors), including dashboards, trends, SLAs, and risk narratives.

Compliance & Continuous Improvement
Knowledge of security frameworks and standards and the skill to embed vulnerability management into continuous security processes, audits, and metrics-driven improvement.

Job Description:

"Summary

The Vulnerability Management Specialist – Application Security is responsible for end to end management of application security vulnerabilities across the SDLC using SAST, DAST, and SCA tools, with a strong focus on risk based prioritization, remediation tracking, and posture visibility through ASPM platforms.

Technical Skills

Strong hands on experience with:

• SAST (e.g., AppScan, Check Marx, GitHub Advanced Security)

• DAST tools and runtime testing approaches

• SCA / OSS security and dependency risk analysis

Working knowledge of ASPM platforms and vulnerability aggregation.

Understanding of OWASP Top 10, secure coding practices, and application threat models.

Soft Skills:

• Must be from global support background.

• Strong documentation, presentation, and communication skills

Experience

• 8-10 + years of experience in application security or vulnerability management roles.

• Experience supporting enterprise scale AppSec programs with multiple applications and teams.

Key -Responsibilities

• Interpret findings across SAST, SCA, Secrets, API and Mobile scanning (tools like GitHub Advanced Security, Traceable, etc)

• Hand-off findings to development teams for remediation

• Provide technical remediation assistance to product development teams

• Track and report remediation progress

• Facilitate extension requests for remediation timelines

• Collaborate across teams using JIRA for ticketing and dashboards

• Familiarity with RBVM/ASPM tools like ArmorCode, Seemplicity, Brinqa a plus.

• Should have good knowledge of information security areas as Vulnerability Management Lifecycle, hardening controls (CIST, NIST) etc.

• Good understanding of information security related fields, including security operations and administration

• Should possess good understanding of assets, threats and vulnerabilities and their correlation in an organization

• Good understanding of vulnerability reports from tools like Qualys/ Tenable etc.

• Hands on experience on vulnerability prioritization tool, RiskSense or Kenna would be a plus

• Strong practical knowledge of vulnerability remediation tracking across infrastructure, applications, and teams/ 3rd parties

• Knowledge on vulnerability exception management process

• Strong practical knowledge on presenting vulnerability remediation tracking updates to the management

• Hands on experience on vulnerability patching

• Should have a good customer handling skill

• Good to have Experience on vulnerability scanning tools Like Qualys and Tenable.

Create a job alert for this search

Remote Vulnerability Management Specialist Application Security • Saint-Bruno-de-Montarville, Quebec

Similar jobs

Senior Security Engineer (Detection & Response) - $119,000 - $225,500 A Year

ScribdVarennes, Canada
Full-time

Senior Security Engineer focused on Detection & Response, developing long-term detection and response capabilities, designing telemetry, and reducing mean time to detect and respond. Show more

 • Promoted

Senior Sdet - Ai-Driven Cloud Security - C$106,000 - C$141,500 A Year

Cybersecurity CompanyVarennes, Canada
Full-time

Seeking a Senior Software Developer in Test to develop and maintain automated test suites for cloud security products using AI-assisted testing strategies. Show more

 • Promoted

Cyber Security Analyst - Soc & Incident Response (6-Month) - C$73,336 - C$110,004 A Year

A leading technology firmBoucherville, Canada
Full-time

Experienced Cyber Security Analyst needed in Ottawa to design controls, investigate incidents, and perform vulnerability assessments. Show more

 • Promoted

EHS Compliance Specialist La Prairie

Business Integra IncLa Prairie, QC, CA
Full-time

Become an EHS Compliance Specialist II with GEV in La Prairie, Quebec.This role requires fluency in French and English and 5 years of experience in industrial health and safety.Reporting directly t... Show more

 • Promoted

Network Security Test Engineer — Vulnerability & Protocols - $115,700 - $142,300 A Year

Ciena CorporationVarennes, Canada
Full-time

The Network Security Test Engineer will test and validate network security, creating test plans and automating testing. Show more

 • Promoted

Specialist, HSSEQ Event Investigation

WSP in CanadaBrossard
Full-time

As a Specialist, HSSEQ Investigations, you will play a critical role in strengthening our safety culture by leading complex investigations into health, safety, environmental, and quality events.You... Show more

 • Promoted

Remote Momentum Systems Engineer O&M & Security - $82,100 - $172,400 A Year - Remote

CACI International Inc.Boucherville, Canada
Remote
Full-time

Seeking a remote Momentum Systems Engineer to support financial and acquisition management systems, requiring 5+ years of experience and strong technical skills. Show more

 • Promoted

Senior Consultant, Security Systems Design

WspBoucherville, Canada
Full-time

Create safer spaces with WSP as a Senior Consultant in Security Systems Design based in Ottawa.Lead innovative projects that integrate strategic security practices with modern technology.As a vital... Show more

 • Promoted

Customer Solutions Architect - Cyber Security Federal - C$116,000 - C$155,000 A Year

SoftchoiceBoucherville, Canada
Full-time

Seeking a Cyber Security Solutions Architect for the Canadian federal government, focusing on creating integrated security solutions.Requires senior pre-sales experience and technical depth in cybe... Show more

 • Promoted

Leader en Cybersécurité chez Solotech

Groupe Solotech Incmontréal- st, qc, Canada
Full-time

Rejoignez Solotech comme Leader en Cybersécurité et façonnez notre avenir numérique.Prenez en charge les opérations de sécurité et participez à la gouvernance cybernétique.Le rôle implique la direc... Show more

 • Promoted

Hybrid Cloud Security Engineer — Ottawa - C$78,627.8 - C$130,038.3 A Year

Thales GroupVarennes, Canada
Full-time

Cloud Security Engineer needed to respond to incidents, provide guidance, and analyze security logs. Show more

 • Promoted

Configuration Specialist (Ivalua) - $60,000 - $110,000 A Year - Remote

CgiVarennes, Canada
Remote
Full-time

Configures and customizes the Ivalua platform by translating business requirements into technical specifications and documentation.Conducts testing, troubleshooting, and data migration, requiring S... Show more

 • Promoted

Senior Consultant, Cloud Security - C$84,000 - C$128,000 A Year

BDO CanadaBoucherville, Canada
Full-time

Seeking a Cloud Security Senior Consultant to lead cloud security assessments and implementations for clients, designing Zero-Trust architectures and advising on data protection and identity manage... Show more

 • Promoted

Senior Cloud Security Operations Engineer - C$89,968 - C$182,564 A Year

ThalesVarennes, Canada
Full-time

The Senior Cloud Security Operations Engineer will lead efforts to secure multi-cloud environments, monitor threats, respond to incidents, and ensure compliance with industry standards. Show more

 • Promoted

Brossard Matterport Pro3 Specialist

AeroFrohne LLCBrossard, Montérégie, CA
Full-time

AeroFrohne seeks an independent Matterport Pro3 Technician in Brossard, Quebec, to enhance virtual tour experiences.Use your skills to capture, edit, and manage 3D modeling projects.As a Matterport... Show more

 • Promoted

Spécialiste/analyste en cybersécurité (ménaces et vulnérabilités)

FOP ConsultantsBrossard
Full-time

Consultant analyste/spécialiste en cybersécurité (menaces et vulnérabilités).FOP EXPERTS CONSEILS recherche des consultants motivés à la réalisation de mandats dans le secteur des technologies de l... Show more

 • Promoted

Cyber Security Manager Enhancing Project Compliance and Resilience

AlstomSaint-Bruno-De-Montarville
Full-time

Leverage your cybersecurity expertise to enhance the safety of transportation projects.Work alongside diverse teams to safeguard systems and ensure compliance with industry standards.As a Cyber Sec... Show more

 • Promoted

Electronics Team Leader – Security Systems

ADGA GroupJoliette, Lanaudière, Canada
Full-time

A Canadian defence technology firm is seeking an Electronics Technician Team Leader in Joliette, Canada.This role involves leading a team in the maintenance of advanced electronic security systems ... Show more

 • Promoted

Senior Engineer – Security Engineering - C$93,600 - C$149,400 A Year - Remote

CienaVarennes, Canada
Remote
Full-time

Develops and implements features for the Ciena Secure Signing Platform (CSSP), integrating security tools and contributing to its architectural evolution. Show more

 • Promoted

Senior Consultant Cyber Security - C$56.3 - C$67.2 An Hour

KpmgBoucherville, Canada
Full-time

Assess cyber maturity, design governance frameworks, and implement roadmaps.Deliver advisory services and support cyber training. Show more