Talent.com
Thales
Cybersecurity Vulnerability EngineerThales • Ottawa, ON, Canada
Cybersecurity Vulnerability Engineer

Cybersecurity Vulnerability Engineer

Thales • Ottawa, ON, Canada
2 days ago
Job type
  • Full-time
Job description

Location: Ottawa, Canada In fast changing markets, customers worldwide rely on Thales. Thales is a business where brilliant people from all over the world come together to share ideas and inspire each other. In aerospace, transportation, defence, security and space, our architects design innovative solutions that make our tomorrow's possible. For decades, Ottawa has been a global technology leader. Today, Canada’s capital holds one of the brightest and most diverse technological ecosystems in North America. Voted as Canada’s best place to live 2017 by Maclean's, Ottawa offers a low cost of living with a high quality of life. The Thales Ottawa office has been a major supplier and long-term trusted partner to DND, enabling the Canadian Armed Forces and the Canadian Coast Guard to achieve mission success.

This is a remote and localized role in Ottawa, ON.

Position Summary

Cyberattacks have been on the rise around the globe, with hackers and other criminals targeting businesses large and small to steal valuable information or bring computer networks to a halt. Cyber Security analysts are valued for their ability to protect an organization’s information and systems from such attacks. This position is responsible for providing ongoing information security services to all aspects of the on premise and cloud corporate IT environments. The Cybersecurity Vulnerability Engineer will require working across several security functions and have a strong primary focus on incident response activities.

Key Areas of Responsibility

  • Must be able to monitor and evaluate newly disclosed and emerging vulnerabilities from Thales CTI, OSINT, Thales CERT, PSIRT, vendor advisories, security researchers, vulnerability databases, and other trusted sources.
  • Must be able to Initiate and coordinate enterprise vulnerability-response activities for vulnerabilities with potential impact to Thales businesses and networks.
  • Must be able to Engage infrastructure, IT, application, cloud, product, and security teams to validate exposure and determine required actions.
  • Must have working knowledge of threat actor tactics and techniques.
  • Must be able to establish clear ownership, priorities, response timelines, and escalation paths.
  • Must be able to track remediation and mitigation activities through completion and validate that identified risk has been appropriately addressed.
  • Must be able to escalate missed timelines, unresolved ownership, significant technical uncertainty, or material residual risk to appropriate leadership.
  • Must be able to maintain clear status reporting for technical teams, cybersecurity leadership, and other stakeholders.
  • Must be able to analyze newly disclosed vulnerabilities to understand affected components, exploitation prerequisites, attack vectors, required privileges, exploitability, potential impact, and available mitigations.
  • Must be able to review CVEs, vendor advisories, security-research publications, proof-of-concept information, exploit intelligence, and relevant technical documentation.
  • Must be able assess whether vulnerable technologies or configurations are present in the enterprise and partner with technology owners to validate actual exposure.
  • Responsible for translating complex vulnerability information into clear, actionable guidance for infrastructure, application, product-development, and leadership teams.
  • Responsible for partnering with detection and incident-response teams when a vulnerability requires investigation for possible prior exploitation or additional monitoring.

Basic Qualifications

  • Bachelor’s degree in computer information systems, programming, engineering or a related field with a minimum of 5+ years of cybersecurity experience, including at least 3–4 years in vulnerability management, vulnerability analysis, security engineering, incident response, threat intelligence, penetration testing, or a closely related technical security function.
  • 5 to 7 years of experience in Cybersecurity domains.
  • 3 to 5 years of experience in demonstrated experience analyzing CVEs and determining their relevance and actual impact within complex enterprise environments.
  • Strong understanding of vulnerability exploitation, attack paths, operating systems, enterprise applications, networking, authentication, privilege boundaries, and common security controls.
  • Ability to interpret vendor advisories, technical security research, proof-of-concept information, logs, configurations, and vulnerability evidence.
  • Working knowledge of Windows and Linux environments, network infrastructure, cloud technologies, virtualization, containers, and enterprise applications.
  • Ability to independently coordinate urgent, cross-functional technical response activities involving multiple teams and competing priorities.
  • Strong organizational skills and the ability to track multiple concurrent vulnerability-response activities through closure.

Preferred Qualifications

  • Strong knowledge of all aspects of information security within the Prevent, Detect and Respond domains.
  • Must be highly analytical and detail-oriented, with organizational skills to manage assigned work to completion.
  • Experience supporting large, complex, or globally distributed enterprise environments.
  • Experience working across corporate IT, shared infrastructure, software-development, cloud, and product environments.
  • Experience using scripting or automation with Python, PowerShell, APIs, SQL, or similar technologies to support vulnerability analysis and data correlation.

Physical Demands

Typical Office environment

Special Position Requirements

Schedule: First Shift Monday through Friday; Core Business Hours Monday-Friday, etc.

Regulatory Compliance Requirements

Canada

Access to Trade Controlled Hardware, Software, Technical Information, Controlled Goods Program Clearance & Secret Security Clearance

What We Offer

  • Thales provides an extensive benefits program for all full-time employees working 24 or more hours per week and their eligible dependents, including the following:
  • Company paid Extended Health, Dental, HSA, Life, AD&D, Short-term Disability, Cancer Care Program, travel insurance, Employee Assistance Plan and Well-Being program.
  • Retirement Savings Plans (RRSP, DCPP, TFSA) with a company contribution and a match to a DCPP, with no vesting period.
  • Company paid holidays, vacation days, and paid sick leave.
  • Voluntary Life, AD&D, Critical Illness, Long-Term Disability.
  • Employee Discounts on home, auto, and gym membership.

Thales provides an extensive benefits program for all full-time employees working 24 or more hours per week and their eligible dependents, including the following:

  • Company paid Extended Health, Dental, HSA, Life, AD&D, Short-term Disability, Cancer Care Program, travel insurance, Employee Assistance Plan and Well-Being program.
  • Retirement Savings Plans (RRSP, DCPP, TFSA) with a company contribution and a match to a DCPP, with no vesting period.
  • Company paid holidays, vacation days, and paid sick leave.
  • Voluntary Life, AD&D, Critical Illness, Long-Term Disability.
  • Employee Discounts on home, auto, and gym membership.

Why Join Us?

The reference Total Target Compensation(TTC) market range for this position, inclusive of annual base salary and the variable compensation target, is between Total Target Cash 123,459.00 - 172,842.60 CAD Annual. This reflects how companies in a similar industry and geographic region generally pay for similar jobs. This range helps the Company make pay decisions as one data point among many. Where a position falls within this range is also dependent on other factors including – but not limited to – the employee’s career path history, competencies, skills and performance, as well as the company’s annual salary budget, the customer’s program requirements, and the company’s internal equity. Thales may offer additional benefits and other compensation, depending on circumstances not related to an applicant’s status protected by local, state, or federal law.

We use artificial intelligence-enabled tools as part of our recruitment process to support activities such as candidate discovery, résumé matching, interview scheduling. These tools may help screen and assess applications and recommend potential matches based on the requirements within the job description. All hiring decisions, including candidate evaluation, selection, and disposition, are made by human recruiters. Artificial intelligence does not make hiring decisions on our behalf.

Thales is an equal opportunity employer which values diversity and inclusivity in the workplace. Thales is committed to providing accommodations in all parts of the interview process. Applicants selected for an interview who require accommodation are asked to advise accordingly upon the invitation for an interview. We will work with you to meet your needs. All accommodation information provided will be treated as confidential and used only for the purpose of providing an accessible candidate experience.

This position requires direct or indirect access to hardware, software or technical information controlled under the Canadian Export Control List, the Canadian Controlled Goods Program, the Canadian Industrial Security Program, the US International Traffic in Arms Regulations (ITAR) and/or the US Export Administration Regulations (EAR). All applicants must be eligible or able to obtain authorization for such access including eligibility to the Canadian Controlled Goods Program and able to obtain a Canadian NATO Secret clearance.

#J-18808-Ljbffr
Create a job alert for this search

Cybersecurity Vulnerability Engineer • Ottawa, ON, Canada

Similar jobs

Lead Platform Engineer Enhancing DevOps and System Reliability

Lillio (formerly HiMama)Ottawa, ON, CA
Full-time

Transform early childhood education as a Senior Platform Engineer focused on system performance and collaborative tooling.Drive key initiatives for scalable, reliable digital platforms.In this pivo... Show more

 • Promoted

Lead Cybersecurity Manager for QNX Systems

BlackBerry Inc.Ottawa, ON, CA
Full-time

Become the Lead Cybersecurity Manager at BlackBerry, guiding teams to achieve and maintain ISO 21434 compliance.Your insights will shape the security architecture for critical automotive systems.In... Show more

 • Promoted

Hybrid Cybersecurity Forward-Deployed Engineer

Blue Signal SearchOttawa, ON, CA
Full-time

An innovative cybersecurity recruiting firm is seeking a Senior Executive Recruiter in Ottawa, Ontario.This role involves deploying advanced security and cloud solutions, as well as collaborating w... Show more

 • Promoted

Lead Cybersecurity Manager For Qnx Systems

BlackBerry Inc.Ottawa, Canada
Full-time

Become the Lead Cybersecurity Manager at BlackBerry, guiding teams to achieve and maintain ISO 21434 compliance.Your insights will shape the security architecture for critical automotive systems.In... Show more

 • Promoted

HPE Senior Cybersecurity Initiative Lead

Hewlett Packard Enterpriseottawa, on, Canada
Full-time

Hewlett Packard Enterprise (HPE) is hiring a Senior Cybersecurity Initiative Lead focused on strengthening risk posture and regulatory compliance.This key role involves working closely with cyberse... Show more

 • Promoted

Cybersecurity Engineer for Air & Naval Defense

General Dynamics Mission Systems–CanadaOttawa, ON, CA
Full-time

Step into a vital role as a Cybersecurity Engineer for General Dynamics Mission Systems–Canada within our Air & Naval division.Focus on developing and implementing security solutions to defend agai... Show more

 • Promoted

Cybersecurity System Engineering, Air & Naval

General Dynamics Mission Systems–CanadaOttawa, Ontario, Canada
Full-time

General Dynamics Mission Systems–Canada has an opportunity for a new Cybersecurity Engineer to join our Air & Naval division.Our team is growing and looking for additional team members to help solv... Show more

 • Promoted

Senior Threat Detection & Response Engineer

1PasswordOttawa, ON, CA
Full-time

A leading cybersecurity company in Canada seeks a Senior Security Engineer to enhance threat detection and response capabilities.You will design systems for threat detection, lead incident response... Show more

 • Promoted

Cybersecurity IT Systems Engineer - Ottawa

Sopra SteriaOttawa, ON, CA
Full-time

Sopra Steria is seeking a Cybersecurity IT Systems Engineer in Ottawa to support a government Cyber Range platform deployment.Engage in training and ongoing technical support.In this role, you'll b... Show more

 • Promoted

Senior Site Reliability Engineer, Node Platform

Chainlink LabsOttawa, ON, CA
Full-time

Chainlink is the industry-standard oracle platform bringing the capital markets onchain and powering the majority of decentralized finance (DeFi).The Chainlink stack provides the essential data, in... Show more

 • Promoted

Senior OT and Cybersecurity Systems Specialist

Adga-Groupottawa, on, Canada
Full-time

Senior OT and Cybersecurity Systems Specialist.Compensation: CAD 100 - CAD 120 per hour.ADGA Group is a Canadian-owned defence and security company that provides integrated, mission‑critical techni... Show more

 • Promoted

Forward Deployed Engineer

H2 AnalyticsOttawa, ON, CA
Full-time

H2 Analytics is a mission-focused technology company redefining how intelligence specialists train and modernize.We partner with military, national security, law enforcement, and other mission-driv... Show more

 • Promoted

Cloud Solutions Deployment Engineer - Ottawa

Cord3 Innovation Inc.Ottawa, ON, CA
Full-time

Elevate your career as a Cloud Deployment Engineer with Cord3 Innovation Inc.This hybrid role focuses on deploying versatile DCS solutions across various environments.As a part of the Delivery team... Show more

 • Promoted

Diamond Services Engineer

Check-Point-Software-Technologies-2Ottawa, ON, CA
Full-time

As the world’s leading vendor of Cyber Security, facing the most sophisticated threats and attacks, we’ve assembled a global team of the most driven, creative, and innovative people.At Check Point,... Show more

 • Promoted

Cybersecurity Channel Solutions Engineer

Marler & Associates SearchOttawa, ON, CA
Full-time

A global cybersecurity firm is seeking a Channel Solutions Engineer to empower strategic partners and enhance technical capabilities.You will provide support as a trusted technical advisor, focusin... Show more

 • Promoted

Lead Cybersecurity Manager For Qnx Systems - $108,750 - $158,750 A Year

BlackBerryOttawa, Canada
Full-time

Worker Sub-Type: Regular Job Description: QNX, a division of BlackBerry Limited (NYSE: BB; TSX: BB), provides the trusted foundation that software-defined and physical AI systems depend on to o... Show more

 • Promoted

Architecte de solutions, Cybersécurité

Bank of Canadaottawa, on, Canada
Full-time

La Banque du Canada s’est donnée comme vision d’être une banque centrale influente – dynamique, engagée et digne de confiance – mobilisée pour un Canada meilleur.Aucun autre employeur ne vous offri... Show more

 • Promoted

AWS Infrastructure Security Engineer Opening

Orion Innovationottawa, on, Canada
Full-time

Elevate our security practices as an AWS Infrastructure Security Engineer.This senior position offers you the chance to design and implement secure, cloud-native infrastructures that protect enterp... Show more

 • Promoted

Lead Cybersecurity Manager For Qnx Systems

BlackBerryOttawa, Canada
Full-time

Worker Sub-Type: Regular Job Description: QNX, a division of BlackBerry Limited (NYSE: BB; TSX: BB), provides the trusted foundation that software-defined and physical AI systems depend on to o... Show more

 • Promoted

Senior DevSecOps Engineer – Blockchain & Cloud Security

FigmentOttawa, ON, CA
Full-time

A leading blockchain infrastructure provider in Canada seeks a Senior DevOps Engineer to enhance security and scalability in blockchain systems.This remote-first role requires strong expertise in D... Show more