Search jobs > Montreal, QC > Analyst management

Vulnerability Management Analyst

CAE
Montreal
$75.6K-$95.7K a year (estimated)
Full-time

About This Role

Vos principaux rôle et responsabilités

  • Être un collaborateur individuel et excellent joueur d’équipe qui a à cœur d’améliorer et de soutenir l’entreprise.
  • Coordonner et gérer la correction diligente des vulnérabilités de sécurité à travers un éventail de technologies.
  • Repérer, résoudre et documenter tout faux positif dans les résultats d’évaluation des vulnérabilités.
  • Posséder une bonne connaissance pratique de l’architecture Rapid7, des moteurs de balayage, des serveurs de collecte, des agents, des constructeurs de requêtes, des objectifs et des projets.
  • Collaborer avec les équipes des applications et les responsables de secteurs pour soumettre des lettres de risque afin de se conformer avec le cadre de sécurité informatique et de gestion des risques de l’entreprise.
  • Effectuer des évaluations hebdomadaires, mensuelles et ponctuelles de la vulnérabilité des serveurs, des systèmes utilisateur, des ressources réseau, des ressources publiques et des bases de données à l’aide de Rapid7, Burp Suite, SonarSource, Qualys, ou Mend.
  • Gérer les configurations d’analyse, notamment le groupement des ressources, l’authentification appropriée, la mise à jour des modèles de balayage, la mise à jour des pools de moteurs de balayage et la programmation des analyses et des rapports.
  • Gérer et dépanner les outils de gestion des vulnérabilités.
  • Surveiller l’état général de l’analyse des vulnérabilités, la vérification de l’état du moteur et la génération de rapports, et s’assurer de la réussite du balayage avec l’authentification appropriée.
  • Dépanner les balayages afin de détecter les ressources manquantes ou les balayages de ressources ayant eu une authentification incorrecte ou un échec d’authentification.
  • Créer des demandes d’assistance auprès du fournisseur d’outils d’analyse pour obtenir un soutien approprié.
  • Démontrer une bonne expérience pratique des outils DAST, SAST et SCA.
  • Faire le suivi de la correction des vulnérabilités au moyen du système de demandes d’assistance et effectuer une validation à l’aide d’analyses ponctuelles.
  • Se coordonner avec les équipes principales de réseau, de points de terminaison et de serveurs pour discuter des correctifs qui ne sont pas appliqués depuis longtemps, du niveau de correctif cible et des vulnérabilités courantes qui sont couvertes par le correctif correspondant.
  • Connaitre la méthode d’évaluation des vulnérabilités CVSS (Common Vulnerability Scoring System), les concepts d’exploitation et de mises à jour correctives.
  • Avoir une bonne connaissance des vulnérabilités des applications web, des outils d’évaluation et des méthodologies.
  • Avoir au moins 3 ans d’expérience pratique avec les outils de détection des vulnérabilités susmentionnées et 5 à 8 ans d’expérience dans le domaine de la sécurité de l’information.
  • CEH, Rapid7 Certified Administrator (obligatoire), Qualys Certification (obligatoire), Security+, ITIL ou d’autres certifications en matière de sécurité sont requises.
  • Le poste sera offert au candidat sélectionné dont la performance durant l’entretien et la vérification des antécédents et des références seront positives.
  • Ouvert uniquement aux candidats qui sont physiquement présents au Canada au moment de la candidature et qui sont citoyens canadiens ou résidents permanents.
  • Ce poste n’est pas ouvert aux candidats titulaires d’un visa ou d’un permis de travail.

Your main role and responsibilities

  • Be an individual contributor and a great team player with a mindset to improve and support the business.
  • Co-ordinate and manage timely remediation of security vulnerabilities across various technologies.
  • Identify, resolve, and document any false positive findings in vulnerability assessment results.
  • Have a good hands-on knowledge with Rapid7 architecture, scan engines, collector servers, agents, query builder, goals, and projects.
  • Collaborate with application teams and business unit owners to submit risk letters to comply with the organization's IT Security and Risk Management Framework.
  • Perform weekly / monthly and ad-hoc vulnerability assessments for servers, user systems, network assets, public-facing assets and databases using Rapid7, Burp Suite, SonarSource, Qualys, or Mend.
  • Manage scan configurations, including asset grouping and appropriate authentication; update scan templates; update scan engine pool;

and schedule scans and reports.

  • Manage and troubleshoot vulnerability management tools.
  • Monitor overall vulnerability scan status, engine health check, report generation and ensure successful scan completion with proper authentication.
  • Troubleshoot scans for any missing assets and assets scanned with improper authentication or authentication failure.
  • Open support case with scanning tools vendor for appropriate support.
  • Demonstrate good hands-on working experience with DAST, SAST & SCA tools.
  • Track vulnerability remediation via ticketing system and perform validation by ad hoc scans.
  • Coordinate with the core network, endpoint teams and server teams to discuss patches that are not applied for a longer time, target patch level, CVEs covered by the corresponding patches.
  • Be knowledgeable of the Common Vulnerability Scoring System (CVSS) vulnerability assessment method, operation concepts and corrective updates.
  • Have good knowledge of web application vulnerabilities, assessment tools and methodologies.
  • Have a minimum of 3 years of hands-on experience working with above said vulnerability tools and 5 to 8 years of experience in the information security domain.
  • CEH, Rapid7 Certified Administrator (Mandatory), Qualys Certification (Mandatory), Security+, ITIL or other security certifications are required.
  • Job offer is based on the positive screening & interview along with the positive background & reference check.
  • This position is only open to candidates who are physically present in Canada at the time of application and are Canadian citizens or permanent residents.
  • This job is not open to candidates on a Work Visa / Work Permit.

Position Type

Regular

CAE thanks all applicants for their interest. However, only those whose background and experience match the requirements of the role will be contacted.

Equal Opportunity Employer

CAE is an equal-opportunity employer committed to diversity, equity, and inclusion. As "One CAE," we take affirmative action to ensure equal opportunity for all applicants regardless of race, nationality, colour, religion, sex, gender identity and expression, sexual orientation, disability, neurodiversity, Veteran status, age, or other legally protected characteristics.

If you don't see yourself fully reflected in every job requirement listed in the job posting, we still encourage you to reach out and apply.

At CAE, everyone is welcome to contribute to our success. If reasonable accommodation is needed to participate in the job application or interview process, please get in touch with us at .

30+ days ago
Related jobs
CAE
Montreal, Quebec

Manage and troubleshoot vulnerability management tools. Be knowledgeable of the Common Vulnerability Scoring System (CVSS) vulnerability assessment method, operation concepts and corrective updates. Connaitre la méthode d’évaluation des vulnérabilités CVSS (Common Vulnerability Scoring System), les ...

Alltech Consulting Services
Montreal, Quebec

The candidate will be joining the Vulnerability Management team within the Firm’s Cyber Data Risk & Resilience organization. This position will work on Attack Surface Management (ASM). ...

Promoted
Hitachi Cyber
Blainville, Quebec

Rejoins l'équipe dynamique et innovante de systèmes de sécurité Hitachi en tant qu'analyste en sécurité de l'information et fais progresser ta carrière en cybersécurité vers de nouveaux sommets. Nos analystes de la sécurité de l'information travaillent depuis deux bureaux, l'un au Canada et l'autre ...

Promoted
Seargin
Canada

Ability to rapidly understand business requirements and communicate business. IT systems to meet business needs. They will be responsible for working closely with our business partners and within IT to understand and help shape the strategic drivers and tactical needs to successfully deliver an expe...

Promoted
LanceSoft, Inc.
Montreal, Quebec

Candidate needs to be familiar with external scan findings from third party cyber security ratings agencies and comfortable escalating vulnerabilities and initiating requests for immediate remediation. The candidate will be joining the Vulnerability Management team within the Firm’s Cyber Data Risk ...

Promoted
SageBeans RPO
Canada

Experience in security engineering, solution architecture, and business analysis to support the design of solutions that span people, processes, and technology. At least 3 years of experience as a Security Engineer. Experience working in a fast-paced security team supporting product/engineering func...

Promoted
Intuitive.Cloud
Canada

The Senior Cybersecurity Specialist will be responsible for developing and implementing comprehensive cybersecurity strategies and solutions, with a focus on Security Cloud Architecture and Risk Assessment. This requirement is to be part of Intuitive’s Cybersecurity Program and will be part of the C...

Promoted
National Bank
Montreal, Quebec

As a Business Analyst in the Cybersecurity team at National Bank, you’ll liaise with business teams and delivery teams. You’ll work in Agile mode and will be part of a squad that manages and delivers business and technology projects for different sectors. In this role, you’ll have the opportunity to...

Promoted
Produits forestiers Résolu
Montreal, Quebec

Subject matter expertise, including a solid working knowledge in SOC, EDR, network security, web security, mail security, and vulnerability management technologies. IT Security Operations Analyst. The information security team provides an IT secure environment by monitoring, analyzing, and protectin...

CAE
Montreal, Quebec

Conceptualize dashboards and reports to measure the evolution of our digital transformation, organizational value model, strategic objectives, operational performance, and the evolution of our Risk Management culture. Report and analyze strategic objectives and key results (OKRs) to track progress a...