remote
Senior Cybersecurity Specialist - Vulnerability Management - Bank of Canada
Security Engineer
Lead enterprise‑wide vulnerability management, orchestrating scans, assessments, and remediation across critical banking systems using tools like Nessus, Qualys, and SIEM platforms, while ensuring compliance with regulatory frameworks and driving continuous security improvement.
About the role
Key Responsibilities
- Design, implement, and maintain vulnerability scanning programs across cloud, on‑premises, and hybrid environments.
- Analyze scan results, prioritize findings, and collaborate with engineering and operations teams to remediate risks.
- Conduct penetration tests and advanced threat simulations to validate controls and uncover hidden vulnerabilities.
- Develop and enforce vulnerability management policies, metrics, and reporting aligned with regulatory and industry standards.
- Integrate threat intelligence feeds and SIEM data to enhance detection and response capabilities.
- Lead incident response activities related to discovered vulnerabilities and coordinate with cross‑functional teams.
Requirements
- 5+ years of experience in vulnerability management, penetration testing, or related cybersecurity roles.
- Strong knowledge of regulatory frameworks (PCI‑DSS, ISO 27001, NIST) and risk assessment methodologies.
- Excellent communication skills, able to translate technical findings into actionable business recommendations.
- Relevant certifications (e.g., CISSP, OSCP, CEH, or CISA) preferred.
Skills
penetration testing