Data First Jobs

LanceSoft, Inc.

Vulnerability Management Analyst

Contract · In Office · Toronto, Ontario (Canada)

Posted Jul 28, 2026

Work Options
Cloud Stack
Skills
Job Type
Position Group
  • Pay Range: CAD 45-50/hr
  • Role Summary
  • We are looking for an Intermediate Infrastructure Vulnerability Management Analyst to support enterprise security operations by identifying, assessing, prioritizing, and driving remediation of vulnerabilities across infrastructure and applications.
  • The role requires strong hands-on experience with vulnerability scanning tools (Qualys, Nessus, Rapid7), risk-based triage, and alignment with frameworks such as CVSS and threat intelligence (e.g., CISA KEV) to reduce organizational risk exposure.
  • ________________________________________
  • Key Responsibilities
  • Must Have: Ansible and Playbooks
  • Vulnerability Management & Analysis
  • • Execute the end-to-end vulnerability management lifecycle – discovery, analysis, triage, prioritization, and remediation tracking
  • • Analyze vulnerability scan outputs from tools such as Qualys, Nessus, Rapid7
  • • Perform false positive validation and exception handling
  • • Conduct vulnerability impact analysis across infrastructure, applications, and platforms
  • Risk Assessment & Threat Prioritization
  • • Perform risk-based vulnerability assessments using:
  • o CVSS scoring and business impact
  • o Threat context and exploitability insights
  • • Use external threat intelligence sources (e.g., CISA Known Exploited Vulnerabilities – KEV) to prioritize remediation
  • • Align remediation timelines based on risk severity and exposure
  • Vulnerability Triage & Reporting
  • • Perform detailed triage of vulnerabilities based on:
  • o Severity, exploitability, asset criticality
  • • Generate dashboards and reports on:
  • o Vulnerability status
  • o Risk posture
  • o SLA adherence and remediation progress
  • • Support audit readiness and compliance reporting
  • Threat Modeling & Security Analysis
  • • Participate in threat modeling exercises to identify potential attack vectors
  • • Evaluate security risks within infrastructure and application ecosystems
  • • Provide recommendations to strengthen system security posture
  • Patch & Remediation Management
  • • Coordinate and validate patch management for OS, middleware, and applications
  • • Track remediation SLAs and ensure timely closure of vulnerabilities
  • • Collaborate with infrastructure and application teams for remediation execution
  • Stakeholder Collaboration
  • • Work closely with:
  • o Security teams
  • o Infrastructure / server teams
  • o Application owners
  • • Communicate risk and remediation strategies clearly to both technical and business stakeholders
  • ________________________________________
  • Required Skills & Experience
  • Experience
  • • 3–5 years of experience in:
  • o Vulnerability Management / Security Operations
  • o Infrastructure Security or IT Operations
  • ________________________________________
  • Technical Skills
  • • Hands-on experience with:
  • o Qualys, Nessus, Rapid7 (or similar vulnerability tools)
  • • Strong understanding of:
  • o Vulnerability lifecycle (discovery → remediation → closure)
  • o CVE / CVSS scoring models
  • o Risk-based prioritization and threat analysis
  • • Knowledge of:
  • o Threat modeling concepts
  • o CISA KEV / threat intelligence-based prioritization
  • • Strong exposure to:
  • o Patch management (OS, middleware, applications)
  • ________________________________________
  • Preferred / Good-to-Have
  • • Experience with:
  • o ITSM tools (ServiceNow preferred)
  • o Scripting (Python, PowerShell, Shell)
  • o Security monitoring / SIEM tools
  • • Knowledge of:
  • o Compliance frameworks (ISO 27001, PCI-DSS, etc.)
  • o Cloud environments (AWS, Azure, VMware)
  • ________________________________________
  • Key Competencies
  • • Strong analytical and problem-solving capabilities
  • • Ability to interpret complex vulnerability data and translate into actionable remediation
  • • Good communication skills for cross-team collaboration
  • • Ability to manage multiple vulnerabilities in SLA-driven environments
  • ________________________________________
  • Role Title Variants
  • • Infrastructure Security Analyst – Vulnerability Management
  • • Cyber Security Analyst – Vulnerability & Risk
  • • Vulnerability Management Engineer (Intermediate)

Mention you found this on Data First Jobs — it helps us bring you more roles like this.

Vulnerability Management Analyst

LanceSoft, Inc.

Like this role? Get carefully selected jobs like it, twice a week, straight to your inbox.

Free, no spam. Unsubscribe anytime.