
Security Analyst
Posted Aug 22

Posted Aug 22
This is a fully remote position, open to applicants in Canada.
• Take charge of the comprehensive vulnerability management lifecycle for servers, endpoints, network assets, and public-facing systems.
• Set up and maintain scanning engines, templates, asset groups, credentialed scanning, and scan schedules.
• Diagnose authentication issues and missing assets to guarantee thorough scanning coverage.
• Reassess and verify remediation efforts to ensure vulnerabilities are fully resolved.
• Monitor remediation efforts against SLAs, manage risk exceptions, and report on vulnerability posture and trends to stakeholders.
• Implement and oversee scan sensors/engines in a distributed, multi-site environment.
• Organize independent penetration tests, which include scoping, vendor engagement, findings triage, and tracking of remediation efforts.
• Conduct internal security assessments to validate detection and response mechanisms.
• Utilize CVSS scoring and contest vendor-assigned severity ratings when appropriate.
• Manage application security SAST/SCA scanning, onboard repositories, and oversee review cycles with development teams.
• Evaluate SAST/SCA findings, identify genuine positives, and drive remediation efforts alongside developers.
• Collaborate with development and cloud teams to integrate secure practices into the software development lifecycle.
• Investigate and suggest improvements to vulnerability management, testing, and application security practices.
• Assist in incident response preparedness and take part in tabletop exercises.
• Keep documentation up to date and maintain current tracking tools for the team.
• Remain informed about cybersecurity trends, tools, vulnerabilities, and best practices.
• Cross-train with cybersecurity colleagues and support team initiatives, special projects, and process enhancements.
• Bachelor’s degree in Computer Science, Information Security, Engineering, or a related discipline (or equivalent practical experience).
• Over 3 years of direct experience in vulnerability management, security testing, or roles focused on offensive security.
• Practical experience with an enterprise vulnerability management platform, including configuration of scan engines and credentialed scanning.
• Familiarity with application security testing concepts and tools (SAST/SCA) and the ability to effectively communicate findings to developers.
• Strong grasp of the Common Vulnerability Scoring System (CVSS) and methodologies for vulnerability assessment.
• Knowledge of penetration testing concepts and experience in coordinating or supporting third-party testing engagements.
• Proficient understanding of Linux and Windows operating systems, network protocols, and prevalent security tools.
• Awareness of cybersecurity frameworks such as NIST 800-53, NIST CSF, or ISO 27001.
• Desired certifications include OSCP, GIAC GPEN/GWAPT, CEH, CompTIA PenTest+, CySA+.
• Excellent problem-solving, documentation, and communication abilities, with the capacity to engage both technical and non-technical audiences.
• Demonstrated ability to juggle multiple security priorities in a dynamic and fast-paced environment.
• Previous experience in an IT Operations/Infrastructure position would be advantageous.
• The selected candidate must successfully pass background and reference checks.
• Comprehensive health and dental coverage.
• Paid vacation time.
• Participation in an employer-supported retirement savings plan.
Parallel Design Studio
Mercor
Phigenics
RWS Group
Get handpicked remote jobs straight to your inbox weekly.