
Security Specialist, Vulnerability Management
Posted Sep 9

Posted Sep 9
This is a fully remote position, open to applicants in Canada.
• Develop and manage a risk-based vulnerability management program across cloud environments, applications, Kubernetes, containers, network infrastructure, software supply chain, and cloud-managed customer-premises equipment.
• Ensure authoritative visibility into vulnerabilities across various asset classes including cloud, applications, containers, Kubernetes, network, endpoints, dependencies, firmware, and CPE.
• Create an inventory of the attack surface and establish coverage for both internet-facing and internal assets, encompassing cloud services, hosts, network devices, containers, Kubernetes clusters, applications, APIs, source code, dependencies, images, infrastructure as code, and CPE/firmware.
• Design, configure, and maintain both authenticated and unauthenticated scans, agent-based assessments, cloud-native checks, container and dependency scans, attack-surface discovery, and targeted validation tests.
• Assess, select, and manage vulnerability-management tools while integrating their results.
• Measure scan coverage, health, credential success, stale assets, and blind spots; enhance asset-to-owner mapping and data quality.
• Review findings to classify them as true positives, false positives, duplicates, accepted risks, mitigated conditions, or actionable vulnerabilities.
• Analyze CVE applicability based on versions, provenance, CPE/firmware bill of materials, reachability, configuration, exposure, privileges, exploit prerequisites, and controls.
• Validate significant findings through advisories, proof-of-concept analysis, logs, configuration evidence, package inspection, and non-production testing.
• Keep track of vulnerability intelligence and vendor advisories.
• Prioritize remediation efforts using CVSS, CISA KEV, EPSS, exploit availability, exposure, reachability, asset criticality, tenant/customer impact, and compensating controls.
• Define remediation and mitigation targets according to risk tiers and escalate vulnerabilities that are actively exploited or accessible via the internet.
• Create records for remediation and coordinate patches, upgrades, configuration changes, image rebuilds, dependency updates, firmware releases, and compensating controls.
• Confirm closure through rescans or equivalent evidence and manage documented risk exceptions.
• Evaluate vulnerabilities throughout the cloud-to-CPE service path, including device management, certificates, secrets, provisioning, telemetry, firmware delivery, and administrative interfaces.
• Identify impacted device models, hardware revisions, firmware branches, software components, and deployed cohorts.
• Develop integrations and automation for asset enrichment, deduplication, risk scoring, ticketing, ownership routing, SLA tracking, notifications, rescans, exception expiry, and evidence collection.
• Maintain dashboards that monitor coverage, exploitable exposure, aging, remediation performance, repeat findings, exceptions, ownership, and risk trends.
• Create playbooks, standards, and procedures for handling vulnerabilities, critical CVEs, zero-day responses, scanner administration, and tool outages.
• Provide reporting to technical owners and leadership, and assist with audits and customer security inquiries.
• 5+ years of hands-on experience in vulnerability management, vulnerability assessment, security engineering, product security, cloud security, or a closely related field.
• Proven ownership of enterprise scanning and vulnerability-management workflows.
• Strong CVE analysis capabilities with the ability to determine applicability and exploitability.
• Experience with enterprise vulnerability platforms and associated cloud, container, dependency, application, and open-source scanning tools.
• Working knowledge of CVE/CWE, NVD, CVSS, CISA KEV, EPSS, vendor advisories, SBOMs, and risk-based prioritization.
• Practical knowledge of Linux, TCP/IP, DNS, TLS/PKI, identity and access controls, APIs, cloud infrastructure, containers, and Kubernetes.
• Ability to read code, package manifests, container images, configurations, logs, and network evidence.
• Proficiency in scripting or programming languages such as Python, Go, PowerShell, Bash, or similar.
• Experience integrating security platforms with APIs, ticketing systems, and dashboards.
• Excellent written and verbal communication skills.
• Bachelor’s degree in cybersecurity, computer science, engineering, or equivalent practical experience.
• Preferred: security experience with service providers, broadband operators, telecom equipment/software vendors, managed-network providers, or distributed device fleets.
• Preferred: experience assessing embedded Linux, firmware, broadband gateways, routers, ONTs, Wi-Fi/mesh systems, or CPE/IoT products.
• Preferred: familiarity with TR-069/CWMP, TR-369/USP, TR-181, ACS/USP controllers, provisioning, telemetry, certificates, and remote firmware lifecycle management.
• Preferred: experience with Google Cloud Platform, Kubernetes, Terraform, Helm, CI/CD, and cloud-native security platforms.
• Preferred: experience with software composition analysis, SBOM/VEX, container/image scanning, secret scanning, SAST/DAST/API security testing, and infrastructure-as-code scanning.
• Preferred: experience with coordinated vulnerability disclosure, penetration-test finding intake, zero-day response, or product security incident response.
• Preferred: familiarity with NIST Cybersecurity Framework, NIST SP 800-40, CIS Controls, OWASP guidance, PCI DSS, SOC 2, or ISO 27001.
• Preferred: relevant certifications such as Security+, CySA+, GSEC, GCIH, GPEN, CISSP, CCSP, or vendor-specific credentials.
• Work primarily during standard business hours, with on-call responsibilities for critical, actively exploited, or zero-day security escalations.
• Strict access controls for sensitive vulnerability, exploit, and customer information based on need-to-know principles.
• Coordinate intrusive scans, validation tests, and production-impacting work through approved change and maintenance processes.
• Escalation availability for critical, actively exploited, or zero-day vulnerabilities.
• Equal opportunities and a non-discrimination policy.
• An inclusive and diverse working environment.
Sony Interactive Entertainment
Squads
Neo4j
PingWind Inc. (SDVOSB)
Get handpicked remote jobs straight to your inbox weekly.