Security Specialist, Vulnerability Management

atAXON NetworksRemoteCA flagCanadaFreelanceCybersecurity / Security EngineerMid-levelSeniorC$60 – C$90/hour

Posted Sep 9

This is a fully remote position, open to applicants in Canada.

📋 Description

• Develop and manage a risk-based vulnerability management program across cloud environments, applications, Kubernetes, containers, network infrastructure, software supply chain, and cloud-managed customer-premises equipment.

• Ensure authoritative visibility into vulnerabilities across various asset classes including cloud, applications, containers, Kubernetes, network, endpoints, dependencies, firmware, and CPE.

• Create an inventory of the attack surface and establish coverage for both internet-facing and internal assets, encompassing cloud services, hosts, network devices, containers, Kubernetes clusters, applications, APIs, source code, dependencies, images, infrastructure as code, and CPE/firmware.

• Design, configure, and maintain both authenticated and unauthenticated scans, agent-based assessments, cloud-native checks, container and dependency scans, attack-surface discovery, and targeted validation tests.

• Assess, select, and manage vulnerability-management tools while integrating their results.

• Measure scan coverage, health, credential success, stale assets, and blind spots; enhance asset-to-owner mapping and data quality.

• Review findings to classify them as true positives, false positives, duplicates, accepted risks, mitigated conditions, or actionable vulnerabilities.

• Analyze CVE applicability based on versions, provenance, CPE/firmware bill of materials, reachability, configuration, exposure, privileges, exploit prerequisites, and controls.

• Validate significant findings through advisories, proof-of-concept analysis, logs, configuration evidence, package inspection, and non-production testing.

• Keep track of vulnerability intelligence and vendor advisories.

• Prioritize remediation efforts using CVSS, CISA KEV, EPSS, exploit availability, exposure, reachability, asset criticality, tenant/customer impact, and compensating controls.

• Define remediation and mitigation targets according to risk tiers and escalate vulnerabilities that are actively exploited or accessible via the internet.

• Create records for remediation and coordinate patches, upgrades, configuration changes, image rebuilds, dependency updates, firmware releases, and compensating controls.

• Confirm closure through rescans or equivalent evidence and manage documented risk exceptions.

• Evaluate vulnerabilities throughout the cloud-to-CPE service path, including device management, certificates, secrets, provisioning, telemetry, firmware delivery, and administrative interfaces.

• Identify impacted device models, hardware revisions, firmware branches, software components, and deployed cohorts.

• Develop integrations and automation for asset enrichment, deduplication, risk scoring, ticketing, ownership routing, SLA tracking, notifications, rescans, exception expiry, and evidence collection.

• Maintain dashboards that monitor coverage, exploitable exposure, aging, remediation performance, repeat findings, exceptions, ownership, and risk trends.

• Create playbooks, standards, and procedures for handling vulnerabilities, critical CVEs, zero-day responses, scanner administration, and tool outages.

• Provide reporting to technical owners and leadership, and assist with audits and customer security inquiries.


⛳️ Requirements

• 5+ years of hands-on experience in vulnerability management, vulnerability assessment, security engineering, product security, cloud security, or a closely related field.

• Proven ownership of enterprise scanning and vulnerability-management workflows.

• Strong CVE analysis capabilities with the ability to determine applicability and exploitability.

• Experience with enterprise vulnerability platforms and associated cloud, container, dependency, application, and open-source scanning tools.

• Working knowledge of CVE/CWE, NVD, CVSS, CISA KEV, EPSS, vendor advisories, SBOMs, and risk-based prioritization.

• Practical knowledge of Linux, TCP/IP, DNS, TLS/PKI, identity and access controls, APIs, cloud infrastructure, containers, and Kubernetes.

• Ability to read code, package manifests, container images, configurations, logs, and network evidence.

• Proficiency in scripting or programming languages such as Python, Go, PowerShell, Bash, or similar.

• Experience integrating security platforms with APIs, ticketing systems, and dashboards.

• Excellent written and verbal communication skills.

• Bachelor’s degree in cybersecurity, computer science, engineering, or equivalent practical experience.

• Preferred: security experience with service providers, broadband operators, telecom equipment/software vendors, managed-network providers, or distributed device fleets.

• Preferred: experience assessing embedded Linux, firmware, broadband gateways, routers, ONTs, Wi-Fi/mesh systems, or CPE/IoT products.

• Preferred: familiarity with TR-069/CWMP, TR-369/USP, TR-181, ACS/USP controllers, provisioning, telemetry, certificates, and remote firmware lifecycle management.

• Preferred: experience with Google Cloud Platform, Kubernetes, Terraform, Helm, CI/CD, and cloud-native security platforms.

• Preferred: experience with software composition analysis, SBOM/VEX, container/image scanning, secret scanning, SAST/DAST/API security testing, and infrastructure-as-code scanning.

• Preferred: experience with coordinated vulnerability disclosure, penetration-test finding intake, zero-day response, or product security incident response.

• Preferred: familiarity with NIST Cybersecurity Framework, NIST SP 800-40, CIS Controls, OWASP guidance, PCI DSS, SOC 2, or ISO 27001.

• Preferred: relevant certifications such as Security+, CySA+, GSEC, GCIH, GPEN, CISSP, CCSP, or vendor-specific credentials.

• Work primarily during standard business hours, with on-call responsibilities for critical, actively exploited, or zero-day security escalations.

• Strict access controls for sensitive vulnerability, exploit, and customer information based on need-to-know principles.

• Coordinate intrusive scans, validation tests, and production-impacting work through approved change and maintenance processes.


🏝️ Benefits

• Escalation availability for critical, actively exploited, or zero-day vulnerabilities.

• Equal opportunities and a non-discrimination policy.

• An inclusive and diverse working environment.

People also viewed

Sony Interactive Entertainment19 hours ago

Senior Security AI Risk Analyst

US flagCalifornia OnlyFull-timeCybersecurity / Security Engineer$167.5k – $251.3k/year
ApplyView job
Squads19 hours ago

Security Engineer

North AmericaFull-timeCybersecurity / Security Engineer$175k – $220k/year
ApplyView job
Neo4j19 hours ago

Senior Director, Product, Security and Privacy

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer$260k – $300k/year
ApplyView job
PingWind Inc. (SDVOSB)20 hours ago

Cloud Security Architect – Engineer

US flagAlabama, +1 more stateFull-timeCybersecurity / Security Engineer
ApplyView job
CSCI Consulting21 hours ago

SAP S/4HANA Defense & Security Functional Lead

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer
ApplyView job
Strategic Systems International21 hours ago

AI Security Engineer – AI, Agentic Security

MX flagMexico, +4 more countriesFreelanceCybersecurity / Security Engineer
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers