Job Title: Vulnerability Lead
Location: Markham, ON
Work Model: Hybrid – 3 Days Onsite (Monday, Tuesday & Wednesday)
Role Summary
We are seeking an experienced Vulnerability Lead to lead and coordinate the end-to-end Vulnerability Management program across applications, infrastructure, cloud environments, databases, and network assets. The ideal candidate will have strong experience in vulnerability assessment, risk analysis, remediation management, security governance, and stakeholder coordination.
The Vulnerability Lead will be responsible for establishing and continuously improving vulnerability management processes, overseeing scanning activities, analyzing security findings, prioritizing risks, and driving remediation within defined SLA timelines.
Key Responsibilities
- Lead and coordinate the end-to-end Vulnerability Management lifecycle across applications, infrastructure, cloud, databases, and network environments.
- Define, implement, and continuously improve vulnerability management strategies, processes, standards, controls, and governance frameworks.
- Ensure vulnerability management activities align with organizational security policies, industry standards, and regulatory requirements.
- Plan, schedule, and oversee vulnerability scanning and assessment activities using approved security tools.
- Review and analyze vulnerability assessment results to identify security weaknesses, vulnerabilities, and misconfigurations.
- Validate findings, investigate vulnerabilities, and eliminate false positives where applicable.
- Assess business impact, exploitability, asset criticality, and overall risk associated with identified vulnerabilities.
- Prioritize vulnerabilities based on risk ratings, exploitability, asset criticality, regulatory requirements, and business impact.
- Work closely with application owners, infrastructure teams, cloud engineering teams, database teams, network teams, and third-party vendors to drive remediation.
- Establish and monitor vulnerability remediation SLAs based on severity and business risk.
- Track remediation activities and ensure vulnerabilities are addressed and closed within agreed timelines.
- Escalate overdue or high-risk vulnerabilities to appropriate stakeholders and management.
- Maintain accurate vulnerability inventories, remediation records, risk acceptances, and exception documentation.
- Prepare regular vulnerability management dashboards, metrics, reports, and executive-level status updates.
- Identify recurring vulnerabilities and security gaps and recommend preventive measures.
- Support vulnerability-related audits, compliance assessments, and security reviews.
- Collaborate with security engineering, SOC, application security, cloud security, and infrastructure security teams.
- Contribute to the continuous improvement and automation of vulnerability management processes.
- Provide guidance and security awareness to technical teams regarding vulnerability remediation and secure configuration practices.
Required Skills & Experience
- 7+ years of experience in Cybersecurity, Vulnerability Management, Information Security, or a related field.
- Strong hands-on experience managing enterprise Vulnerability Management programs.
- Experience working across applications, infrastructure, cloud, databases, and network environments.
- Strong understanding of vulnerability assessment, risk management, remediation, and security governance.
- Experience with vulnerability scanning and management tools such as Tenable/Nessus, Qualys, Rapid7, or similar platforms.
- Strong knowledge of CVSS, CVE, CWE, vulnerability scoring, exploitability, and risk prioritization.
- Experience developing and managing vulnerability remediation SLAs.
- Strong understanding of cloud security concepts across Azure, AWS, or GCP.
- Experience working with Windows and Linux environments.
- Understanding of network security, application security, database security, and cloud security vulnerabilities.
- Strong experience with vulnerability reporting, dashboards, metrics, and executive-level communication.
- Experience working with cross-functional teams and third-party vendors.
- Strong analytical, problem-solving, communication, and stakeholder-management skills.
Preferred Qualifications
- Experience with Security Information and Event Management (SIEM) and security operations environments.
- Knowledge of OWASP Top 10 and application security vulnerabilities.
- Experience with vulnerability remediation automation and scripting.
- Familiarity with ServiceNow or similar ITSM platforms for vulnerability tracking and remediation.
- Knowledge of security frameworks such as NIST, CIS, ISO 27001, or similar.
- Experience supporting security audits and regulatory/compliance requirements.
- Relevant cybersecurity certifications such as CISSP, CISM, CEH, Security+, or equivalent are preferred.
Key Competencies
- Vulnerability & Risk Management
- Security Governance
- Vulnerability Assessment & Prioritization
- Risk-Based Remediation
- Security Tools & Scanning
- Cloud Security
- Application & Infrastructure Security
- SLA & Remediation Tracking
- Stakeholder Management
- Security Reporting & Metrics
- Incident & Security Operations Collaboration
- Continuous Process Improvement