Senior Information Security Analyst (Vulnerability Governance)
$81,600–$115,200 year
On-siteToronto, Ontario, Canada
Job Summary
Coordinate vulnerability management operations, including scanning coordination, operational tracking, and issue follow-up. Analyze and validate vulnerability data to identify quality issues, process gaps, and remediation priorities while supporting governance of application security testing and remediation processes. Track remediation activities with application owners and development teams to resolve operational issues and improve program outcomes. Develop and maintain reports, metrics, dashboards, procedures, and secure coding training curriculum. Prepare clear reports, analyses, and communications for technical teams, business partners, and leadership. Support audit, regulatory, and risk requests by gathering evidence and preparing defensible responses. Communicate vulnerabilities, control requirements, and remediation expectations to technical and non-technical audiences. Work independently to prioritize assignments and deliver high-quality work within established timelines.
Required Qualifications
- Bachelor's degree or equivalent relevant professional experience
- Five or more years of experience in information security, technology risk, governance, risk and compliance, application security, vulnerability management, patch management, systems development, or another relevant technical role
- Strong understanding of governance, risk, and compliance concepts, including policies, standards, controls, risk identification, issue management, remediation tracking, and evidence validation
- Familiarity with application security, vulnerability management, patch management, secure software development, or related security operations
- Working knowledge of Common Vulnerabilities and Exposures (CVEs), Common Weakness Enumeration (CWEs), vulnerability severity and prioritization, risk treatment, and remediation processes
- Experience using ServiceNow Security Operations module
- Familiarity with application, infrastructure, or cloud security scanning tools such as Veracode, Snyk, Qualys VM, Wiz, or comparable platforms
- Experience analyzing, validating, and reporting data, including the ability to identify inconsistencies, explain trends, and communicate actionable findings
- Ability to develop and maintain clear procedures, guidance, reports, training materials, and governance documentation
- Excellent written and verbal communication skills, with the ability to communicate technical, operational, and risk information clearly to technical and non-technical audiences
- Strong organizational skills and attention to detail, with the ability to manage multiple priorities and deliver accurate work within established timelines
- Demonstrated ability to work independently, exercise sound judgment, take ownership of assigned responsibilities, and escalate issues appropriately
- Ability to collaborate effectively with application owners, developers, security teams, technology partners, risk and compliance functions, and external vendors
- Demonstrated ability to support complex initiatives and contribute to the continuous improvement of processes, controls, reporting, and operational practices
Desired Qualifications
- background in governance, risk, or compliance and familiarity with application security, vulnerability and patch management, systems development, or another relevant technical discipline
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.