We are seeking an experienced Vulnerability Management Manager to lead and manage our centralized vulnerability management function for Canada Life. This role is critical to protecting our business, data, and clients by driving a risk-based approach to identifying, assessing, and responding to emerging threats, while prioritizing and coordinating the remediation of existing vulnerabilities across the enterprise.
The ideal candidate will have deep expertise in the vulnerability management lifecycle, strong leadership skills, and the ability to collaborate across various departments and stakeholders.
As part of our Information Security team, you will align with regulatory expectations and industry best practices to deliver a mature and effective vulnerability management program. Your work will directly contribute to minimizing risks, safeguarding sensitive information, and enhancing the overall cybersecurity posture of our organization.
What you will do
Lead a centralized, risk-driven vulnerability management function to reduce enterprise cyber risk and enhance executive visibility
Define and maintain vulnerability management strategy, standards, governance, and reporting frameworks aligned to regulatory expectations
Operate a comprehensive program to identify, assess, prioritize, and track vulnerabilities across applications, infrastructure, and cloud environments
Oversee end-to-end vulnerability lifecycle management, ensuring transparent ownership, accountability, and timely remediation
Tailor vulnerability reporting to reflect asset criticality, risk exposure, and organizational priorities
Drive performance measurement and continuous improvement of remediation effectiveness and timeliness
Serve as the primary escalation point for vulnerability-related risks and decisions
Continuously evaluate emerging cyber threat intelligence and assess relevance to the enterprise and industry
Incorporate threat intelligence, exploit data, and attack trends into vulnerability prioritization and response strategies
Collaboration and Stakeholder Engagement
Partner with technology, engineering, and business teams to identify, prioritize, and remediate vulnerabilities aligned to organizational risk
Collaborate with internal audit, governance, and risk management functions to ensure alignment with corporate policies and regulatory requirements
Communicate vulnerability posture, remediation performance, and material risk exposures to senior leadership through clear, concise reporting
Provide timely communication during critical vulnerabilities, including impact assessment, response actions, and mitigation plans
Translate technical vulnerability data into actionable business risk insights for non-technical stakeholders
Influence stakeholders to prioritize remediation based on risk, exploitability, and business impact
Process Development and Maturity
Develop, implement, and continuously enhance the vulnerability management framework in alignment with evolving threats, business objectives, and regulatory requirements
Establish and maintain policies, standards, and procedures aligned with industry best practices
Define and track key performance indicators (KPIs) and metrics to measure program effectiveness, efficiency, and maturity
Leadership and Team Management
Establish and execute the vision, strategy, and roadmap for the vulnerability management program
Define governance structures, roles, and responsibilities to support effective program execution
Lead and coordinate response efforts during critical vulnerability events, such as zero-day exposures
Ensure scalable, consistent processes across infrastructure, applications, cloud, and endpoint environments
Foster a culture of accountability, continuous improvement, and strong security ownership
What you will bring
Bachelor's degree in computer science, Information Security, or a related field.
5+ years of experience in vulnerability management with at least 3 years in a leadership role.
Demonstrated experience leading vulnerability management teams.
Strong project management skills and the ability to manage multiple issues and priorities simultaneously.
Preferred Qualifications
Certifications such as GIAC GEVA, CISSP, CRISC, or CompTIA Pen Test+ are highly desirable.
Experience in the insurance or financial services sector is a strong asset.
Familiarity with privacy regulations (PIPEDA, GDPR, CCPA) and industry compliance requirements.
Experience working with executive leadership and Board-level communications during incidents.
Critical thinking and problem-solving under pressure.
Excellent communication skills with the ability to explain technical concepts to non-technical audiences.
Robust collaboration and interpersonal skills to work effectively across teams and business units.
Detail-oriented with a high level of integrity and professionalism.
The base salary for this position is between $119,300 - $169,300 annually. This represents base salary only and does not represent other variable compensation components of our total compensation ( i.e. annual bonus, commission etc). If you are selected to move forward in our recruitment process, your recruiter will be able to discuss additional details of our total rewards program with you.
Career opportunities will be open a minimum of 5 business days from the date of posting, closing dates will vary depending on the search activity. All applications received will be reviewed on a rolling basis.
Grow with Canada Life
We'reunited by a shared purpose: to improve the financial,physicaland mental well-beingof Canadians. Our company is trusted by 1 in 3 Canadians and contributes to the strength of communities across the country.
We'relooking for people who live our values everyday: we step up, we do the right thing, and we deliver – for our customers,communitiesand each other. Are you someone who always strives to do the right thing, who steps up for themselves and others, and who delivers with impact?
Then we want to hear from you!
What we offer
We're committed to supporting our employees through every stage of their career. Here's what you can expect as a full-time or part-time permanent team member:
Career Development: Opportunities for career advancement, access to industry-leading learning programs and up to$2,000 annuallytowardseducation reimbursement.
Health & Wellness: Versatile health and dental benefits,plus a $5,000 mental health benefit to support your well-being.
Time Off: In addition to regular vacation andpersonal days,we support communityinvolvement with avolunteer day.
Financial Security: Company-matching pension plan,share ownership program andadditionalinvestment options.
Rewards and Recognition: Employee recognition programs, service milestone celebrations, employee discounts and more!
Emphasis on Community: We provide aworkplace whereemployeesfeel connected and supported through Employee Resource Groups (ERGs),mentorshipprograms,socialclubsandevents.
We'recommitted to removing barriers and ensuring equal access to employment. Applicants requiring reasonable accommodation during the application process may contact
[email protected] . All information provided will be handledin accordance withapplicable laws and Canada Life policies.
Canada Life would like to thank all applicants, however only those who qualify for an interview will be contacted
Location: Canada, ON, CA Winnipeg, MB, CA Toronto, ON, CA
#J-18808-Ljbffr
📌 Manager, Vulnerability Management (Winnipeg)
🏢 TechAlliance of Southwestern Ontario, London Economic Development
📍 Winnipeg