11 Sep
|
CMHC - SCHL
|
Montreal
11 Sep
CMHC - SCHL
Montreal
Job Requisition ID: 12428
Position Status: Permanent Full Time
Position Type: Hybrid
Office Location: Montreal (QC); Ottawa (ON)
Travel Requirement: Limited
Language Designation: Bilingual
Language Skill Levels (Read/Write/Speak): BBB
Security Requirement: Secret
Salary: Our salaries generally range from $ 86816.59 to $ 108520.74 and are based on qualifications and experience.
About CMHC The work you do and the work we do together matters. We come to work every day with a common purpose: to contribute to a well-functioning housing system.
At CMHC, we hold ourselves accountable for our results and support our colleagues in their achievements. We thrive on collaboration, connecting across CMHC and involving the right people to get our work done. Our leadership style is guided by trust, where our leaders favour an adaptive approach based on the needs of their teams.
Join us and be part of a team that's committed to making a real difference and be part of something meaningful.
What’s in it for you
We’ve got the purpose, the people and the perks you need for a fulfilling career. Here’s the comprehensive and generous benefits you get when you’re a permanent employee:
- Annual Paid vacation.
- Annual individual performance incentive.
- Defined benefit pension plan.
- Comprehensive group insurance plan to support your well-being from day one.
- Support towards your personal and qualified growth with training, mentorship and more.
- An inclusive workplace culture and environment.
Members of the following employment equity deserving groups will be prioritized for this job: Indigenous Peoples
About the role
Join the Security team, in the Specialist, Enterprise Vulnerability Management position. You will provide specialized expertise to apply and operationalize established vulnerability management standards, application security practices, risk methodologies, and threat intelligence to determine appropriate remediation priorities and control actions within established frameworks and defined operating procedures.
Accountable for the consistent operational execution and data integrity of the enterprise vulnerability management program across infrastructure, applications, cloud environments, APIs, and software delivery platforms. The role ensures vulnerabilities are identified, assessed, prioritized, tracked, communicated, remediated, and escalated in accordance with established security standards, risk methodologies,
and service expectations.
The position directly contributes to reducing technology risk by enabling the timely identification, assessment, and remediation of vulnerabilities and by providing reliable vulnerability data to support risk management, compliance, and security oversight.
What you'll do:
- Identify, analyze, and assess vulnerabilities across infrastructure, cloud environments, applications, APIs, containers, and related technologies using security scanning and testing tools.
- Validate findings through risk assessments by eliminating false positives and determining exploitability, business impact, and overall risk.
- Classify, prioritize, and maintain accurate vulnerability records using approved risk-rating methodologies, threat intelligence, OWASP guidance, supporting evidence, and remediation tracking.
- Coordinate remediation efforts with infrastructure, development, architecture, cloud, and technology teams, providing guidance on security controls, secure coding practices, and treatment options.
- Monitor remediation progress, validate fixes, drive follow-up actions, and escalate overdue, high-risk, or unresolved vulnerabilities through to closure or formal risk acceptance.
- Support the integration of vulnerability management practices into Agile, DevOps, and DevSecOps workflows while ensuring consistent execution of enterprise standards.
- Develop and maintain reports, dashboards, metrics, and audit-ready vulnerability data to support risk management, compliance, security investigations, assurance, and oversight activities.
- Drive continuous improvement by identifying recurring security weaknesses, recommending process and tool enhancements, staying informed on emerging threats, and influencing stakeholders to strengthen security practices and reduce organizational risk exposure.
What you should have:
- An undergraduate degree in Information Technology, Cybersecurity, Computer Science, Software Engineering, Computer Engineering, or a related field, or equivalent experience.
- A minimum 5 years of experience in information security, vulnerability management, application security, infrastructure security, DevSecOps, or related technology disciplines.
- A security certification completed or in progress (e.g., Security+, CEH, CSSLP, ISC2 CC, GWAPT, or equivalent) with practical experience supporting cybersecurity and vulnerability management activities.
- Experience using vulnerability scanning, application security testing, and remediation management tools to identify, assess, and track security weaknesses.
- A strong understanding of the full vulnerability management lifecycle, including identification, assessment, prioritization, remediation, and validation of vulnerabilities.
- Knowledge of infrastructure security, cloud security, application security, OWASP Top 10 risks, and common cybersecurity threats and controls.
- An understanding of Secure Software Development Lifecycle (SSDLC) practices and modern delivery frameworks, including Agile, DevOps, and DevSecOps.
- Strong analytical, communication, documentation, stakeholder engagement, risk assessment, data management, and issue escalation skills, with the ability to identify recurring vulnerability trends and address systemic risks.
Posting closing date: Note, the competition will remain active until filled. Our commitment to diversity, equity, and inclusion
We’re committed to employment equity and encourage women, Indigenous Peoples, persons with disabilities, veterans and persons of all races, ethnicities, religions, abilities, sexual orientations, and gender identities and expressions to apply. We also welcome applications from non-Canadians who are eligible to work in Canada.
CMHC is an inclusive workplace where diversity of thought – and of people – are recognized, valued, and considered essential to achieving our mission.
Learn more about our commitment to diversity and inclusion
What happens after you apply
We know that applying for a new job can be both exciting and daunting, and we appreciate your effort. Learn more about our hiring process. If you are selected for an interview or testing, please advise us if you require an accommodation.
If you applied before and you were not successful don’t worry – we're always posting new positions, so don’t hesitate to give it another shot. We’re excited to see what you bring to the table this time around!
📌 Specialist, Enterprise Vulnerability Management (Montreal)
🏢 CMHC - SCHL
📍 Montreal