26 Sep
|
SoTalent
|
Canada
Intermediate Security Analyst, Vulnerability Operations
? Location: Canada (Remote)
? Industry: IT Services and IT Consulting
? Work Setting: Remote (Continental U.S. & Canada) with occasional travel
Are you passionate about cybersecurity, vulnerability management, and helping protect customers from emerging security threats? We’re looking for a Security Analyst to support product security operations, investigate security reports, coordinate vulnerability response activities, and collaborate with cross-functional teams to strengthen the security posture of customer-facing products and services.
Key Responsibilities
- Review and triage incoming security reports, validating findings, assessing potential impact, identifying duplicates, and routing issues to the appropriate stakeholders.
- Support vulnerability management processes by tracking identified security issues through assessment, remediation, verification, and closure.
- Collaborate with security engineers, development teams, and operational stakeholders to gather technical details, reproduce issues, and determine affected systems, products, and configurations.
- Assist with severity assessments using industry-standard frameworks and methodologies.
- Engage professionally with security researchers participating in responsible disclosure and vulnerability reporting programs.
- Support vulnerability disclosure and identification processes by maintaining accurate records, preparing documentation, and coordinating related activities.
- Contribute to customer-facing communications regarding security vulnerabilities, remediation guidance, release updates, and mitigation strategies.
- Maintain detailed records of security reports, remediation activities, timelines, communications, and follow-up actions.
- Monitor operational metrics, identify trends, and recommend process improvements to enhance response quality and efficiency.
- Develop and improve runbooks, procedures, templates, and documentation to streamline security operations.
- Participate in incident reviews, root cause analysis efforts, lessons-learned discussions, and product security assessments.
- Continuously build expertise in vulnerability management, security response, and coordinated disclosure practices.
Required Qualifications
- Early-career experience or relevant education in Cybersecurity, Information Technology, Software Engineering, Computer Science, or a related field.
- Foundational understanding of software security concepts, including web applications, APIs, authentication, authorization, and modern development environments.
- Familiarity with common security frameworks, vulnerability classification methodologies, and industry best practices.
- Solid attention to detail with the ability to manage and prioritize multiple tasks and security reports simultaneously.
- Excellent written and verbal communication skills, with the ability to explain technical concepts to both technical and non-technical audiences.
- Exposure to vulnerability disclosure programs, bug bounty platforms, security research initiatives, or related security activities.
- Experience reviewing security findings, participating in cybersecurity labs or competitions, conducting vulnerability research, or working with security tools.
- Understanding of vulnerability databases, security advisories, and remediation processes.
Preferred Qualifications
- Basic scripting, automation, log analysis, or data analysis experience.
- Familiarity with issue tracking and security workflow management tools.
- Experience creating technical documentation, operational procedures, customer communications, or security-related knowledge articles.
- Strong interest in advancing expertise within product security, incident response, and vulnerability management domains.
📌 Security Analyst (Canada)
🏢 SoTalent
📍 Canada