Infrastructure Security Analyst – Vulnerability Management
Job in
Toronto, Ontario, C6A, Canada
Listed on 2026-07-30
Listing for:
LanceSoft, Inc.
Full Time
position Listed on 2026-07-30
Job specializations:
-
IT/Tech
Cybersecurity, Information Security & Data Protection, Security Management & Operations
Job Description & How to Apply Below
We are looking for an Intermediate Infrastructure Vulnerability Management Analyst to support enterprise security operations by identifying, assessing, prioritizing, and driving remediation of vulnerabilities across infrastructure and applications.
The role requires strong hands-on experience with vulnerability scanning tools (Qualys, Nessus, Rapid7), risk-based triage, and alignment with frameworks such as CVSS and threat intelligence (e.g., CISA KEV) to reduce organizational risk exposure.
Key Responsibilities Vulnerability Management & Analysis- Execute the end-to-end vulnerability management lifecycle – discovery, analysis, triage, prioritization, and remediation tracking
- Analyze vulnerability scan outputs from tools such as Qualys, Nessus, Rapid7
- Perform false positive validation and exception handling
- Conduct vulnerability impact analysis across infrastructure, applications, and platforms
- Perform risk-based vulnerability assessments using:
- CVSS scoring and business impact
- Threat context and exploitability insights
- Use external threat intelligence sources (e.g.,
CISA Known Exploited Vulnerabilities – KEV
) to prioritize remediation - Align remediation timelines based on risk severity and exposure
- Perform detailed triage of vulnerabilities based on:
- Generate dashboards and reports on:
- Vulnerability status
- Risk posture
- SLA adherence and remediation progress
- Support audit readiness and compliance reporting
- Participate in threat modeling exercises to identify potential attack vectors
- Evaluate security risks within infrastructure and application ecosystems
- Provide recommendations to strengthen system security posture
- Coordinate and validate patch management for OS, middleware, and applications
- Track remediation SLAs and ensure timely closure of vulnerabilities
- Collaborate with infrastructure and application teams for remediation execution
- Work closely with:
- Security teams
- Infrastructure / server teams
- Application owners
- Communicate risk and remediation strategies clearly to both technical and business stakeholders
- 3–5 years of experience in:
- Vulnerability Management / Security Operations
- Infrastructure Security or IT Operations
- Hands-on experience with:
- Qualys, Nessus, Rapid7 (or similar vulnerability tools)
- Strong understanding of:
- Risk-based prioritization and threat analysis
- Knowledge of:
- Threat modeling concepts
- CISA KEV / threat intelligence-based prioritization
- Strong exposure to:
- Patch management (OS, middleware, applications)
- Experience with:
- ITSM tools (Service Now preferred)
- Scripting (Python, Power Shell, Shell)
- Security monitoring / SIEM tools
- Knowledge of:
- Cloud environments (AWS, Azure, VMware)
- Strong analytical and problem-solving capabilities
- Ability to interpret complex vulnerability data and translate into actionable remediation
- Good communication skills for cross-team collaboration
- Ability to manage multiple vulnerabilities in SLA-driven environments
- Infrastructure Security Analyst – Vulnerability Management
- Cyber Security Analyst – Vulnerability & Risk
- Vulnerability Management Engineer (Intermediate)
Note that applications are not being accepted from your jurisdiction for this job currently via this jobsite. Candidate preferences are the decision of the Employer or Recruiting Agent, and are controlled by them alone.
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search:
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search:
Search for further Jobs Here:
×