The Cybersecurity Vulnerability Engineer will require working across several security functions and ... Must be able to analyze newly disclosed vulnerabilities to understand affected components ...
The Cybersecurity Vulnerability Engineer will require working across several security functions and ... Must be able to analyze newly disclosed vulnerabilities to understand affected components ...
Senior Information Security Analyst (Vulnerability Governance)
CA$81K - CA$115K/yr
Analyze and validate vulnerability data to identify data-quality issues, process gaps, trends, and remediation priorities. * Support the governance of application security testing and vulnerability ...
Senior Information Security Analyst (Vulnerability Governance)
CA$81K - CA$115K/yr
Analyze and validate vulnerability data to identify data-quality issues, process gaps, trends, and remediation priorities. * Support the governance of application security testing and vulnerability ...
Security Analyst
Toronto, ON · On-site
Security Technology Analyst We are seeking a Security Technology Analyst to support the day-to-day ... Conduct vulnerability assessments, validate findings, prioritize risks, and coordinate remediation ...
Security Analyst
Toronto, ON · On-site
Security Technology Analyst We are seeking a Security Technology Analyst to support the day-to-day ... Conduct vulnerability assessments, validate findings, prioritize risks, and coordinate remediation ...
Vulnerability Research Intern
Toronto, ON · On-site
Collaborate with other vulnerability researchers on research, analysis, and report production Required Qualifications: * Currently enrolled in a post-secondary program in Computer Science, Computer ...
Vulnerability Research Intern
Toronto, ON · On-site
Collaborate with other vulnerability researchers on research, analysis, and report production Required Qualifications: * Currently enrolled in a post-secondary program in Computer Science, Computer ...
Security Analyst
Ottawa, ON · On-site
... Analyst to join our Cybersecurity team. This is a unique opportunity for an individual passionate ... Responsibilities Vulnerability Management * Own the end-to-end vulnerability management lifecycle ...
Security Analyst
Ottawa, ON · On-site
... Analyst to join our Cybersecurity team. This is a unique opportunity for an individual passionate ... Responsibilities Vulnerability Management * Own the end-to-end vulnerability management lifecycle ...
... Analyst to join our Cybersecurity team. This is a unique opportunity for an individual passionate ... Responsibilities Vulnerability Management * Own the end-to-end vulnerability management lifecycle ...
... Analyst to join our Cybersecurity team. This is a unique opportunity for an individual passionate ... Responsibilities Vulnerability Management * Own the end-to-end vulnerability management lifecycle ...
Key Responsibilities: • Lead compliance with cybersecurity standards • Conduct vulnerability analysis and risk mitigation • Collaborate with stakeholders for expert security support • ...
Key Responsibilities: • Lead compliance with cybersecurity standards • Conduct vulnerability analysis and risk mitigation • Collaborate with stakeholders for expert security support • ...
This role will translate vulnerability insights into actionable, audit-ready hardening standards aligned to NIST CSF, CIS benchmarks enabling consistent risk reduction and remediation at scale.
Quick apply
This role will translate vulnerability insights into actionable, audit-ready hardening standards aligned to NIST CSF, CIS benchmarks enabling consistent risk reduction and remediation at scale.
Lead vulnerability management activities, including scanning, analysis, risk assessment, reporting, and remediation tracking across enterprise environments. * Partner with application owners ...
Lead vulnerability management activities, including scanning, analysis, risk assessment, reporting, and remediation tracking across enterprise environments. * Partner with application owners ...
Engineer - Cybersecurity (Vulnerability & Threat Management) Location: Krakow, Poland (Hybrid) Type: Full-time employment Hybrid work: 2 days in office and 3 days remote Working Hours: 9 am - 5 pm ...
Engineer - Cybersecurity (Vulnerability & Threat Management) Location: Krakow, Poland (Hybrid) Type: Full-time employment Hybrid work: 2 days in office and 3 days remote Working Hours: 9 am - 5 pm ...
The Technical Support Analyst, Hardware is responsible for the 24x7 lifecycle management ... Key responsibilities include vulnerability management, firmware updates, patching, and disaster ...
The Technical Support Analyst, Hardware is responsible for the 24x7 lifecycle management ... Key responsibilities include vulnerability management, firmware updates, patching, and disaster ...
... Threats and vulnerability analysis in compliance with the APTA standards Attend the technical discussions with the customer to shoulder review the document submittals Manage the customer ...
... Threats and vulnerability analysis in compliance with the APTA standards Attend the technical discussions with the customer to shoulder review the document submittals Manage the customer ...
Conduct vulnerability assessments and coordinate remediation activities across corporate IT and ... Strong analytical and problem-solving skills, with the ability to communicate technical risk ...
Conduct vulnerability assessments and coordinate remediation activities across corporate IT and ... Strong analytical and problem-solving skills, with the ability to communicate technical risk ...
Director, Governance Advisory
Toronto, ON · On-site
Conduct complex governance and compensation analyses, including transaction memos and activism vulnerability analyses * Develop and maintain industry-leading intellectual capital, research resources ...
Quick apply
Director, Governance Advisory
Toronto, ON · On-site
Conduct complex governance and compensation analyses, including transaction memos and activism vulnerability analyses * Develop and maintain industry-leading intellectual capital, research resources ...
The IT Security Analyst is expected to monitor computer networks and systems for security issues ... Design, and execute vulnerability assessments and discuss resolution planning with appropriate ...
Quick apply
The IT Security Analyst is expected to monitor computer networks and systems for security issues ... Design, and execute vulnerability assessments and discuss resolution planning with appropriate ...
Vulnerability research, analysis and validation Security Consulting & Communication * Technical report writing and presentation of findings * Translating complex technical risks into practical ...
Vulnerability research, analysis and validation Security Consulting & Communication * Technical report writing and presentation of findings * Translating complex technical risks into practical ...
The IT Security Analyst is expected to monitor computer networks and systems for security issues ... Design, and execute vulnerability assessments and discuss resolution planning with appropriate ...
The IT Security Analyst is expected to monitor computer networks and systems for security issues ... Design, and execute vulnerability assessments and discuss resolution planning with appropriate ...
Information Security Analyst
Toronto, ON · Hybrid
CA$59K - CA$84K/yr
Perform vulnerability assessments and tests to uncover flaws and help technical teams to remediate ... Strong analytical skills to analyze security requirements and relate them to appropriate security ...
Information Security Analyst
Toronto, ON · Hybrid
CA$59K - CA$84K/yr
Perform vulnerability assessments and tests to uncover flaws and help technical teams to remediate ... Strong analytical skills to analyze security requirements and relate them to appropriate security ...
Senior Analyst, Application Integration
Toronto, ON · On-site
CA$95K - CA$115K/yr
Security vulnerability remediation tasks completed within agreed timelines Required Experience * Bachelor's degree in Computer Science, Engineering, Information Management, Data Analytics or related ...
Senior Analyst, Application Integration
Toronto, ON · On-site
CA$95K - CA$115K/yr
Security vulnerability remediation tasks completed within agreed timelines Required Experience * Bachelor's degree in Computer Science, Engineering, Information Management, Data Analytics or related ...
Lead Vulnerability management efforts, including identification, tracking, remediation, and closure ... Support incident management and root cause analysis (RCA) for deployment or environment-related ...
Lead Vulnerability management efforts, including identification, tracking, remediation, and closure ... Support incident management and root cause analysis (RCA) for deployment or environment-related ...
Vulnerability Analyst information
See Ontario salary details
$27.64 - $31.73
4% of jobs
$31.73 - $35.82
6% of jobs
$35.82 - $39.90
11% of jobs
$41.10 is the 25th percentile. Wages below this are outliers.
$39.90 - $43.99
13% of jobs
The median wage is $47.60 / hr.
$43.99 - $48.08
18% of jobs
$48.08 - $52.16
13% of jobs
$54.10 is the 75th percentile. Wages above this are outliers.
$52.16 - $56.25
21% of jobs
$56.25 - $60.34
3% of jobs
$60.34 - $64.42
1% of jobs
$64.42 - $68.51
0% of jobs
$68.51 - $72.60
10% of jobs
$27
$49
$72
How much do vulnerability analyst jobs pay per hour?
What is a vulnerability analyst?
A Vulnerability Analyst is a cybersecurity professional responsible for identifying, assessing, and mitigating security weaknesses in an organization's systems, networks, and applications. They use tools like vulnerability scanners, penetration testing frameworks, and security assessments to identify potential threats. Their role includes analyzing vulnerabilities, prioritizing risks, and working with IT and security teams to implement necessary patches or fixes. They also stay up to date with emerging threats and ensure compliance with security policies and regulations.
What are the typical day-to-day responsibilities of a vulnerability analyst?
As a Vulnerability Analyst, your daily tasks often include running vulnerability scans, analyzing findings, prioritizing risks based on severity, and working with IT or development teams to coordinate remediation efforts. You will also document your findings, prepare reports for stakeholders, and stay informed about the latest security threats and exploits. Collaboration with other security professionals and IT staff is common, as resolving vulnerabilities often requires cross-functional teamwork. This role requires a balance of technical analysis and effective communication to ensure organizational security posture is continuously improved.
What are the key skills and qualifications needed to thrive as a vulnerability analyst, and why are they important?
To thrive as a Vulnerability Analyst, you need expertise in cybersecurity principles, risk assessment, and vulnerability management, often supported by a degree in information security or a related field. Familiarity with vulnerability scanning tools (such as Nessus, Qualys, or Rapid7), knowledge of operating systems, and certifications like CompTIA Security+ or CEH are commonly required. Strong analytical thinking, attention to detail, and effective communication skills set top candidates apart. These abilities are crucial for accurately identifying system weaknesses and effectively advising teams on how to remediate security threats.
How do you become a vulnerability analyst?
What does a vulnerability analyst do?
What are the most commonly searched types of Vulnerability Analyst jobs in Ontario?
The most popular types of Vulnerability Analyst jobs in Ontario are:
What are popular job titles related to Vulnerability Analyst jobs in Ontario?
For Vulnerability Analyst jobs in Ontario, the most frequently searched job titles are:
What job categories do people searching Vulnerability Analyst jobs in Ontario look for?
The top searched job categories for Vulnerability Analyst jobs in Ontario are:

Full-time
Medical, Dental, Life, Retirement, PTO
Posted 28 days ago
Thales rating
8.9
Based on 21 frontline employees who took The Breakroom Quiz
10th of 159 rated electronics manufacturers
Job description
This is a remote and localized role in Ottawa, ON.
Position Summary
Cyberattacks have been on the rise around the globe, with hackers and other criminals targeting businesses large and small to steal valuable information or bring computer networks to a halt. Cyber Security analysts are valued for their ability to protect an organization's information and systems from such attacks.
This position is responsible for providing ongoing information security services to all aspects of the on premise and cloud corporate IT environments. The Cybersecurity Vulnerability Engineer will require working across several security functions and have a strong primary focus on incident response activities.
Key Areas of Responsibility
Must be able to monitor and evaluate newly disclosed and emerging vulnerabilities from Thales CTI, OSINT, Thales CERT, PSIRT, vendor advisories, security researchers, vulnerability databases, and other trusted sources.
Must be able to Initiate and coordinate enterprise vulnerability-response activities for vulnerabilities with potential impact to Thales businesses and networks.
Must be able to Engage infrastructure, IT, application, cloud, product, and security teams to validate exposure and determine required actions.
Must have working knowledge of threat actor tactics and techniques.
Must be able to establish clear ownership, priorities, response timelines, and escalation paths.
Must be able to track remediation and mitigation activities through completion and validate that identified risk has been appropriately addressed.
Must be able to escalate missed timelines, unresolved ownership, significant technical uncertainty, or material residual risk to appropriate leadership.
Must be able to maintain clear status reporting for technical teams, cybersecurity leadership, and other stakeholders.
Must be able to analyze newly disclosed vulnerabilities to understand affected components, exploitation prerequisites, attack vectors, required privileges, exploitability, potential impact, and available mitigations.
Must be able to review CVEs, vendor advisories, security-research publications, proof-of-concept information, exploit intelligence, and relevant technical documentation.
Must be able assess whether vulnerable technologies or configurations are present in the enterprise and partner with technology owners to validate actual exposure.
Responsible for translating complex vulnerability information into clear, actionable guidance for infrastructure, application, product-development, and leadership teams.
Responsible for partnering with detection and incident-response teams when a vulnerability requires investigation for possible prior exploitation or additional monitoring.
Basic Qualifications
Bachelor's degree in computer information systems, programming, engineering or a related field with a minimum of 5+ years of cybersecurity experience, including at least 3-4 years in vulnerability management, vulnerability analysis, security engineering, incident response, threat intelligence, penetration testing, or a closely related technical security function.
5 to 7 years of experience in Cybersecurity domains.
3 to 5 years of experience in demonstrated experience analyzing CVEs and determining their relevance and actual impact within complex enterprise environments.
Strong understanding of vulnerability exploitation, attack paths, operating systems, enterprise applications, networking, authentication, privilege boundaries, and common security controls.
Ability to interpret vendor advisories, technical security research, proof-of-concept information, logs, configurations, and vulnerability evidence.
Working knowledge of Windows and Linux environments, network infrastructure, cloud technologies, virtualization, containers, and enterprise applications.
Ability to independently coordinate urgent, cross-functional technical response activities involving multiple teams and competing priorities.
Strong organizational skills and the ability to track multiple concurrent vulnerability-response activities through closure.
Preferred Qualifications
Strong knowledge of all aspects of information security within the Prevent, Detect and Respond domains.
Must be highly analytical and detail-oriented, with organizational skills to manage assigned work to completion.
Experience supporting large, complex, or globally distributed enterprise environments.
Experience working across corporate IT, shared infrastructure, software-development, cloud, and product environments.
Experience using scripting or automation with Python, PowerShell, APIs, SQL, or similar technologies to support vulnerability analysis and data correlation.
Physical Demands
Typical Office environment
Special Position Requirements
Schedule: First Shift Monday through Friday; Core Business Hours Monday-Friday, etc.
Regulatory Compliance Requirements
Canada
Access to Trade Controlled Hardware, Software, Technical Information, Controlled Goods Program Clearance & Secret Security Clearance
What We Offer
Thales provides an extensive benefits program for all full-time employees working 24 or more hours per week and their eligible dependents, including the following:
Company paid Extended Health, Dental, HSA, Life, AD&D, Short-term Disability, Cancer Care Program, travel insurance, Employee Assistance Plan and Well-Being program.
Retirement Savings Plans (RRSP, DCPP, TFSA) with a company contribution and a match to a DCPP, with no vesting period.
Company paid holidays, vacation days, and paid sick leave.
Voluntary Life, AD&D, Critical Illness, Long-Term Disability.
Employee Discounts on home, auto, and gym membership.
Why Join Us?
Say HI and learn more about working at Thalesclick here.
The reference Total Target Compensation(TTC) market range for this position, inclusive of annual base salary and the variable compensation target, is betweenTotal Target Cash 123,459.00 - 172,842.60 CAD Annual.
This reflects how companies in a similar industry and geographic region generally pay for similar jobs. This range helps the Company make pay decisions as one data point among many. Where a position falls within this range is also dependent on other factors including - but not limited to - the employee's career path history, competencies, skills and performance, as well as the company's annual salary budget, the customer's program requirements, and the company's internal equity. Thales may offer additional benefits and other compensation, depending on circumstances not related to an applicant's status protected by local, state, or federal law.
We use artificial intelligence-enabled tools as part of our recruitment process to support activities such as candidate discovery, resume matching, and interview scheduling. These tools may help screen and assess applications and recommend potential matches based on the requirements within the job description. All hiring decisions, including candidate evaluation, selection, and disposition, are made by human recruiters. Artificial intelligence does not make hiring decisions on our behalf.
#LI-Remote
#LI-WM1
Thales provides an extensive benefits program for all full-time employees working 24 or more hours per week and their eligible dependents, including the following:
Company paid Extended Health, Dental, HSA, Life, AD&D, Short-term Disability, Cancer Care Program, travel insurance, Employee Assistance Plan and Well-Being program.
Retirement Savings Plans (RRSP, DCPP, TFSA) with a company contribution and a match to a DCPP, with no vesting period.
Company paid holidays, vacation days, and paid sick leave.
Voluntary Life, AD&D, Critical Illness, Long-Term Disability.
Employee Discounts on home, auto, and gym membership.
Thales is an equal opportunity employer which values diversity and inclusivity in the workplace. Thales is committed to providing accommodations in all parts of the interview process. Applicants selected for an interview who require accommodation are asked to advise accordingly upon the invitation for an interview. We will work with you to meet your needs. All accommodation information provided will be treated as confidential and used only for the purpose of providing an accessible candidate experience.
This position requires direct or indirect access to hardware, software or technical information controlled under the Canadian Export Control List, the Canadian Controlled Goods Program, the Canadian Industrial Security Program, the US International Traffic in Arms Regulations (ITAR) and/or the US Export Administration Regulations (EAR). All applicants must be eligible or able to obtain authorization for such access including eligibility to the Canadian Controlled Goods Program and able to obtain a Canadian NATO Secret clearance.About Thales
Sourced by ZipRecruiter