1

Vulnerability Analyst Jobs in Quebec (NOW HIRING)

Own cloud security posture (CSPM), SIEM/SOAR integration, vulnerability management, and secrets/key ... SLIs/SLOs, error budgets, incident/postmortem practices, observability (Azure Monitor/Log Analytics ...

This role is the analytical backbone of our IAM program you will be the person who digs into the data, maps out the processes, and ensures our identity governance controls are well documented, well ...

Performs root cause analysis and assumes responsibility for managing vulnerability studies (VS). * Manages the implementation of Air Liquide technical standards and procedures, and manages and ...

Performs root cause analysis and assumes responsibility for managing vulnerability studies (VS). * Manages the implementation of Air Liquide technical standards and procedures, and manages and ...

... vulnerability Ensure rigorous record-keeping in accordance with Law 25 Participating in the ... Good listening and psychosocial analysis skills Autonomy and professional judgment Ability to ...

... vulnerability Ensure rigorous record-keeping in accordance with Law 25 Participating in the ... Good listening and psychosocial analysis skills Autonomy and professional judgment Ability to ...

... vulnerability Ensure rigorous record-keeping in accordance with Law 25 Participating in the ... Good listening and psychosocial analysis skills Autonomy and professional judgment Ability to ...

... vulnerability Ensure rigorous record-keeping in accordance with Law 25 Participating in the ... Good listening and psychosocial analysis skills Autonomy and professional judgment Ability to ...

... vulnerability Ensure rigorous record-keeping in accordance with Law 25 Participating in the ... Good listening and psychosocial analysis skills Autonomy and professional judgment Ability to ...

Official Internal Job Title: IT Security Analyst Status: Regular Relevant du Directeur - Gestion des identites et des acces, l'analyste securite informatique (GIA), est la passerelle essentielle ...

Official Internal Job Title: IT Security Analyst Status: Regular Relevant du Directeur - Gestion des identites et des acces, l'analyste securite informatique (GIA), est la passerelle essentielle ...

Showing results 41-60

Vulnerability Analyst information

See Quebec salary details

$27

$49

$72

How much do vulnerability analyst jobs pay per hour?

As of Aug 8, 2026, the average hourly pay for vulnerability analyst in Quebec is $49.28, according to ZipRecruiter salary data. Most workers in this role earn between $42.55 and $55.29 per hour, depending on experience, location, and employer.

What are the key skills and qualifications needed to thrive as a vulnerability analyst, and why are they important?

To thrive as a Vulnerability Analyst, you need expertise in cybersecurity principles, risk assessment, and vulnerability management, often supported by a degree in information security or a related field. Familiarity with vulnerability scanning tools (such as Nessus, Qualys, or Rapid7), knowledge of operating systems, and certifications like CompTIA Security+ or CEH are commonly required. Strong analytical thinking, attention to detail, and effective communication skills set top candidates apart. These abilities are crucial for accurately identifying system weaknesses and effectively advising teams on how to remediate security threats.

What are the typical day-to-day responsibilities of a vulnerability analyst?

As a Vulnerability Analyst, your daily tasks often include running vulnerability scans, analyzing findings, prioritizing risks based on severity, and working with IT or development teams to coordinate remediation efforts. You will also document your findings, prepare reports for stakeholders, and stay informed about the latest security threats and exploits. Collaboration with other security professionals and IT staff is common, as resolving vulnerabilities often requires cross-functional teamwork. This role requires a balance of technical analysis and effective communication to ensure organizational security posture is continuously improved.

What is a vulnerability analyst?

A Vulnerability Analyst is a cybersecurity professional responsible for identifying, assessing, and mitigating security weaknesses in an organization's systems, networks, and applications. They use tools like vulnerability scanners, penetration testing frameworks, and security assessments to identify potential threats. Their role includes analyzing vulnerabilities, prioritizing risks, and working with IT and security teams to implement necessary patches or fixes. They also stay up to date with emerging threats and ensure compliance with security policies and regulations.

What are popular job titles related to Vulnerability Analyst jobs in Quebec? For Vulnerability Analyst jobs in Quebec, the most frequently searched job titles are:
What job categories do people searching Vulnerability Analyst jobs in Quebec look for? The top searched job categories for Vulnerability Analyst jobs in Quebec are:
Infographic showing various Vulnerability Analyst job openings in Quebec as of August 2026, with employment types broken down into 75% Full Time, and 25% Temporary. Highlights an 100% In-person job distribution, with an average salary of $102,493 per year, or $49.3 per hour.

Team Lead, Cloud Business Office (CBO)

BRP

Montreal, QC • On-site

Other

Medical, Retirement

Re-posted 3 days ago


Job description

The Cloud Business Office is seeking a security-focused Team Lead to operate, secure, and continuously improve our Azure and Google Cloud Platform (GCP) landscape through implementing strong operational process, hands-on coding, and delivery leadership. You will own day-to-day operations; help to set standards and guardrails; and lead projects end-to-end with an automation-first mindset. As a technical leader, you'll coach team members and drive context-appropriate and fit-for-purpose cloud outcomes.

YOU'LL HAVE THE OPPORTUNITY TO:

  • Process Excellence & Operations

    • Design, implement, and run robust cloud operating processes: on‑call rotations, incident & problem management, change management (normal/standard/emergency), release gating, production readiness reviews, and blameless postmortems with actionable follow‑ups.

    • Establish runbooks, OLAs/SLOs, RACIs, ADRs, and quality gates for platform changes; ensure SOX compliance

    • Maintain a service catalog

  • Site Reliability Engineering  & Automation

    • Define and track SLIs/SLOs and error budgets for key services; drive MTTR reduction and change failure rate improvements.

    • Standardize Infrastructure as Code (Terraform modules), policy‑as‑code (Azure Policy, GCP Org Policies, OPA/Gatekeeper), and CI/CD pipelines (GitHub Actions/Azure DevOps/Cloud Build) with drift detection and auto‑remediation.

    • Build reusable automation for landing zones, networks, and AKS/GKE; enforce Zero Trust IAM hygiene (least privilege, PIM/PAM, workload identities).

  • Security & Compliance

    • Own cloud security posture (CSPM), SIEM/SOAR integration, vulnerability management, and secrets/key management (Key Vault / Secret Manager / KMS).

    • Implement secure‑by‑default guardrails and continuous compliance checks.

  • Hands-on Engineering

    • Write and review code: Terraform (mandatory), Go/PowerShell for automation, pipelines, policy tests

    • Build auto‑remediation functions, CLI tools, and integrations (SSO/SCIM; tagging/FinOps APIs); instrument telemetry (logs/metrics/traces) and dashboards.

    • Enforce secure SDLC practices: code reviews, unit/integration tests, IaC/security scanning, secrets hygiene, and Git workflows.

  • Delivery Leadership

    • Serve as technical lead for projects by contributing to reference architectures, controls, and paved paths

    • Orchestrate cross‑functional delivery (security, platform, network, data, app teams; vendors), remove impediments, and keep outcomes front‑and‑center.

  • FinOps

    • Implement tagging standards, showback/chargeback, budgets/alerts, rightsizing, and commitment optimization (Reservations/Savings Plans/CUDs).

    • Operate rolling forecasts and transparent unit economics; apply FinOps principles to empower teams within global guardrails.

  • Culture & Enablement

    • Coach team members in automation and secure patterns; lead inclusive decision forums (ops reviews, risk/cost councils) with documented outputs.

    • Publish training, playbooks, and templates; increase adoption of paved paths and reduce variance across product teams.

YOU'LL THRIVE IN THIS ROLE IF YOU HAVE THE FOLLOWING SKILLS AND QUALITIES:

Required

  • 7+ years operating production Azure and GCP services; 3+ years in cloud security with demonstrated scale.

  • Experience with a variety of cloud architectures (web/database, API/Microservices, k8s, big data, AI platforms, etc)

  • Deep automation experience with Terraform (module design, environments, state, testing) and CI/CD (GitHub Actions/Azure DevOps/Bitbucket); scripting in PowerShell/Go

  • SRE proficiency: SLIs/SLOs, error budgets, incident/postmortem practices, observability (Azure Monitor/Log Analytics, Cloud Logging/Monitoring, Prometheus/Grafana, OpenTelemetry).

  • Security depth: IAM (Entra ID/Google Cloud IAM, PIM/PAM, workload identity), KMS/Key Vault/Secret Manager, network segmentation (hub‑and‑spoke, Private Link/Service Connect), CSPM/SIEM, vulnerability management.

  • Proven process design & execution: on‑call, incident/problem/change management, production readiness, audit evidence, and runbook quality.

  • Demonstrated ability to code and deliver: building automation/pipelines, testing and scanning, deploying secure changes, and leading releases end‑to‑end.

  • Strong leadership, facilitation, communication, and stakeholder management; habit of documenting ADRs, guardrails, and playbooks.

Preferred

  • Manufacturing/OT/IoT exposure; secure connectivity and segmentation patterns; integration experience with enterprise SaaS (SAP, ServiceNow, Salesforce) using SSO/SCIM.

  • Certifications: CCSK, Azure Security Engineer Associate, Google Professional Cloud Security Engineer, CISSP/CCSP, CKA/CKS

ACKNOWLEDGING THE POWER OF DIVERSITY

BRP is dedicated to nurturing a culture that invites, connects, and propels the ambitions of people of all backgrounds, profiles, beliefs and experiences. Ultimately, the diversity and uniqueness of our people fuel our ingenuity and set the course for the path ahead!

For this reason, we value diversity and we strive to always push each other forward to build an inclusive workplace where every employee feels like they belong, where they can grow and find meaning.

AT BRP, WHEN WE TALK ABOUT BENEFITS, WE GO ALL IN.

Let’s start with a strong foundation - You want it, we have it:

  • Annual bonus based on the company’s financial results

  • Generous paid time away

  • Pension plan

  • Collective saving opportunities

  • Industry leading healthcare fully paid by BRP

What about some feel good perks:

  • Flexible work schedule

  • A summer schedule that varies by department and location

  • Holiday season shutdown

  • Educational resources

  • Discount on BRP products

WELCOME TO BRP

We’re a world leader in recreational vehicles and boats, creating innovative ways to move on snow, water, asphalt, dirt and even in the air. Headquartered in the Canadian town of Valcourt, Quebec, our company is rooted in a spirit of ingenuity and intense customer focus. Today, we operate manufacturing facilities in Canada, the United States, Mexico, Finland, Australia and Austria, with a workforce made up of close to 17,000 spirited people, all driven by the deeply held belief that at work, as with life itself, it’s not about the destination: It’s about the journey.

#LI-Hybrid