Own cloud security posture (CSPM), SIEM/SOAR integration, vulnerability management, and secrets/key ... SLIs/SLOs, error budgets, incident/postmortem practices, observability (Azure Monitor/Log Analytics ...
Own cloud security posture (CSPM), SIEM/SOAR integration, vulnerability management, and secrets/key ... SLIs/SLOs, error budgets, incident/postmortem practices, observability (Azure Monitor/Log Analytics ...
Own cloud security posture (CSPM), SIEM/SOAR integration, vulnerability management, and secrets/key ... SLIs/SLOs, error budgets, incident/postmortem practices, observability (Azure Monitor/Log Analytics ...
New
Own cloud security posture (CSPM), SIEM/SOAR integration, vulnerability management, and secrets/key ... SLIs/SLOs, error budgets, incident/postmortem practices, observability (Azure Monitor/Log Analytics ...
New
Security & Compliance Own cloud security posture (CSPM), SIEM/SOAR integration, vulnerability ... SLIs/SLOs, error budgets, incident/postmortem practices, observability (Azure Monitor/Log Analytics ...
Security & Compliance Own cloud security posture (CSPM), SIEM/SOAR integration, vulnerability ... SLIs/SLOs, error budgets, incident/postmortem practices, observability (Azure Monitor/Log Analytics ...
Security Analyst II - IAM
Laval, QC · Hybrid
This role is the analytical backbone of our IAM program you will be the person who digs into the data, maps out the processes, and ensures our identity governance controls are well documented, well ...
Security Analyst II - IAM
Laval, QC · Hybrid
This role is the analytical backbone of our IAM program you will be the person who digs into the data, maps out the processes, and ensures our identity governance controls are well documented, well ...
This role is the analytical backbone of our IAM program you will be the person who digs into the data, maps out the processes, and ensures our identity governance controls are well documented, well ...
This role is the analytical backbone of our IAM program you will be the person who digs into the data, maps out the processes, and ensures our identity governance controls are well documented, well ...
This role is the analytical backbone of our IAM program you will be the person who digs into the data, maps out the processes, and ensures our identity governance controls are well documented, well ...
This role is the analytical backbone of our IAM program you will be the person who digs into the data, maps out the processes, and ensures our identity governance controls are well documented, well ...
This role is the analytical backbone of our IAM program you will be the person who digs into the data, maps out the processes, and ensures our identity governance controls are well documented, well ...
This role is the analytical backbone of our IAM program you will be the person who digs into the data, maps out the processes, and ensures our identity governance controls are well documented, well ...
Plant Supervisor
Contrecoeur, QC · On-site
Performs root cause analysis and assumes responsibility for managing vulnerability studies (VS). * Manages the implementation of Air Liquide technical standards and procedures, and manages and ...
Plant Supervisor
Contrecoeur, QC · On-site
Performs root cause analysis and assumes responsibility for managing vulnerability studies (VS). * Manages the implementation of Air Liquide technical standards and procedures, and manages and ...
Performs root cause analysis and assumes responsibility for managing vulnerability studies (VS). * Manages the implementation of Air Liquide technical standards and procedures, and manages and ...
Performs root cause analysis and assumes responsibility for managing vulnerability studies (VS). * Manages the implementation of Air Liquide technical standards and procedures, and manages and ...
Apply your knowledge of risk analysis, vulnerability assessment and threat monitoring to support operational security and the integration of controls into IT projects 🛡 Security governance intern
Apply your knowledge of risk analysis, vulnerability assessment and threat monitoring to support operational security and the integration of controls into IT projects 🛡 Security governance intern
Apply your knowledge of risk analysis, vulnerability assessment and threat monitoring to support operational security and the integration of controls into IT projects 🛡 Security governance intern
Apply your knowledge of risk analysis, vulnerability assessment and threat monitoring to support operational security and the integration of controls into IT projects 🛡 Security governance intern
Social Work Technician
Montreal, QC · On-site
CA$50/hr
... vulnerability Ensure rigorous record-keeping in accordance with Law 25 Participating in the ... Good listening and psychosocial analysis skills Autonomy and professional judgment Ability to ...
Social Work Technician
Montreal, QC · On-site
CA$50/hr
... vulnerability Ensure rigorous record-keeping in accordance with Law 25 Participating in the ... Good listening and psychosocial analysis skills Autonomy and professional judgment Ability to ...
Social Work Technician
Montreal, QC · On-site
CA$50/hr
... vulnerability Ensure rigorous record-keeping in accordance with Law 25 Participating in the ... Good listening and psychosocial analysis skills Autonomy and professional judgment Ability to ...
Social Work Technician
Montreal, QC · On-site
CA$50/hr
... vulnerability Ensure rigorous record-keeping in accordance with Law 25 Participating in the ... Good listening and psychosocial analysis skills Autonomy and professional judgment Ability to ...
Social Work Technician
Montreal, QC · On-site
CA$50/hr
... vulnerability Ensure rigorous record-keeping in accordance with Law 25 Participating in the ... Good listening and psychosocial analysis skills Autonomy and professional judgment Ability to ...
Social Work Technician
Montreal, QC · On-site
CA$50/hr
... vulnerability Ensure rigorous record-keeping in accordance with Law 25 Participating in the ... Good listening and psychosocial analysis skills Autonomy and professional judgment Ability to ...
Social Work Technician
Montreal, QC · On-site
CA$50/hr
... vulnerability Ensure rigorous record-keeping in accordance with Law 25 Participating in the ... Good listening and psychosocial analysis skills Autonomy and professional judgment Ability to ...
Social Work Technician
Montreal, QC · On-site
CA$50/hr
... vulnerability Ensure rigorous record-keeping in accordance with Law 25 Participating in the ... Good listening and psychosocial analysis skills Autonomy and professional judgment Ability to ...
Social Work Technician
Montreal, QC · On-site
CA$50/hr
... vulnerability Ensure rigorous record-keeping in accordance with Law 25 Participating in the ... Good listening and psychosocial analysis skills Autonomy and professional judgment Ability to ...
Social Work Technician
Montreal, QC · On-site
CA$50/hr
... vulnerability Ensure rigorous record-keeping in accordance with Law 25 Participating in the ... Good listening and psychosocial analysis skills Autonomy and professional judgment Ability to ...
Surveiller et analyser la gestion de l'information de securite et des evenements (GIES) pour reperer les problemes de securite a corriger. * Connaitre la creation d'ensembles de regles de gestion de ...
Surveiller et analyser la gestion de l'information de securite et des evenements (GIES) pour reperer les problemes de securite a corriger. * Connaitre la creation d'ensembles de regles de gestion de ...
IT Security Analyst
Quebec, QC · On-site
Official Internal Job Title: IT Security Analyst Status: Regular Relevant du Directeur - Gestion des identites et des acces, l'analyste securite informatique (GIA), est la passerelle essentielle ...
IT Security Analyst
Quebec, QC · On-site
Official Internal Job Title: IT Security Analyst Status: Regular Relevant du Directeur - Gestion des identites et des acces, l'analyste securite informatique (GIA), est la passerelle essentielle ...
Official Internal Job Title: IT Security Analyst Status: Regular Relevant du Directeur - Gestion des identites et des acces, l'analyste securite informatique (GIA), est la passerelle essentielle ...
Official Internal Job Title: IT Security Analyst Status: Regular Relevant du Directeur - Gestion des identites et des acces, l'analyste securite informatique (GIA), est la passerelle essentielle ...
Ensure platform security and compliance, including certificate management, mesh security policies, and vulnerability remediation. * Analyze and resolve platform issues. * Maintain operational ...
Ensure platform security and compliance, including certificate management, mesh security policies, and vulnerability remediation. * Analyze and resolve platform issues. * Maintain operational ...
Vulnerability Analyst information
See Quebec salary details
$27.64 - $31.73
4% of jobs
$31.73 - $35.82
6% of jobs
$35.82 - $39.90
11% of jobs
$41.10 is the 25th percentile. Wages below this are outliers.
$39.90 - $43.99
13% of jobs
The median wage is $47.60 / hr.
$43.99 - $48.08
18% of jobs
$48.08 - $52.16
13% of jobs
$54.10 is the 75th percentile. Wages above this are outliers.
$52.16 - $56.25
21% of jobs
$56.25 - $60.34
3% of jobs
$60.34 - $64.42
1% of jobs
$64.42 - $68.51
0% of jobs
$68.51 - $72.60
10% of jobs
$27
$49
$72
How much do vulnerability analyst jobs pay per hour?
What are the key skills and qualifications needed to thrive as a vulnerability analyst, and why are they important?
To thrive as a Vulnerability Analyst, you need expertise in cybersecurity principles, risk assessment, and vulnerability management, often supported by a degree in information security or a related field. Familiarity with vulnerability scanning tools (such as Nessus, Qualys, or Rapid7), knowledge of operating systems, and certifications like CompTIA Security+ or CEH are commonly required. Strong analytical thinking, attention to detail, and effective communication skills set top candidates apart. These abilities are crucial for accurately identifying system weaknesses and effectively advising teams on how to remediate security threats.
What are the typical day-to-day responsibilities of a vulnerability analyst?
As a Vulnerability Analyst, your daily tasks often include running vulnerability scans, analyzing findings, prioritizing risks based on severity, and working with IT or development teams to coordinate remediation efforts. You will also document your findings, prepare reports for stakeholders, and stay informed about the latest security threats and exploits. Collaboration with other security professionals and IT staff is common, as resolving vulnerabilities often requires cross-functional teamwork. This role requires a balance of technical analysis and effective communication to ensure organizational security posture is continuously improved.
What is a vulnerability analyst?
A Vulnerability Analyst is a cybersecurity professional responsible for identifying, assessing, and mitigating security weaknesses in an organization's systems, networks, and applications. They use tools like vulnerability scanners, penetration testing frameworks, and security assessments to identify potential threats. Their role includes analyzing vulnerabilities, prioritizing risks, and working with IT and security teams to implement necessary patches or fixes. They also stay up to date with emerging threats and ensure compliance with security policies and regulations.

Other
Medical, Retirement
Re-posted 3 days ago
Job description
The Cloud Business Office is seeking a security-focused Team Lead to operate, secure, and continuously improve our Azure and Google Cloud Platform (GCP) landscape through implementing strong operational process, hands-on coding, and delivery leadership. You will own day-to-day operations; help to set standards and guardrails; and lead projects end-to-end with an automation-first mindset. As a technical leader, you'll coach team members and drive context-appropriate and fit-for-purpose cloud outcomes.
YOU'LL HAVE THE OPPORTUNITY TO:
-
Process Excellence & Operations
-
Design, implement, and run robust cloud operating processes: on‑call rotations, incident & problem management, change management (normal/standard/emergency), release gating, production readiness reviews, and blameless postmortems with actionable follow‑ups.
-
Establish runbooks, OLAs/SLOs, RACIs, ADRs, and quality gates for platform changes; ensure SOX compliance
-
Maintain a service catalog
-
-
Site Reliability Engineering & Automation
-
Define and track SLIs/SLOs and error budgets for key services; drive MTTR reduction and change failure rate improvements.
-
Standardize Infrastructure as Code (Terraform modules), policy‑as‑code (Azure Policy, GCP Org Policies, OPA/Gatekeeper), and CI/CD pipelines (GitHub Actions/Azure DevOps/Cloud Build) with drift detection and auto‑remediation.
-
Build reusable automation for landing zones, networks, and AKS/GKE; enforce Zero Trust IAM hygiene (least privilege, PIM/PAM, workload identities).
-
-
Security & Compliance
-
Own cloud security posture (CSPM), SIEM/SOAR integration, vulnerability management, and secrets/key management (Key Vault / Secret Manager / KMS).
-
Implement secure‑by‑default guardrails and continuous compliance checks.
-
-
Hands-on Engineering
-
Write and review code: Terraform (mandatory), Go/PowerShell for automation, pipelines, policy tests
-
Build auto‑remediation functions, CLI tools, and integrations (SSO/SCIM; tagging/FinOps APIs); instrument telemetry (logs/metrics/traces) and dashboards.
-
Enforce secure SDLC practices: code reviews, unit/integration tests, IaC/security scanning, secrets hygiene, and Git workflows.
-
-
Delivery Leadership
-
Serve as technical lead for projects by contributing to reference architectures, controls, and paved paths
-
Orchestrate cross‑functional delivery (security, platform, network, data, app teams; vendors), remove impediments, and keep outcomes front‑and‑center.
-
-
FinOps
-
Implement tagging standards, showback/chargeback, budgets/alerts, rightsizing, and commitment optimization (Reservations/Savings Plans/CUDs).
-
Operate rolling forecasts and transparent unit economics; apply FinOps principles to empower teams within global guardrails.
-
-
Culture & Enablement
-
Coach team members in automation and secure patterns; lead inclusive decision forums (ops reviews, risk/cost councils) with documented outputs.
-
Publish training, playbooks, and templates; increase adoption of paved paths and reduce variance across product teams.
-
YOU'LL THRIVE IN THIS ROLE IF YOU HAVE THE FOLLOWING SKILLS AND QUALITIES:
Required
-
7+ years operating production Azure and GCP services; 3+ years in cloud security with demonstrated scale.
-
Experience with a variety of cloud architectures (web/database, API/Microservices, k8s, big data, AI platforms, etc)
-
Deep automation experience with Terraform (module design, environments, state, testing) and CI/CD (GitHub Actions/Azure DevOps/Bitbucket); scripting in PowerShell/Go
-
SRE proficiency: SLIs/SLOs, error budgets, incident/postmortem practices, observability (Azure Monitor/Log Analytics, Cloud Logging/Monitoring, Prometheus/Grafana, OpenTelemetry).
-
Security depth: IAM (Entra ID/Google Cloud IAM, PIM/PAM, workload identity), KMS/Key Vault/Secret Manager, network segmentation (hub‑and‑spoke, Private Link/Service Connect), CSPM/SIEM, vulnerability management.
-
Proven process design & execution: on‑call, incident/problem/change management, production readiness, audit evidence, and runbook quality.
-
Demonstrated ability to code and deliver: building automation/pipelines, testing and scanning, deploying secure changes, and leading releases end‑to‑end.
-
Strong leadership, facilitation, communication, and stakeholder management; habit of documenting ADRs, guardrails, and playbooks.
Preferred
-
Manufacturing/OT/IoT exposure; secure connectivity and segmentation patterns; integration experience with enterprise SaaS (SAP, ServiceNow, Salesforce) using SSO/SCIM.
-
Certifications: CCSK, Azure Security Engineer Associate, Google Professional Cloud Security Engineer, CISSP/CCSP, CKA/CKS
ACKNOWLEDGING THE POWER OF DIVERSITY
BRP is dedicated to nurturing a culture that invites, connects, and propels the ambitions of people of all backgrounds, profiles, beliefs and experiences. Ultimately, the diversity and uniqueness of our people fuel our ingenuity and set the course for the path ahead!
For this reason, we value diversity and we strive to always push each other forward to build an inclusive workplace where every employee feels like they belong, where they can grow and find meaning.
AT BRP, WHEN WE TALK ABOUT BENEFITS, WE GO ALL IN.
Let’s start with a strong foundation - You want it, we have it:
-
Annual bonus based on the company’s financial results
-
Generous paid time away
-
Pension plan
-
Collective saving opportunities
-
Industry leading healthcare fully paid by BRP
What about some feel good perks:
-
Flexible work schedule
-
A summer schedule that varies by department and location
-
Holiday season shutdown
-
Educational resources
-
Discount on BRP products
WELCOME TO BRP
We’re a world leader in recreational vehicles and boats, creating innovative ways to move on snow, water, asphalt, dirt and even in the air. Headquartered in the Canadian town of Valcourt, Quebec, our company is rooted in a spirit of ingenuity and intense customer focus. Today, we operate manufacturing facilities in Canada, the United States, Mexico, Finland, Australia and Austria, with a workforce made up of close to 17,000 spirited people, all driven by the deeply held belief that at work, as with life itself, it’s not about the destination: It’s about the journey.
#LI-Hybrid
About BOMBARDIER RECREATIONAL PRODUCTS
Sourced by ZipRecruiter
Industry
Manufacturing
Company size
10,000+ Employees
Headquarters location
Valcourt, QC, CA