This role operates in a fastpaced environment where responsibilities such as vulnerability management, SIEM monitoring, incident response, security awareness activities, and metrics reporting may ...
New
This role operates in a fastpaced environment where responsibilities such as vulnerability management, SIEM monitoring, incident response, security awareness activities, and metrics reporting may ...
New
This role operates in a fastpaced environment where responsibilities such as vulnerability management, SIEM monitoring, incident response, security awareness activities, and metrics reporting may ...
New
Toronto, ON ยท On-site
CA$81K - CA$115K/yr
Support vulnerability management business-as-usual operations, including scanning coordination, operational tracking, issue follow-up, and stakeholder communications. * Analyze and validate ...
New
Toronto, ON ยท On-site
CA$81K - CA$115K/yr
Support vulnerability management business-as-usual operations, including scanning coordination, operational tracking, issue follow-up, and stakeholder communications. * Analyze and validate ...
New
Must be highly analytical and detail-oriented, with organizational skills to manage assigned work ... vulnerability analysis and data correlation. Physical Demands Typical Office environment Special ...
Must be highly analytical and detail-oriented, with organizational skills to manage assigned work ... vulnerability analysis and data correlation. Physical Demands Typical Office environment Special ...
Senior Cybersecurity Specialist, Vulnerability Management Take a central role The Bank of Canada has a vision to be a leading central bank-dynamic, engaged and trusted-committed to a better Canada.
Senior Cybersecurity Specialist, Vulnerability Management Take a central role The Bank of Canada has a vision to be a leading central bank-dynamic, engaged and trusted-committed to a better Canada.
Engineer - Cybersecurity (Vulnerability & Threat Management) Location: Krakow, Poland (Hybrid) Type: Full-time employment Hybrid work: 2 days in office and 3 days remote Working Hours: 9 am - 5 pm ...
Engineer - Cybersecurity (Vulnerability & Threat Management) Location: Krakow, Poland (Hybrid) Type: Full-time employment Hybrid work: 2 days in office and 3 days remote Working Hours: 9 am - 5 pm ...
Toronto, ON ยท On-site
Conduct vulnerability assessments, validate findings, prioritize risks, and coordinate remediation efforts. Support identity and access management processes, including user provisioning, access ...
Toronto, ON ยท On-site
Conduct vulnerability assessments, validate findings, prioritize risks, and coordinate remediation efforts. Support identity and access management processes, including user provisioning, access ...
Analyze vulnerability and remediation data to produce dashboards and management reports ... Identifying and articulating the means to resolution / remediation of servers as part of the ...
Analyze vulnerability and remediation data to produce dashboards and management reports ... Identifying and articulating the means to resolution / remediation of servers as part of the ...
CA$73K - CA$100K/yr
This role manages endpoint security and vulnerability assessments, collaborates with Cybersecurity and IT Operations, serves as an escalation point for complex endpoint issues, and contributes to ...
CA$73K - CA$100K/yr
This role manages endpoint security and vulnerability assessments, collaborates with Cybersecurity and IT Operations, serves as an escalation point for complex endpoint issues, and contributes to ...
Toronto, ON ยท Hybrid
This role operates in a fastpaced environment where responsibilities such as vulnerability management, SIEM monitoring, incident response, security awareness activities, and metrics reporting may ...
Toronto, ON ยท Hybrid
This role operates in a fastpaced environment where responsibilities such as vulnerability management, SIEM monitoring, incident response, security awareness activities, and metrics reporting may ...
CA$138K - CA$181K/yr
Improve Vulnerability Management * Drive vulnerability triage, prioritization, remediation, and retesting. * Partner with engineering teams to implement risk-based remediation practices. * Mature bug ...
CA$138K - CA$181K/yr
Improve Vulnerability Management * Drive vulnerability triage, prioritization, remediation, and retesting. * Partner with engineering teams to implement risk-based remediation practices. * Mature bug ...
Toronto, ON ยท On-site
Improve Vulnerability Management * Drive vulnerability triage, prioritization, remediation, and retesting. * Partner with engineering teams to implement risk-based remediation practices. * Mature bug ...
Quick apply
Toronto, ON ยท On-site
Improve Vulnerability Management * Drive vulnerability triage, prioritization, remediation, and retesting. * Partner with engineering teams to implement risk-based remediation practices. * Mature bug ...
Drive risk-based vulnerability management across infrastructure and cloud environments by prioritizing remediation and partnering with stakeholders to reduce risk. * Design, implement, and ...
Drive risk-based vulnerability management across infrastructure and cloud environments by prioritizing remediation and partnering with stakeholders to reduce risk. * Design, implement, and ...
London, ON ยท On-site
Proactively identify and mitigate potential network security threats, ensuring continuous vulnerability management. * Stay updated on emerging cybersecurity threats and vulnerabilities, implementing ...
London, ON ยท On-site
Proactively identify and mitigate potential network security threats, ensuring continuous vulnerability management. * Stay updated on emerging cybersecurity threats and vulnerabilities, implementing ...
Demonstrated expertise in vulnerability management, including strong knowledge of security frameworks, governance practices, and vulnerability assessment methodologies * Strong leadership and project ...
Demonstrated expertise in vulnerability management, including strong knowledge of security frameworks, governance practices, and vulnerability assessment methodologies * Strong leadership and project ...
... Access Management Operations (IAMO) is responsible for the security posture, and continuous ... and vulnerability remediation, support for identity governance standards and adoption, and ...
... Access Management Operations (IAMO) is responsible for the security posture, and continuous ... and vulnerability remediation, support for identity governance standards and adoption, and ...
Proactively identify and mitigate potential network security threats, ensuring continuous vulnerability management. * Stay updated on emerging cybersecurity threats and vulnerabilities, implementing ...
Proactively identify and mitigate potential network security threats, ensuring continuous vulnerability management. * Stay updated on emerging cybersecurity threats and vulnerabilities, implementing ...
Understanding of cybersecurity operations, incident response, vulnerability management, security monitoring, and common SOC processes. * Familiarity with security frameworks and practices such as the ...
Understanding of cybersecurity operations, incident response, vulnerability management, security monitoring, and common SOC processes. * Familiarity with security frameworks and practices such as the ...
Toronto, ON ยท On-site
... vulnerability identification and remediation, and secure design patterns. You will also lead our ... Lead and grow the Product Security team, managing, coaching, and developing a team of senior ...
Toronto, ON ยท On-site
... vulnerability identification and remediation, and secure design patterns. You will also lead our ... Lead and grow the Product Security team, managing, coaching, and developing a team of senior ...
Research and build new vulnerability prioritization models, run simulations to test approaches, and validate enhancements that improve how we manage security risk * Develop and maintain robust data ...
Research and build new vulnerability prioritization models, run simulations to test approaches, and validate enhancements that improve how we manage security risk * Develop and maintain robust data ...
Toronto, ON ยท Remote
CA$90K - CA$108K/yr
Knowledge of OWASP Top 10, secure coding, vulnerability management, and application security. * Experience with Mend.io or similar SCA/security platforms. * Excellent leadership and communication ...
Toronto, ON ยท Remote
CA$90K - CA$108K/yr
Knowledge of OWASP Top 10, secure coding, vulnerability management, and application security. * Experience with Mend.io or similar SCA/security platforms. * Excellent leadership and communication ...
$29K - $41K
3% of jobs
$41K - $53K
4% of jobs
$53K - $65K
4% of jobs
$65K - $77K
12% of jobs
$79.5K is the 25th percentile. Wages below this are outliers.
$77K - $89K
6% of jobs
$89K - $101K
6% of jobs
$101K - $113K
12% of jobs
The median wage is $114.4K / yr.
$113K - $125K
14% of jobs
$134.4K is the 75th percentile. Wages above this are outliers.
$125K - $137K
16% of jobs
$137K - $149K
12% of jobs
$149K - $161K
10% of jobs
$29K
$109.6K
$161K
| Aspect | Vulnerability Manager | Security Analyst |
|---|---|---|
| Certifications | Certified Vulnerability Assessor (CVA), CISSP, CEH | CISSP, Security+, CEH |
| Work Environment | Oversees vulnerability assessments, manages teams, develops strategies | Monitors security systems, analyzes threats, responds to incidents |
| Employer & Industry Usage | Used in cybersecurity teams across industries to manage vulnerabilities | Commonly employed in security operations centers (SOCs) to analyze threats |
While both roles focus on cybersecurity, Vulnerability Managers primarily oversee vulnerability assessments and strategy, whereas Security Analysts focus on monitoring and incident response. Both roles require relevant certifications and work within cybersecurity teams, but their daily responsibilities and focus areas differ.
Cities in Ontario with the most Vulnerability Manager job openings:

Full-time
Medical, Life, Retirement
Posted 3 days ago
New
Application Deadline:
Address:
250 Yonge StreetJob Family Group:
BMO BLUE REWARDS is seeking an experienced IT Vulnerability Security Analyst to join our Security Operations team. This role operates in a fastpaced environment where responsibilities such as vulnerability management, SIEM monitoring, incident response, security awareness activities, and metrics reporting may occur simultaneously-often alongside troubleshooting and internal consulting.
In addition to detecting and responding to security threats across the organization's digital infrastructure, the Security Analyst will be expected to demonstrate strong expertise in vulnerability management, system hardening, endpoint security, and cybersecurity incident response. The ideal candidate will bring a proven track record in these areas, supported by relevant industry-recognized certifications.
Join a team where you can make a measurable security impact, continuously grow your expertise, and advance your career while helping protect the business. This role offers the opportunity to protect the organisation from cyber threats while developing highly valuable cybersecurity skills and experience.
This role follows a hybrid work model, with employees expected to work from the office three days per week. The successful candidate will be based at Blue Rewards (BR) , part of the Bank of Montreal family of companies, at its downtown Toronto office located at 250 Yonge Street, Toronto, Ontario.
This position follows a standard Monday to Friday schedule from 9:00 a.m. to 5:00 p.m., with no shift work required.
As part of the role, the successful candidate will participate in a 24/7 pager-based on-call rotation, typically one week per month (Tuesday to Tuesday), including coverage during statutory holidays when scheduled.
Additional compensation is provided for participation in the on-call rotation.
CORE/KEY SKILLS and experience :
3-4 years of expertise with enterprise vulnerability management tools (Tenable, Qualys, Rapid7, etc.).
3-4 years of demonstrated success in understanding of vulnerabilities, CVEs, CVSS, and risk prioritization, specially nowadays with AI-enabled threats.
Strogn experience with analyzing scan results and validating remediation actions (including suggestion of security controls to be implemented to reduce the exploitability of the vulnerability).Ability to collaborate with technical teams to drive timely vulnerability remediation efforts.
Strong analytical and communication skills with experience reporting on security risk and remediation metrics.
Proficiency with cloud-based vulnerability scan tools, SIEM(s), endpoint protection platforms, email security solutions, and incident response frameworks.
Experience monitoring, analysing, and responding to cybersecurity threats and security alerts.
Strong understanding of cybersecurity principles, technologies, and security controls.
Experience with security tools such as SIEM, EDR, email security, and mainly on vulnerability management platforms.
Ability to investigate security incidents and perform root cause analysis.
Strong analytical and problem-solving skills with attention to detail.
Ability to communicate security risks, findings, and recommendations clearly to stakeholders (sometimes, non-technical)
Knowledge of common cyber threats, attack techniques, and mitigation strategies.
Ability to deal with many initiatives/work at the same time
Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field.
Proven experience in security operations, vulnerability management, endpoint security, and incident response.
Analytical and Communication Skills: Strong analytical abilities, attention to detail, prioritization skills, and excellent written and verbal communication skills.
Teamwork: Ability to work collaboratively in a fast-paced environment and communicate effectively with technical and non-technical stakeholders.
Recognized professional certifications such as GIAC Incident Handler (GCIH), Certified Ethical Hacker (CEH or CEH-Practical). Vendor-based and relevant cloud certifications from major public cloud providers (e.g., AWS, GCP, Azure) are highly desirable.
KEY Responsibilities:
Vulnerability and Configuration Management: ongoing operations to conduct regular vulnerability scans, assess risks, and advise on remediation efforts to minimize exposure to cyber threats, and adherence to remediation timelines.
Monitor, Detect, and Respond to Security Threats: Utilize Security Information and Event Management (SIEM) tools to identify, correlate and escalate potential security incidents.
Endpoint and Email Security: Manage and enhance endpoint protection solutions and email security protocols to safeguard against malware, phishing, and other cyberattacks.
Incident Response: Act as a key member of the incident response team, coordinating with IT and business stakeholders to investigate, contain, and remediate security incidents. This may involve on-call 24/7 pager rotation with other team members.
Security Documentation and Metrics Reporting: Maintain detailed playbooks, incident reports, and security documentation. Collect data and generate regular reports on security metrics and threat trends for senior management.
Collaboration and Training: Work closely with IT, infrastructure, and compliance teams to enforce security policies and support user awareness training initiative.
Continuous Improvement: Recommend and implement improvements to security processes, tools, and procedures based on emerging threats and best practices.
Compliance and Audits: Assist with compliance audits, risk assessments, and ensure adherence to internal policies and external regulations
Additional Information:
Monitors, restores service, changes, supports and handles day-to-day activities 7/24/365 required to run the mission critical Information Security systems for BMO. Provides responsive customer service in support of cyber security.
Qualifications:
Salary:
Pay Type:
SalariedThe above represents AIR MILES' pay range and type.
Salaries will vary based on factors such as location, skills, experience, education, and qualifications for the role, and may include a commission structure. Salaries for part-time roles will be pro-rated based on number of hours regularly worked. For commission roles, the salary listed above represents AIR MILES' expected target for the first year in this position.
AIR MILES' total compensation package will vary based on the pay type of the position and may include performance-based incentives, discretionary bonuses, as well as other perks and rewards. AIR MILES also offers health insurance, tuition reimbursement, accident and life insurance, and retirement savings plans. To view more details of our benefits, please visit: https://jobs.bmo.com/global/en/Total-Rewards
About Us
The AIR MILES Reward Program is one of Canada's most recognized loyalty programs, with over 10 million active collector accounts, representing more than half of all Canadian households. AIR MILES collectors earn Reward Miles at more than 300 leading Canadian, global and online brands and at thousands of retail and service locations across the country. AIR MILES is a wholly-owned subsidiary of the Bank of Montreal (BMO). BMO is Canada's oldest bank and the 8th largest in North America with more than 12 million customers globally.
As a member of the AIR MILES team you are valued, respected and heard, and you have more ways to grow and make an impact. We strive to help you make an impact from day one - for yourself and our customers. We'll support you with the tools and resources you need to reach new milestones, as you help our customers reach theirs. From in-depth training and coaching, to manager support and network-building opportunities, we'll help you gain valuable experience, and broaden your skillset.
To find out more visit us at https://bmo.wd3.myworkdayjobs.com/en-US/External-AIR-MILES.
AIR MILES is committed to an inclusive, equitable and accessible workplace. By learning from each other's differences, we gain strength through our people and our perspectives. Accommodations are available on request for candidates taking part in all aspects of the selection process. To request accommodation, please contact your recruiter.
Note to Recruiters: AIR MILES does not accept unsolicited resumes from any source other than directly from a candidate. Any unsolicited resumes sent to AIR MILES, directly or indirectly, will be considered AIR MILES property. AIR MILES will not pay a fee for any placement resulting from the receipt of an unsolicited resume. A recruiting agency must first have a valid, written and fully executed agency agreement contract for service to submit resumes.