Cybersecurity Vulnerability Engineer
- Role
- Security
- Experience
- Senior
- Employment
- Full-time
Open to CA only. Set where you work from to check your eligibility.
No BS summary
Cybersecurity Vulnerability Engineer with 5+ years of experience in cybersecurity, including 3-4 years in vulnerability management, analysis, security engineering, incident response, threat intelligence, or penetration testing. Must have a strong understanding of vulnerability exploitation, attack paths, operating systems, enterprise applications, networking, and common security controls. Experience with Windows and Linux environments, network infrastructure, cloud technologies, and enterprise applications is required. Bachelor's degree in a related field is necessary.
Core skills
Required skills
Optional skills
Required languages
What you'll do
- Monitor and evaluate newly disclosed and emerging vulnerabilities from Thales CTI, OSINT, Thales CERT, PSIRT, vendor advisories, security researchers, vulnerability databases, and other trusted sources.
- Initiate and coordinate enterprise vulnerability-response activities for vulnerabilities with potential impact to Thales businesses and networks.
- Engage infrastructure, IT, application, cloud, product, and security teams to validate exposure and determine required actions.
- Establish clear ownership, priorities, response timelines, and escalation paths.
- Track remediation and mitigation activities through completion and validate that identified risk has been appropriately addressed.
- Escalate missed timelines, unresolved ownership, significant technical uncertainty, or material residual risk to appropriate leadership.
- Maintain clear status reporting for technical teams, cybersecurity leadership, and other stakeholders.
- Analyze newly disclosed vulnerabilities to understand affected components, exploitation prerequisites, attack vectors, required privileges, exploitability, potential impact, and available mitigations.
- Review CVEs, vendor advisories, security-research publications, proof-of-concept information, exploit intelligence, and relevant technical documentation.
- Assess whether vulnerable technologies or configurations are present in the enterprise and partner with technology owners to validate actual exposure.
- Translate complex vulnerability information into clear, actionable guidance for infrastructure, application, product-development, and leadership teams.
- Partner with detection and incident-response teams when a vulnerability requires investigation for possible prior exploitation or additional monitoring.
What they require
- Bachelor’s degree in computer information systems, programming, engineering or a related field with a minimum of 5+ years of cybersecurity experience, including at least 3–4 years in vulnerability management, vulnerability analysis, security engineering, incident response, threat intelligence, penetration testing, or a closely related technical security function.
- 5 to 7 years of experience in Cybersecurity domains.
- 3 to 5 years of experience in demonstrated experience analyzing CVEs and determining their relevance and actual impact within complex enterprise environments.
- Strong understanding of vulnerability exploitation, attack paths, operating systems, enterprise applications, networking, authentication, privilege boundaries, and common security controls.
- Ability to interpret vendor advisories, technical security research, proof-of-concept information, logs, configurations, and vulnerability evidence.
- Working knowledge of Windows and Linux environments, network infrastructure, cloud technologies, virtualization, containers, and enterprise applications.
- Ability to independently coordinate urgent, cross-functional technical response activities involving multiple teams and competing priorities.
- Strong organizational skills and the ability to track multiple concurrent vulnerability-response activities through closure.
- Must be highly analytical and detail-oriented, with organizational skills to manage assigned work to completion.
- Experience supporting large, complex, or globally distributed enterprise environments.
- Experience working across corporate IT, shared infrastructure, software-development, cloud, and product environments.
- Experience using scripting or automation with Python, PowerShell, APIs, SQL, or similar technologies to support vulnerability analysis and data correlation.
- This position requires direct or indirect access to hardware, software or technical information controlled under the Canadian Export Control List, the Canadian Controlled Goods Program, the Canadian Industrial Security Program, the US International Traffic in Arms Regulations (ITAR) and/or the US Export Administration Regulations (EAR).
- All applicants must be eligible or able to obtain authorization for such access including eligibility to the Canadian Controlled Goods Program and able to obtain a Canadian NATO Secret clearance.
Benefits
- Company paid Extended Health, Dental, HSA, Life, AD&D, Short-term Disability, Cancer Care Program, travel insurance, Employee Assistance Plan and Well-Being program.
- Retirement Savings Plans (RRSP, DCPP, TFSA) with a company contribution and a match to a DCPP, with no vesting period.
- Company paid holidays, vacation days, and paid sick leave.
- Voluntary Life, AD&D, Critical Illness, Long-Term Disability.
- Employee Discounts on home, auto, and gym membership.
Thales people architect identity management and data protection solutions at the heart of digital security. Business and governments rely on us to bring trust to the billions of digital interactions they have with people. Our technologies and services help banks exchange funds, people cross borders, energy become smarter and much more. More than 30,000 organizations already rely on us to verify the identities of people and things, grant access to digital services, analyze vast quantities of information and encrypt data to make the connected world more secure.