Impress employers and recruiters.
Choose from hundreds of resume examples.

Impress employers and recruiters.
Choose from hundreds of resume examples.
Tailor your resume to this Security Specialist, Vulnerability Management (Canada - Remote) role.
Rezi rewrites your resume against AXON-Networks's job description. Free.

Tailor your resume to this Security Specialist, Vulnerability Management (Canada - Remote) role.
Rezi rewrites your resume against AXON-Networks's job description. Free.
Don't guess if your resume is good enough.
See how it scores against the Security Specialist, Vulnerability Management (Canada - Remote) posting at AXON-Networks — free, in seconds.

Don't guess if your resume is good enough.
See how it scores against the Security Specialist, Vulnerability Management (Canada - Remote) posting at AXON-Networks — free, in seconds.
About the Role
Establish and operate a risk-based vulnerability management capability across the company’s cloud platform, applications, Kubernetes and container environments, network infrastructure, software supply chain, and cloud-managed customer-premises equipment (CPE). This is a hands-on security engineering role for someone who can distinguish a scanner finding from a relevant and exploitable vulnerability in the company’s actual environment.
Responsibilities
- Establish authoritative visibility into vulnerabilities across cloud, application, container, Kubernetes, network, endpoint, dependency, firmware and CPE asset classes.
- Determine whether findings and CVEs apply to the versions, configurations, exposure paths and controls present in the environment.
- Prioritize remediation using technical severity, known exploitation, likelihood, reachability, asset criticality, customer impact and compensating controls.
- Create a durable operating model for intake, validation, assignment, service levels, exceptions, rescanning, closure and executive reporting.
- Partner with Engineering, DevOps, NOC, Support, Product and Compliance to reduce measurable exposure without disrupting reliable customer service.
- Own scanning strategy and coverage, including inventorying the attack surface and defining coverage for various assets.
- Design, configure, and maintain authenticated and unauthenticated scans, agent-based assessments, cloud-native configuration checks, container and dependency scans, external attack-surface discovery, and targeted validation tests.
- Establish safe scan windows, credentials, rate limits, exclusions, and testing procedures.
- Evaluate, select, and administer appropriate capabilities from vulnerability management platforms.
- Integrate results from multiple tools rather than requiring one product to solve every use case.
- Measure coverage, scan health, credential success, stale assets, and blind spots; continuously improve asset-to-owner mapping and data quality.
- Review new and existing scan findings to determine their validity and applicability.
- Analyze CVE applicability using affected component and version, package provenance, CPE or firmware bill of materials, runtime reachability, configuration, network exposure, privileges, exploit prerequisites, and existing controls.
- Reproduce or safely validate material findings when needed.
- Document defensible disposition evidence and prevent unsupported suppression of findings or indefinite exception status.
- Monitor vulnerability intelligence and vendor advisories for relevant technologies.
- Use CVSS as a severity input, not a standalone risk decision, and enrich prioritization with CISA KEV, EPSS, exploit availability, exposure, reachability, asset criticality, tenant/customer impact, and compensating controls.
- Define remediation and mitigation targets by risk tier; rapidly escalate actively exploited or internet-reachable vulnerabilities and coordinate emergency response when required.
- Create clear remediation records with affected assets, evidence, owners, due dates, recommended actions, validation criteria, and customer or operational considerations.
- Partner with Engineering and DevOps on patches, upgrades, configuration changes, image rebuilds, dependency updates, firmware releases, and compensating controls; verify closure through rescans or equivalent evidence.
- Manage risk exceptions with documented rationale, accountable approval, compensating controls, expiration dates, and scheduled reassessment.
- Understand the end-to-end service path from cloud control plane and APIs through messaging, device-management protocols, and access networks to CPE.
- Assess vulnerabilities in the context of multi-tenant cloud services, remote device management, certificates and secrets, provisioning, telemetry, firmware delivery, administrative interfaces, and fleet-scale exposure.
- Work with Engineering to identify affected device models, hardware revisions, firmware branches, software components, and deployed cohorts; support safe remediation planning and rollout validation.
- Recognize the different evidence and remediation paths required for cloud software, third-party dependencies, network appliances, embedded Linux, and customer-deployed CPE.
- Build integrations and automation for asset enrichment, deduplication, risk scoring, ticket creation, ownership routing, SLA tracking, notifications, rescans, exception expiry, and evidence collection.
- Maintain dashboards for coverage, exploitable exposure, aging, remediation performance, repeat findings, exceptions, asset ownership, and risk trends.
- Develop playbooks, standards, and procedures for routine vulnerability handling, critical CVEs, zero-day response, scanner administration, and tool outages.
- Provide concise reporting to technical owners and leaders, separating raw finding volume from material risk and clearly identifying decisions or overdue actions.
- Support audits and customer security inquiries with traceable evidence while protecting sensitive vulnerability and customer information.
Requirements
- 5+ years of hands-on experience in vulnerability management, vulnerability assessment, security engineering, product security, cloud security or a closely related discipline.
- Demonstrated ownership of enterprise scanning and vulnerability-management workflows, including scanner configuration, authenticated scanning, coverage analysis, finding validation, false-positive handling, remediation tracking and rescanning.
- Strong CVE analysis skills and the ability to determine applicability and exploitability using versions, configurations, exposure, reachability, privileges, controls and business context.
- Experience with one or more enterprise vulnerability platforms and practical familiarity with complementary cloud, container, dependency, application and open-source scanning tools.
- Working knowledge of CVE/CWE, NVD, CVSS, CISA KEV, EPSS, vendor advisories, software bills of materials and risk-based prioritization.
- Hands-on knowledge of Linux, TCP/IP, DNS, TLS/PKI, identity and access controls, APIs, cloud infrastructure, containers and Kubernetes.
- Ability to read code, package manifests, container images, configurations, logs and network evidence sufficiently to validate findings and guide remediation.
- Scripting or programming ability in Python, Go, PowerShell, Bash or a comparable language, plus experience integrating security platforms with APIs, ticketing and dashboards.
- Strong written and verbal communication, including the ability to explain technical risk, uncertainty, tradeoffs and required decisions to engineers and operational leaders.
- Bachelor’s degree in cybersecurity, computer science, engineering or equivalent practical experience.
- Security experience with service providers, broadband operators, telecom equipment/software vendors, managed-network providers or large distributed device fleets.
- Experience assessing embedded Linux, firmware, broadband gateways, routers, ONTs, Wi-Fi/mesh systems or other CPE/IoT products.
- Familiarity with TR-069/CWMP, TR-369/USP, TR-181, ACS/USP controllers, device provisioning, telemetry, certificates and remote firmware lifecycle management.
- Experience with Google Cloud Platform, Kubernetes, Terraform, Helm, CI/CD and cloud-native security posture or workload-protection platforms.
- Experience with software composition analysis, SBOM/VEX, container/image scanning, secret scanning, SAST/DAST/API security testing and infrastructure-as-code scanning.
- Experience with coordinated vulnerability disclosure, penetration-test finding intake, zero-day response or product security incident response.
- Familiarity with NIST Cybersecurity Framework, NIST SP 800-40, CIS Controls, OWASP guidance, PCI DSS, SOC 2 or ISO 27001 control expectations.
- Relevant certifications such as Security+, CySA+, GSEC, GCIH, GPEN, CISSP, CCSP or vendor-specific vulnerability-management credentials; practical expertise is valued more than certification alone.
- Work primarily during normal business hours with escalation availability for critical, actively exploited or zero-day vulnerabilities.
- Handle sensitive vulnerability, exploit and customer information with strict need-to-know access and evidence controls.
- Coordinate intrusive scans, validation tests and production-impacting work through approved change and maintenance processes.
- Challenge scanner results and remediation claims constructively while maintaining clear evidence, ownership and deadlines.
Skills
- Vulnerability Management
- Vulnerability Assessment
- Security Engineering
- Product Security
- Cloud Security
- Enterprise Scanning
- Vulnerability Assessment Workflows
- Scanner Configuration
- Authenticated Scanning
- Coverage Analysis
- Finding Validation
- False Positive Handling
- Remediation Tracking
- Rescanning
- CVE Analysis
- Applicability Determination
- Exploitability Determination
- Enterprise Vulnerability Platforms
- Cloud Scanning
- Container Scanning
- Dependency Scanning
- Application Scanning
- Open-Source Scanning Tools
- CVE/CWE
- NVD
- CVSS
- CISA KEV
- EPSS
- Vendor Advisories
- Software Bills of Materials
- Risk-Based Prioritization
- Linux
- TCP/IP
- DNS
- TLS/PKI
- Identity and Access Controls
- APIs
- Cloud Infrastructure
- Containers
- Kubernetes
- Code Reading
- Package Manifests
- Container Images
- Configuration Analysis
- Log Analysis
- Network Evidence Analysis
- Python
- Go
- PowerShell
- Bash
- API Integration
- Ticketing System Integration
- Dashboard Integration
- Written Communication
- Verbal Communication
- Technical Risk Explanation
- Service Provider Security
- Broadband Operator Security
- Telecom Equipment Security
- Managed Network Security
- Embedded Linux Assessment
- Firmware Assessment
- Broadband Gateway Assessment
- Router Assessment
- ONT Assessment
- Wi-Fi/Mesh System Assessment
- CPE/IoT Product Assessment
- TR-069/CWMP
- TR-369/USP
- TR-181
- ACS/USP Controllers
- Device Provisioning
- Telemetry
- Certificates
- Remote Firmware Lifecycle Management
- Google Cloud Platform (GCP)
- Terraform
- Helm
- CI/CD
- Cloud-Native Security Posture Management
- Workload Protection Platforms
- Software Composition Analysis (SCA)
- SBOM/VEX
- Secret Scanning
- SAST
- DAST
- API Security Testing
- Infrastructure-as-Code Scanning
- Coordinated Vulnerability Disclosure
- Penetration Test Finding Intake
- Zero-Day Response
- Product Security Incident Response
- NIST Cybersecurity Framework
- NIST SP 800-40
- CIS Controls
- OWASP
- PCI DSS
- SOC 2
- ISO 27001
- Security+
- CySA+
- GSEC
- GCIH
- GPEN
- CISSP
- CCSP
Location
- Irvine, CA USA
- Singapore
- Denmark
- Spain
- Vietnam
Work Type
- Contract
Experience Level
- 5+ years
Education Level
- Bachelor’s degree in cybersecurity, computer science, engineering or equivalent practical experience.
Salary/Compensations
- CAD 60/hr - CAD 90/hr
About the Company
- AXON Networks delivers a robust AI-driven, analytics-based orchestration platform and a wide portfolio of next-gen high-speed routers that leverage the newest Wi-Fi technologies.
- Together, these technologies give ISPs the ability to manage and troubleshoot their networks in real time, and to deliver an outstanding customer experience.
- AXON Networks is a trusted strategic partner for its customers, helping them evaluate their current technologies and business models, and creating and executing strategies that enable them to innovate faster, accelerate their digital transformations, and strengthen their relationships with consumers.
- AXON Networks is headquartered in Irvine, CA USA with Asia HQ in Singapore and also operating in Denmark, Spain and Vietnam.
Equal Opportunity
- At AXON Networks, we promote equal opportunities in all our recruitment processes, ensuring non-discrimination on the basis of gender, age, origin, disability, or any other personal circumstances. We assess talent based on objective criteria and foster an inclusive and diverse working environment.