FREE ACCESS
5,000–10,000 jobs/day
See all jobs on Scoutfield
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.

Lead Information Security Analyst, Vulnerability and External Attack Surface Management
Radio-Canada. Optimize CBC/Radio-Canada’s vulnerability management program .
Core Competencies
Role fitCore Competencies
Use this summary to align your resume positioning with the role.
Demonstrates expertise in vulnerability management, risk assessment, and compliance with a strong command of security frameworks and methodologies. Capable of providing technical leadership and translating complex security concepts for diverse audiences.
Highest-signal resume keywords
Vulnerability ManagementRisk AssessmentISO/IEC 27001CISSPBilingualism
ATS Keywords
Tailor your resumeApplicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills
Vulnerability DetectionImpact AnalysisThreat IntelligenceCloud SecurityWeb Infrastructure SecurityLAN/WAN SecurityDatabase ArchitectureSecure Software DevelopmentBCP/DRPCompliance Programs
Soft Skills
Analytical AbilitiesProblem-SolvingCommunication Skills
Tools & Technologies
WAFFirewallsIDS/IPSDNSWeb Filtering
Certifications & Qualifications
CISSPCRISCCBCPCISACISM
Industry Keywords
Vulnerability Management ProgramCVSSMITRE ATT&CKSecurity Technical DebtGovernance
Tech Stack
Tools & technologiesCloudDNSFirewalls
About the role
Key responsibilities & impact- Optimize CBC/Radio-Canada’s vulnerability management program
- Design, build and deploy the external attack surface management service
- Map and inventory internet-exposed assets, domains, certificates, cloud accounts, public APIs and exposed data
- Develop procedures to detect exposed services, vulnerable or expired certificates, leaked credentials and source code
- Lead vulnerability detection, triage, impact analysis, prioritization, remediation and verification
- Establish the scope and frequency of automated and manual vulnerability scans
- Assess vulnerabilities using CVSS, business context, asset criticality, compensating controls and threat intelligence
- Recommend remediation measures such as patching, reconfiguration, workarounds and WAF/firewall rules
- Provide technical leadership during critical zero-day vulnerabilities and incidents
- Review and adjudicate security exemption requests and assess residual risk
- Maintain the vulnerability risk register, security technical debt and approved exceptions
- Present risk status reports to governance and executive committees
- Align vulnerability processes with regulatory requirements, internal policies and industry standards
- Define and track KPIs and KRIs through metrics and dashboards
- Enhance security tools and processes in response to emerging threats
- Monitor vulnerability trends, proof-of-concept exploits and evolving frameworks such as CVSS v4 and MITRE ATT&CK
- Maintain current information security industry expertise
Requirements
What you’ll need- University degree in computer science, IT or information security
- Minimum five years' experience in vulnerability management, risk assessment or IT governance, including at least three years in an information security role
- Extensive knowledge of security technology and risk assessment methodologies, policies and processes
- Excellent written and verbal communication skills, with ability to translate complex technical concepts for non-technical decision-makers
- Excellent analytical, evaluative and problem-solving abilities
- Experience with compliance programs and their technical and security requirements
- Strong command of ISO/IEC 27001, 27002, 27005, NIST SP 800-53 / 800-161, COBIT and ITIL
- Solid understanding of web infrastructure and cloud environment security
- Thorough understanding of LAN/WAN, routers, firewalls, IDS/IPS, DNS, web filtering and cryptographic principles
- Working knowledge of database architecture and secure software development best practices
- Solid understanding of BCP/DRP, operational resilience and physical security controls
- Relevant professional security certifications are a definite asset, including CISSP, CRISC, CBCP, CISA or CISM
- Bilingualism (English and French) essential
- Candidates may be subject to skills and knowledge testing
- Candidates advancing to the next step must complete a mandatory criminal record check; other background checks may apply
Benefits
Comp & perks- Permanent employment status
- Hybrid work arrangement with a mix of in-office and remote work
- Work with leading-edge data management, cloud, IP broadcasting, AI, security and reliability technologies
- Inclusive workplace and equal opportunity
- Accommodation support during the recruitment process