Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
Scoutfield Logo

See all jobs on Scoutfield

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
Radio-Canada

Lead Information Security Analyst, Vulnerability and External Attack Surface Management

Radio-Canada

. Optimize CBC/Radio-Canada’s vulnerability management program .

Posted 9/15/2026full-timeMontreal • CanadaSeniorWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates expertise in vulnerability management, risk assessment, and compliance with a strong command of security frameworks and methodologies. Capable of providing technical leadership and translating complex security concepts for diverse audiences.

Highest-signal resume keywords
Vulnerability ManagementRisk AssessmentISO/IEC 27001CISSPBilingualism

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
Vulnerability DetectionImpact AnalysisThreat IntelligenceCloud SecurityWeb Infrastructure SecurityLAN/WAN SecurityDatabase ArchitectureSecure Software DevelopmentBCP/DRPCompliance Programs
Soft Skills
Analytical AbilitiesProblem-SolvingCommunication Skills
Tools & Technologies
WAFFirewallsIDS/IPSDNSWeb Filtering
Certifications & Qualifications
CISSPCRISCCBCPCISACISM
Industry Keywords
Vulnerability Management ProgramCVSSMITRE ATT&CKSecurity Technical DebtGovernance

Tech Stack

Tools & technologies
CloudDNSFirewalls

About the role

Key responsibilities & impact
  • Optimize CBC/Radio-Canada’s vulnerability management program
  • Design, build and deploy the external attack surface management service
  • Map and inventory internet-exposed assets, domains, certificates, cloud accounts, public APIs and exposed data
  • Develop procedures to detect exposed services, vulnerable or expired certificates, leaked credentials and source code
  • Lead vulnerability detection, triage, impact analysis, prioritization, remediation and verification
  • Establish the scope and frequency of automated and manual vulnerability scans
  • Assess vulnerabilities using CVSS, business context, asset criticality, compensating controls and threat intelligence
  • Recommend remediation measures such as patching, reconfiguration, workarounds and WAF/firewall rules
  • Provide technical leadership during critical zero-day vulnerabilities and incidents
  • Review and adjudicate security exemption requests and assess residual risk
  • Maintain the vulnerability risk register, security technical debt and approved exceptions
  • Present risk status reports to governance and executive committees
  • Align vulnerability processes with regulatory requirements, internal policies and industry standards
  • Define and track KPIs and KRIs through metrics and dashboards
  • Enhance security tools and processes in response to emerging threats
  • Monitor vulnerability trends, proof-of-concept exploits and evolving frameworks such as CVSS v4 and MITRE ATT&CK
  • Maintain current information security industry expertise

Requirements

What you’ll need
  • University degree in computer science, IT or information security
  • Minimum five years' experience in vulnerability management, risk assessment or IT governance, including at least three years in an information security role
  • Extensive knowledge of security technology and risk assessment methodologies, policies and processes
  • Excellent written and verbal communication skills, with ability to translate complex technical concepts for non-technical decision-makers
  • Excellent analytical, evaluative and problem-solving abilities
  • Experience with compliance programs and their technical and security requirements
  • Strong command of ISO/IEC 27001, 27002, 27005, NIST SP 800-53 / 800-161, COBIT and ITIL
  • Solid understanding of web infrastructure and cloud environment security
  • Thorough understanding of LAN/WAN, routers, firewalls, IDS/IPS, DNS, web filtering and cryptographic principles
  • Working knowledge of database architecture and secure software development best practices
  • Solid understanding of BCP/DRP, operational resilience and physical security controls
  • Relevant professional security certifications are a definite asset, including CISSP, CRISC, CBCP, CISA or CISM
  • Bilingualism (English and French) essential
  • Candidates may be subject to skills and knowledge testing
  • Candidates advancing to the next step must complete a mandatory criminal record check; other background checks may apply

Benefits

Comp & perks
  • Permanent employment status
  • Hybrid work arrangement with a mix of in-office and remote work
  • Work with leading-edge data management, cloud, IP broadcasting, AI, security and reliability technologies
  • Inclusive workplace and equal opportunity
  • Accommodation support during the recruitment process