Vulnerability Management Analyst – ICS/OT, Rapid7, Wiz & MCAS

Summary

Vulnerability Management Senior Analyst focused on ICS/OT security, managing the full vulnerability lifecycle using Rapid7, Wiz, and MCAS while coordinating between IT, OT, and cybersecurity teams to ensure SLA adherence and compliance.

Vulnerability Management Senior Analyst – Rapid7, Wiz, MCAS & ICS Security

Location: Calgary - 4 days WFO

Hybrid

Required Technical Skill Set

• Vulnerability lifecycle management (identify → assess → prioritize → remediate → verify)
• Risk-based prioritization
• Patch management processes and coordination
• Remediation validation and reporting
• False positive analysis and tuning
• SLA tracking and compliance alignment
• Penetration testing basics
• Hands-on experience in Rapid7, MCAS, Wiz.

Must-Have

• Monitor threat intelligence and vendor advisories.
• Analyze vulnerabilities affecting ICS (Industrial Control Systems).
• Analyze and Conduct vulnerability assessments for ICS devices.
• Coordinate activities between OT, IT, cybersecurity, and operations teams.
• Conducted regular vulnerability scans across network, systems, and applications using tools such as Tenable, Qualys, and Rapid7, identifying critical security gaps.
• Managed the end-to-end vulnerability lifecycle including identification, assessment, prioritization, remediation, and validation.
• Partnered with security operations and incident response teams to address actively exploited vulnerabilities and reduce attack surface.
• Delivered continuous improvement initiatives to enhance scanning coverage, reduce MTTR, and strengthen overall security posture.
• Performed risk-based prioritization using threat intelligence and business impact to focus remediation on high-risk vulnerabilities.
• Drive timely remediation and patch management, ensuring SLA adherence.
• Validated remediation efforts through re-scans and manual verification, reducing false positives and ensuring accurate closure.
• Analyzed vulnerability data and generated actionable reports and dashboards for technical teams and executive stakeholders.
• Leveraged automation using Python/PowerShell and APIs to streamline vulnerability scanning, reporting, and remediation workflows.
• Monitored emerging threats using CVE and threat intelligence feeds, correlating exploitability with organizational risk.
• Ensured compliance with industry standards and frameworks such as NIST, CIS Benchmarks, ISO 27001, and PCI-DSS.

Good-to-Have

• Experience in dealing with customers directly and working in a global delivery model.
• Negotiation Skills.
• Good Assertive Communication (Written & Oral).
• External certifications any.


See also

Security jobs by country — openings, pay and top skills →

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available