Vulnerability Management Analyst – ICS/OT, Rapid7, Wiz & MCAS
Summary
Vulnerability Management Senior Analyst focused on ICS/OT security, managing the full vulnerability lifecycle using Rapid7, Wiz, and MCAS while coordinating between IT, OT, and cybersecurity teams to ensure SLA adherence and compliance.
Vulnerability Management Senior Analyst – Rapid7, Wiz, MCAS & ICS Security Location: Calgary - 4 days WFO Hybrid Required Technical Skill Set • Vulnerability lifecycle management (identify → assess → prioritize → remediate → verify) • Risk-based prioritization • Patch management processes and coordination • Remediation validation and reporting • False positive analysis and tuning • SLA tracking and compliance alignment • Penetration testing basics • Hands-on experience in Rapid7, MCAS, Wiz. Must-Have • Monitor threat intelligence and vendor advisories. • Analyze vulnerabilities affecting ICS (Industrial Control Systems). • Analyze and Conduct vulnerability assessments for ICS devices. • Coordinate activities between OT, IT, cybersecurity, and operations teams. • Conducted regular vulnerability scans across network, systems, and applications using tools such as Tenable, Qualys, and Rapid7, identifying critical security gaps. • Managed the end-to-end vulnerability lifecycle including identification, assessment, prioritization, remediation, and validation. • Partnered with security operations and incident response teams to address actively exploited vulnerabilities and reduce attack surface. • Delivered continuous improvement initiatives to enhance scanning coverage, reduce MTTR, and strengthen overall security posture. • Performed risk-based prioritization using threat intelligence and business impact to focus remediation on high-risk vulnerabilities. • Drive timely remediation and patch management, ensuring SLA adherence. • Validated remediation efforts through re-scans and manual verification, reducing false positives and ensuring accurate closure. • Analyzed vulnerability data and generated actionable reports and dashboards for technical teams and executive stakeholders. • Leveraged automation using Python/PowerShell and APIs to streamline vulnerability scanning, reporting, and remediation workflows. • Monitored emerging threats using CVE and threat intelligence feeds, correlating exploitability with organizational risk. • Ensured compliance with industry standards and frameworks such as NIST, CIS Benchmarks, ISO 27001, and PCI-DSS. Good-to-Have • Experience in dealing with customers directly and working in a global delivery model. • Negotiation Skills. • Good Assertive Communication (Written & Oral). • External certifications any. |