- Company Name
- Loblaw Companies Limited
- Job Title
- Senior Analyst, Vulnerability and Compliance Management
- Job Description
-
**Job title:** Senior Analyst, Vulnerability and Compliance Management
**Role Summary:**
Lead and execute the vulnerability management (VM) program within a large enterprise, integrating asset discovery, scanning, risk analysis, and remediation across on‑premises, virtual, and cloud environments.
Collaborate with cross‑functional teams, managed service providers, and vendors to automate VM processes, maintain tooling, and report risk status to stakeholders.
**Expectations:**
- Ensure continuous identification and remediation of vulnerabilities.
- Deliver accurate, risk‑prioritized reports to technical and business stakeholders.
- Maintain configuration and policy compliance across Windows, Linux, and container platforms.
- Provide expertise on industry frameworks (CIS, NIST, CVSS, EPSS).
**Key Responsibilities:**
- Manage VM and configuration tools (Qualys, Rapid7, Tenable, XSOAR, CMDB).
- Design, automate, and evolve scanning schedules and remediation workflows.
- Roll out and troubleshoot VM agents on servers, VMs, and containers.
- Build and maintain Power BI dashboards and database queries for vulnerability metrics.
- Coordinate with infrastructure, application, and security teams to prioritize and close remediation tickets.
- Escalate critical vulnerabilities and lead incident response discussions.
- Produce risk‑based reports for executive and technical audiences.
- Participate in security governance meetings and audit reviews.
**Required Skills:**
- Hands‑on experience with VM tools (Qualys, Rapid7, Tenable).
- Proficiency in database querying (SQL) and Power BI reporting.
- Scripting knowledge (Python, PowerShell, Bash).
- Understanding of configuration scanning, policy compliance frameworks, and scoring models (CVSS, EPSS).
- Experience with enterprise infrastructure: Windows & Linux servers, Hyper‑V/VX, Docker/Containers, GCP, Azure, Oracle Cloud.
- Knowledge of CIS Benchmarks, NIST SP 800‑53, and similar standards.
- Strong communication skills for cross‑team coordination and reporting.
**Required Education & Certifications:**
- Bachelor’s degree in Computer Science, Information Security, or related field (or equivalent work experience).
- Industry certifications considered strong assets:
- CISSP, CCSP (ISC2)
- CISM (ISACA)
- GSEC, GCIA, GMON (SANS)
- Any relevant vendor‑specific security or cloud certifications.