Base Career helps you apply smarter for this job.
Key skills for this role
Conduct in-depth vulnerability research and analysis.
Produce timely, consolidated, multi-source vulnerability intelligence reports (e.g., vulnerability assessments, briefings,).
Conduct deep-dive research into emerging vulnerability trends, specifically focusing on the intersection of cybersecurity and Frontier AI (e.g., adversarial machine learning, LLM vulnerabilities, and AI supply chain risks).
Translate highly technical vulnerability findings into clear, risk-quantified business narratives for executive leadership and board-level consumption.
Monitor vulnerabilities through a variety of tools and sources and rank them according to relevance to Payments Canada.
Collaborate with internal stakeholders to define vulnerability operations requirements.
Own, design, and mature the end-to-end vulnerability management lifecycle, evaluating and optimizing SLAs for remediation across corporate and payment systems.
Evolve traditional risk-ranking methodologies by combining CVE and KEV scores with real-world threat intelligence and AI-specific threat modeling (e.g., MITRE ATLAS).
Establish automated workflows and monitoring plans to ingest, filter, and prioritize massive data streams of threat and vulnerability data efficiently.
Report any imminent vulnerabilities to the organization in a timely manner.
Coordinate the response, including reporting, on vulnerabilities to multiple levels of stakeholders.
Provide cyber-focused guidance and vulnerability operations support to internal stakeholders.
Skip the repetitive application forms
Install the Base Career Chrome Extension and autofill job applications across major job boards with your profile.
Trusted by over 500,000 job seekers on Base Career
More from this employer
Ottawa, CAN
Payments Canada is seeking a Senior Risk Analyst to support payment product risk management within its Enterprise Risk Management program. The role develops risk frameworks, monitors payment systems and strategic initiat
Toronto, CAN
Payments Canada is seeking a Senior Risk Analyst to support payment product risk management within its Enterprise Risk Management program. The role covers risk frameworks, oversight, reporting, research, stakeholder chal
Ottawa, CAN
Payments Canada is seeking an Analyst, Technology Governance to manage data governance, GRC operations, technology lifecycle controls, and cross-functional remediation. The role requires experience with data structures,
Toronto, CAN
Ottawa, CAN
Payments Canada is seeking a Director to build and lead product enablement governance, roadmap, go-to-market, communications, and performance frameworks in a regulated payments environment. The role requires extensive pr
Toronto, CAN
Payments Canada is seeking a Senior Analyst, Vulnerability Operations to lead and mature its cyber vulnerability management program across applications and on-premise and cloud infrastructure. The role requires vulnerabi
Ottawa, CAN
Toronto, CAN
Toronto, CAN
Ottawa, CAN
Ottawa, CAN
Toronto, CAN
Ottawa, CAN
Toronto, CAN
Facilitate regular, cross-functional risk alignment workshops to help product owners understand the security posture of their applications.
Disseminate reports to inform decision makers about the cyber vulnerability position of the organization. Collaborate with external teams in the Financial and Critical Infrastructure sectors.
Maintain relationships with external partners who are involved in cyber planning or information sharing groups.
Provide subject-matter expertise and support to planning/developmental working groups as appropriate.
Construct vulnerability monitoring plans and matrices using established guidance and procedures.
Regularly audit and adapt the vulnerability monitoring cadence to proactively meet shifting organizational priorities and regulatory demands.
Gather and analyze feedback from internal stakeholders to continually improve the efficiency, accuracy, and actionability of vulnerability reporting.
Champion automation across the collection and processing pipelines to reduce alert fatigue.
Adjust the monitoring plan to address identified issues/challenges and to align with organizational requirements.
Proficiency in expressing technical discoveries through creation of reports, briefing notes that are both succinct and comprehensible.
Experience in advanced threat modeling frameworks (e.g., STRIDE, PASTA) expanded to account for systemic AI risks.
Advanced proficiency in threat infrastructure tools and analytic methodologies to chart complex threat campaigns.
Knowledge of enterprise IT networks, cybersecurity ecosystems, and roles and responsibilities.
Knowledge of common computer/network infections (virus, Trojan, etc.) and methods of infection (ports, attachments, etc.)
Knowledge of security capabilities and how those affect exploitation and reduce vulnerability.
Knowledge of criteria for evaluating collection products.
Knowledge of best practices for automation to support the collection and processing of large amounts of threat data/information.
Skilled in using multiple analytic tools, databases, and techniques (e.g., Analyst’s Notebook, A-Space, Anchory, M3, divergent/convergent thinking, link charts, matrices, etc.).
Skilled in writing, reviewing and editing cyber-related products.
Skilled at articulating a needs statement/requirement and integrating new and emerging collection capabilities, accesses and/or processes into the monitoring and reporting plan.
Skilled at preparing and delivering reports, presentations, and briefings, including the use of visual aids or presentation technology.
Skilled in identifying monitoring and reporting gaps.
Skilled in using critical thinking and an investigative mindset for research and analysis.
Demonstrates strong communication, team work, emotional intelligence and business acumen.
Strong curiosity and drive for solving problems.
| What you need to be successful
Requires a four (4) year degree, or a relevant two (2) year diploma or equivalent combined with two (2) years of additional experience.
Minimum of five (5) years’ experience in IT support, system administration, or security operations is considered good to have.
Minimum of three (3) years’ experience in vulnerability management.
Eligibility to obtain and maintain a Government of Canada Reliability Status Clearance and can successfully complete enhanced background checks that may be carried out by Payments Canada.
Ability to work outside of regular working hours based on operational requirements.
Willing to travel periodically to meet with external partners or attend industry events and conferences.
| You will really stand out with
Industry certification (CISSP, GCTI, CTIA) is considered an asset.
Experience as CTI Analyst, SOC Analyst, or Vulnerability Management Analyst is preferred and considered an asset.
| Salary range
Our target starting rate for this role is $ 100,300 with flexibility based on your experience and qualifications. The full salary range and benefits package are detailed below.
Please submit your application by September 18, 2026.
| What's in it for you?
Flexible, hybrid (remote/office) environment.
Competitive compensation package, including annual variable bonus and defined contribution pension plan with employer matching percentage (if eligible).
Comprehensive health and dental benefit coverage, including mental health coverage, life insurance and a health spending account for you and your dependents (Permanent and temporary employees with contracts 12 months and over).
Paid time off: minimum four weeks paid vacation, sick and personal days, December holiday shutdown and cultural holiday observance days.
26 weeks of paid maternity and parental leave top-up (if eligible)
Rewards and recognition program.
Access to office gym facilities.
Internal and external professional development opportunities.
Fun team and organizational events.
Monthly all staff forums led by our Executive Leadership Team .
| Our Commitment to Fair Hiring
At Payments Canada, we are dedicated to fair, transparent and inclusive hiring. We are an equal opportunity employer and value diversity at our company. Our recruitment process uses automated tools, but not generative AI, to objectively screen and evaluate applications and confirm that a candidate’s qualifications meet job requirements.
It is important to remember that these tools support, but do not replace, human decision-making. Our trained recruitment professionals and hiring managers always make the final hiring decisions.
| Our diversity, inclusion and equity commitment
At Payments Canada, we are committed to making everyone feel they can be themselves and thrive at work. We will continue to build on a foundation of respect and appreciation for diversity in all forms and collectively create an inclusive and equitable culture where our differences are valued.
We are committed to employment equity and actively encourage applications from women, Aboriginal people, persons with disabilities and visible minorities. If selected for an interview, please advise us if you require special accommodation by emailing hrinfo@payments.ca .
We thank all applicants for their interest in this opportunity. Preference will be given to Canadian citizens and permanent residents. Only selected candidates will be contacted for an interview.
Canadian nonprofit payment infrastructure operator serving financial institutions, businesses, governments, and consumers.
Visit company websiteJobs and hiring trendsCAD 88500-147500 yearly / year
Full-time
Senior · 3+ years experience
Hybrid
Apply faster on company sites with our extension.