Senior Specialist, IT Vulnerability Management
Job Requisition ID: 12038
Position Status: Permanent Full Time
Position Type: Hybrid
Office Location: Ottawa (ON); Montreal (QC); Toronto (ON)
Travel Requirement: Limited
Language Designation: English Essential
Language Skill Levels (Read/Write/Speak): ZZZ
Security Requirement: Secret
Salary: Our salaries generally range from $ 104,180.28 to $ 130,225.36 and are based on qualifications and experience.
About CMHC
The work you do and the work we do together matters. We come to work every day with a common purpose: to contribute to a well-functioning housing system.
At CMHC, we hold ourselves accountable for our results and support our colleagues in their achievements. We thrive on collaboration, connecting across CMHC and involving the right people to get our work done. Our leadership style is guided by trust, where our leaders favour an adaptive approach based on the needs of their teams.
Join us and be part of a team that's committed to making a real difference and be part of something meaningful.
What’s in it for you
We’ve got the purpose, the people and the perks you need for a fulfilling career. Here’s the comprehensive and generous benefits you get when you’re a permanent employee:
- Annual Paid vacation.
- Annual individual performance incentive.
- Defined benefit pension plan.
- Comprehensive group insurance plan to support your well-being from day one.
- Support towards your personal and professional growth with training, mentorship and more.
- An inclusive workplace culture and environment.
- While positions at CMHC require some in-office presence, alternative work arrangements may be considered for Indigenous candidates.
About the role
Join the IT Security Operations Team in the Senior Specialist, IT Vulnerability Management position. In this role you will be responsible for designing, governing, and continuously improving the enterprise Vulnerability Management program. You will ensure that technology vulnerabilities are identified, prioritized, communicated, and remediate in alignment with the organization’s risk tolerance, security strategy, and regulatory obligations. The role provides expert-level advisory services to senior management and ensures that vulnerability risks are effectively managed across infrastructure, applications, cloud, and third-party environments.
What you’ll do:
- Own the enterprise Vulnerability Management strategy, framework, standards, and operating model.
- Define vulnerability risk scoring, prioritization, and exception handling aligned with enterprise risk management practices.
- Ensure vulnerability management practices align with recognized frameworks (e.g., ISO 27001/27002, NIST, ITSG‑33).
- Maintain accountability for the effectiveness and outcomes of vulnerability management services, including third‑party providers.
- Translate technical vulnerability findings into clear, business‑relevant risk insights for senior leadership.
- Advise on vulnerability risk acceptance, remediation prioritization, compensating controls, and security implications of new technologies and architectures.
- Define, track, and report on vulnerability management KPIs and KRIs, including executive‑ and board‑level reporting on exposure, trends, and remediation effectiveness.
- Lead and collaborate across security, IT, application, and infrastructure teams; mentor specialists and engage with vendors, auditors, and regulators as required.
What you should have:
- A bachelor’s degree in information technology, Cybersecurity, or a related field. An equivalent combination of education and/or experience may be considered.
- An advanced security certification is required (e.g., CISSP, CISM, or equivalent).
- A minimum of 7 to 10 years of progressive experience in information security, including vulnerability management or risk management.
- Demonstrated experience advising senior leadership and influencing enterprise-level decisions.
- Experience designing and governing security programs.
Posting closing date: Note, the competition will remain active until filled.
Standby and Call Back duties are a requirement of this position and will be subject to CMHC policies, including the Standby and Call Back Pay Procedure.
Our commitment to diversity, equity, and inclusion
We’re committed to employment equity and encourage women, Indigenous Peoples, persons with disabilities, veterans and persons of all races, ethnicities, religions, abilities, sexual orientations, and gender identities and expressions to apply. We also welcome applications from non-Canadians who are eligible to work in Canada.
CMHC is an inclusive workplace where diversity of thought – and of people – are recognized, valued, and considered essential to achieving our mission.
Learn more about our commitment to diversity and inclusion
What happens after you apply
We know that applying for a new job can be both exciting and daunting, and we appreciate your effort. Learn more about our hiring process. If you are selected for an interview or testing, please advise us if you require an accommodation.
If you applied before and you were not successful don’t worry – we're always posting new positions, so don’t hesitate to give it another shot. We’re excited to see what you bring to the table this time around!