About the role
Pay Range: CAD 45-50/hr Role Summary We are looking for an Intermediate Infrastructure Vulnerability Management Analyst to support enterprise security operations by identifying, assessing, prioritizing, and driving remediation of vulnerabilities across infrastructure and applications. The role requires strong hands-on experience with vulnerability scanning tools (Qualys, Nessus, Rapid7), risk-based triage, and alignment with frameworks such as CVSS and threat intelligence (e.g., CISA KEV) to reduce organizational risk exposure.
Key Responsibilities Must Have: Ansible and Playbooks Vulnerability Management & Analysis • Execute the end-to-end vulnerability management lifecycle – discovery, analysis, triage, prioritization, and remediation tracking • Analyze vulnerability scan outputs from tools such as Qualys, Nessus, Rapid7 • Perform false positive validation and exception handling • Conduct vulnerability impact analysis across infrastructure, applications, and platforms Risk Assessment & Threat Prioritization • Perform risk-based vulnerability assessments using: o CVSS scoring and business impact o Threat context and exploitability insights • Use external threat intelligence sources (e.g., CISA Known Exploited Vulnerabilities – KEV) to prioritize remediation • Align remediation timelines based on risk severity and exposure Vulnerability Triage & Reporting • Perform detailed triage of vulnerabilities based on: o Severity, exploitability, asset criticality • Generate dashboards and reports on: o Vulnerability status o Risk posture o SLA adherence and remediation progress • Support audit readiness and compliance reporting Threat Modeling & Security Analysis • Participate in threat modeling exercises to identify potential attack vectors • Evaluate security risks within infrastructure and application ecosystems • Provide recommendations to strengthen system security posture Patch & Remediation Management • Coordinate and validate patch management for OS, middleware, and applications • Track remediation SLAs and ensure timely closure of vulnerabilities • Collaborate with infrastructure and application teams for remediation execution Stakeholder Collaboration • Work closely with: o Security teams o Infrastructure / server teams o Application owners • Communicate risk and remediation strategies clearly to both technical and business stakeholders
Required Skills & Experience Experience • 3–5 years of experience in: o Vulnerability Management / Security Operations o Infrastructure Security or IT Operations
Technical Skills • Hands-on experience with: o Qualys, Nessus, Rapid7 (or similar vulnerability tools) • Strong understanding of: o Vulnerability lifecycle (discovery → remediation → closure) o CVE / CVSS scoring models o Risk-based prioritization and threat analysis • Knowledge of: o Threat modeling concepts o CISA KEV / threat intelligence-based prioritization • Strong exposure to: o Patch management (OS, middleware, applications)
Preferred / Good-to-Have • Experience with: o ITSM tools (ServiceNow preferred) o Scripting (Python, PowerShell, Shell) o Security monitoring / SIEM tools • Knowledge of: o Compliance frameworks (ISO 27001, PCI-DSS, etc.) o Cloud environments (AWS, Azure, VMware)
Key Competencies • Strong analytical and problem-solving capabilities • Ability to interpret complex vulnerability data and translate into actionable remediation • Good communication skills for cross-team collaboration • Ability to manage multiple vulnerabilities in SLA-driven environments
Role Title Variants • Infrastructure Security Analyst – Vulnerability Management • Cyber Security Analyst – Vulnerability & Risk • Vulnerability Management Engineer (Intermediate)
About LanceSoft, Inc.
Established in 2000, LanceSoft is a pioneer in delivering top-notch Global Workforce Solutions and IT Services to a diverse clientele. As a Certified MBE and Woman-Owned organization, we pride ourselves on fostering global cross-cultural connections that advance both the careers of our employees and the success of our clients' businesses.
At LanceSoft, our mission is clear: to leverage our global network to seamlessly connect businesses with the right talent and individuals with the right opportunities, all without bias. We believe in providing Global Workforce Solutions with a personalized, human touch.
Our comprehensive range of services spans various domains, encompassing temporary and permanent staffing, Statement of Work (SOW) arrangements, payrolling, Recruitment Process Outsourcing (RPO), application design and development, program/project management, and engineering solutions.
Currently, our team of over 5,000 professionals caters to 110+ enterprise clients worldwide, including Fortune companies. Our client base represents a diverse spectrum of industries, including Banking & Financial Services, Semiconductor/VLSI, Technology, Healthcare & Life Sciences, Government, Telecom & Media, Retail & Distribution, Oil & Gas, and Energy & Utilities.
Headquartered in Herndon, VA, LanceSoft operates 32+ regional offices across the North America, Europe, Asia, and Australia. We also have nine delivery centers strategically located in India in Bangalore, Indore, Noida, Baroda, Hyderabad, Bhubaneshwar, Dehradun, Goa, and Aligarh to further enhance our client service capabilities.
Similar Jobs
About the role
Pay Range: CAD 45-50/hr Role Summary We are looking for an Intermediate Infrastructure Vulnerability Management Analyst to support enterprise security operations by identifying, assessing, prioritizing, and driving remediation of vulnerabilities across infrastructure and applications. The role requires strong hands-on experience with vulnerability scanning tools (Qualys, Nessus, Rapid7), risk-based triage, and alignment with frameworks such as CVSS and threat intelligence (e.g., CISA KEV) to reduce organizational risk exposure.
Key Responsibilities Must Have: Ansible and Playbooks Vulnerability Management & Analysis • Execute the end-to-end vulnerability management lifecycle – discovery, analysis, triage, prioritization, and remediation tracking • Analyze vulnerability scan outputs from tools such as Qualys, Nessus, Rapid7 • Perform false positive validation and exception handling • Conduct vulnerability impact analysis across infrastructure, applications, and platforms Risk Assessment & Threat Prioritization • Perform risk-based vulnerability assessments using: o CVSS scoring and business impact o Threat context and exploitability insights • Use external threat intelligence sources (e.g., CISA Known Exploited Vulnerabilities – KEV) to prioritize remediation • Align remediation timelines based on risk severity and exposure Vulnerability Triage & Reporting • Perform detailed triage of vulnerabilities based on: o Severity, exploitability, asset criticality • Generate dashboards and reports on: o Vulnerability status o Risk posture o SLA adherence and remediation progress • Support audit readiness and compliance reporting Threat Modeling & Security Analysis • Participate in threat modeling exercises to identify potential attack vectors • Evaluate security risks within infrastructure and application ecosystems • Provide recommendations to strengthen system security posture Patch & Remediation Management • Coordinate and validate patch management for OS, middleware, and applications • Track remediation SLAs and ensure timely closure of vulnerabilities • Collaborate with infrastructure and application teams for remediation execution Stakeholder Collaboration • Work closely with: o Security teams o Infrastructure / server teams o Application owners • Communicate risk and remediation strategies clearly to both technical and business stakeholders
Required Skills & Experience Experience • 3–5 years of experience in: o Vulnerability Management / Security Operations o Infrastructure Security or IT Operations
Technical Skills • Hands-on experience with: o Qualys, Nessus, Rapid7 (or similar vulnerability tools) • Strong understanding of: o Vulnerability lifecycle (discovery → remediation → closure) o CVE / CVSS scoring models o Risk-based prioritization and threat analysis • Knowledge of: o Threat modeling concepts o CISA KEV / threat intelligence-based prioritization • Strong exposure to: o Patch management (OS, middleware, applications)
Preferred / Good-to-Have • Experience with: o ITSM tools (ServiceNow preferred) o Scripting (Python, PowerShell, Shell) o Security monitoring / SIEM tools • Knowledge of: o Compliance frameworks (ISO 27001, PCI-DSS, etc.) o Cloud environments (AWS, Azure, VMware)
Key Competencies • Strong analytical and problem-solving capabilities • Ability to interpret complex vulnerability data and translate into actionable remediation • Good communication skills for cross-team collaboration • Ability to manage multiple vulnerabilities in SLA-driven environments
Role Title Variants • Infrastructure Security Analyst – Vulnerability Management • Cyber Security Analyst – Vulnerability & Risk • Vulnerability Management Engineer (Intermediate)
About LanceSoft, Inc.
Established in 2000, LanceSoft is a pioneer in delivering top-notch Global Workforce Solutions and IT Services to a diverse clientele. As a Certified MBE and Woman-Owned organization, we pride ourselves on fostering global cross-cultural connections that advance both the careers of our employees and the success of our clients' businesses.
At LanceSoft, our mission is clear: to leverage our global network to seamlessly connect businesses with the right talent and individuals with the right opportunities, all without bias. We believe in providing Global Workforce Solutions with a personalized, human touch.
Our comprehensive range of services spans various domains, encompassing temporary and permanent staffing, Statement of Work (SOW) arrangements, payrolling, Recruitment Process Outsourcing (RPO), application design and development, program/project management, and engineering solutions.
Currently, our team of over 5,000 professionals caters to 110+ enterprise clients worldwide, including Fortune companies. Our client base represents a diverse spectrum of industries, including Banking & Financial Services, Semiconductor/VLSI, Technology, Healthcare & Life Sciences, Government, Telecom & Media, Retail & Distribution, Oil & Gas, and Energy & Utilities.
Headquartered in Herndon, VA, LanceSoft operates 32+ regional offices across the North America, Europe, Asia, and Australia. We also have nine delivery centers strategically located in India in Bangalore, Indore, Noida, Baroda, Hyderabad, Bhubaneshwar, Dehradun, Goa, and Aligarh to further enhance our client service capabilities.