Jobs Companies CBC/Radio-Canada Lead Information Security Analyst, Vulnerability and External Attack Surface Management (T & I) (Telework/Hybrid)

Über diese Lead Information Security Analyst, Vulnerability and External Attack Surface Management (T & I) (Telework/Hybrid) Stelle bei CBC/Radio-Canada

CBC/Radio-Canada · Hybrid · Montreal, QC

Position Title:

Lead Information Security Analyst, Vulnerability and External Attack Surface Management (T & I) (Telework/Hybrid)

Status of Employment:

Permanent

Position Language Requirement:

English, French

Language Skills:

English (Reading - C - Advanced), English (Speaking - C - Advanced), English (Writing - B - Intermediate), French (Reading - C - Advanced), French (Speaking - C - Advanced), French (Writing - B - Intermediate)

Work at CBC/Radio-Canada

At CBC/Radio-Canada, we create content that informs, entertains and connects Canadians on multiple platforms. Our successes and accomplishments are driven by embodying and upholding values, which include creativity, integrity, inclusiveness and relevance. 
 
Do you think you have the ability and drive to keep up with this exciting, ever-changing industry? Whether it be in front of the camera, on air, online or behind the scenes, you would be joining a team that thrives on making connections and telling stories that are important to Canadians.

Unposting Date:

2026-09-29 11:59 PM

Behind the scenes, but ahead of the curve: help us develop the next-generation public service media organization.

Technology & Infrastructure (T&I) is the backbone and the future-forward arm of CBC/Radio-Canada. Our purpose is to constantly innovate to evolve and maintain the Corporation’s technology and infrastructure. We are the people that make stuff work. We make connections between media content, systems, people and places. We are the space in between.

A place with purpose. CBC/Radio-Canada has always been a highly regarded pioneer of media technology — not just in Canada but around the world. Today, we are transforming ourselves into a modern and agile public service media organization. Technology is the driving force, and we are the team making it happen.

This is a hybrid role with a mix of in-office and remote work. Work arrangements will be discussed with hiring managers per departmental guidelines.

Your Role


CBC/Radio-Canada is seeking a Lead Analyst, Vulnerability and External Attack Surface Management, to optimize the Corporation’s vulnerability management program and design, build and deploy its external attack surface management (EASM) service. 

In this role, you will take strategic and operational ownership of this domain. You will establish a comprehensive map of the Corporation’s external digital footprint — including internet-exposed assets, domains, certificates, cloud accounts, public APIs and exposed data — while driving continuous improvements to internal and hybrid vulnerability management. As a recognized subject matter expert, you will serve as a technical authority for leadership, maintain the vulnerability and exposure risk register, and adjudicate security exemption requests across the organization.

This position can be based in Montreal or Toronto.

What’s in It for You

Challenges. We spend our days solving problems of all kinds. Media files are highly nuanced and incredibly complicated; updating, installing and supporting technologies that are organization-wide and that impact broadcasting content is a time-sensitive, complex technical feat. And that’s just the beginning. You’ll be working with leading-edge data management, cloud, IP broadcasting, AI, security and reliability technologies.

As Lead Analyst, you will:

  • Map the digital footprint: Identify, classify and inventory CBC/Radio-Canada’s complete external attack surface for the first time, establishing the baseline for domain names, subdomains, public IP address ranges, exposed services, public cloud environments and APIs.
  • Implement continuous detection: Develop and execute procedures to detect inadvertently exposed services, expired or vulnerable certificates and leaked credentials or source code on the public web.
  • Lead the vulnerability life cycle: Define and optimize end-to-end processes for vulnerability detection, triage, impact analysis, prioritization, remediation and verification.
  • Define the scanning strategy: Establish the scope and frequency of automated and manual vulnerability scans across the entire IT environment.
  • Assess risk in context: Evaluate discovered vulnerabilities by cross-referencing CVSS scores with business context, asset criticality, existing compensating controls and active threat intelligence (e.g., known exploits).
  • Develop remediation plans: Recommend targeted corrective measures — such as patch management, system reconfigurations, temporary workarounds or WAF/firewall rules — for internal teams.
  • Lead zero-day response: Provide technical leadership during critical zero-day vulnerabilities and incidents (e.g., Log4j, major OS/hardware flaws), co-ordinating rapid detection and mitigation.
  • Evaluate and adjudicate security exemptions: Conduct in-depth technical reviews of exemption requests when prescribed patching or remediation timelines cannot be met. Assess residual risk based on exploitability and asset criticality, requiring robust compensating controls where necessary.
  • Manage the vulnerability risk register: Document, maintain and map unpatched vulnerabilities, security technical debt and approved exceptions in the Corporation's risk register. Monitor residual risk levels, update mitigation plans and present clear status reports to governance and executive committees to inform adjudication and investment decisions.
  • Partner on compliance and regulatory frameworks: Work closely with the policy and compliance lead to align vulnerability detection and remediation processes with regulatory requirements, internal policies and industry standards.
  • Develop metrics and dashboards: Define and track key performance indicators (KPIs) and key risk indicators (KRIs) to monitor program effectiveness.
  • Drive program evolution and threat intelligence: Continually enhance security tools and processes to address emerging threats (e.g., zero-day vulnerabilities). Monitor global vulnerability trends, proof-of-concept (PoC) exploits and evolving frameworks (e.g., CVSS v4, MITRE ATT&CK).
  • Maintain industry expertise: Stay current on information security best practices and industry trends.
     

What You Bring

  • University degree in computer science, IT or information security.
  • Minimum five years' experience in vulnerability management, risk assessment or IT governance, including at least three years in an information security role.
  • Extensive knowledge of security technology and risk assessment methodologies, policies and processes.
  • Excellent written and verbal communication skills, with a demonstrated ability to translate complex technical concepts for non-technical decision-makers (e.g., governance committees, business units, legal teams).
  • Excellent analytical, evaluative and problem-solving abilities.
  • Experience with compliance programs as well as their technical and security requirements.
  • Technical expertise across key domains:
    • Standards and Frameworks: Strong command of industry standards such as ISO/IEC 27001, 27002, 27005, NIST SP 800-53 / 800-161, COBIT and ITIL.
    • Cloud and Web Architecture Security: Solid understanding of web infrastructure and cloud environment security.
    • Network and Security Technologies: Thorough understanding of network architectures (LAN/WAN, routers), network security technologies (firewalls, IDS/IPS, DNS, web filtering) and cryptographic principles (encryption at rest and in transit).
    • Architecture and Data Security: Working knowledge of database architecture concepts and secure software development best practices.
    • Operational Resilience and Physical Security: Solid understanding of business continuity and disaster recovery planning (BCP/DRP), operational resilience and physical security controls.
  • Relevant professional security certifications a definite asset (e.g., CISSP, CRISC, CBCP, CISA, CISM or equivalent).
  • Bilingualism (English and French) essential.

Candidates may be subject to skills and knowledge testing.
 

We thank all applicants for their interest, but only candidates selected for an interview will be contacted.

As part of our recruitment process, candidates who advance to the next

step will be asked to complete a background check. This includes:  

  • A mandatory Criminal record check. 

  • Other background checks may be conducted based on the operational requirements of the position.


CBC/Radio-Canada is committed to being a leader in reflecting our country’s diversity. That’s because we can only create and tell the stories that connect Canadians, by having a workforce that mirrors the ever-changing makeup of our country. That’s why we, as an employer, value equal opportunity and nurture an inclusive workplace where our individual differences are not only recognized and valued, but also extend to and pervade all the services we provide as Canada’s public broadcaster. For more information, visit the Diversity and Inclusion section of our website. If you have accommodation needs at this stage of the recruitment process, please inform us as soon as possible by sending an e-mail to [email protected].
 
You are invited to consult and familiarize yourself with our Code of Conduct, which can be found on our corporate website. All employees must adhere to the Code as a condition of employment. We also invite you to take a look at our policy on conflicts of interest. In the event that you become an employee, it will be important to inform us, as quickly as possible, of any situation that, because of your hiring, constitutes or could appear to constitute a conflict of interest.

Primary Location:

1000, Rue Papineau, Montreal, Quebec, H2K 0C2

Number of Openings:

1

Work Schedule:

Full time
Bereit, sich bei CBC/Radio-Canada zu bewerben?
Bei CBC/Radio-Canada bewerben

Über CBC/Radio-Canada

At CBC/Radio-Canada , we create content that informs, entertains and connects Canadians on multiple platforms. Our successes and accomplishments are driven by embodying and upholding values, which include creativity, integrity, inclusiveness and relevance.

Alle Jobs bei CBC/Radio-Canada ansehen →

Ähnliche Jobs

CR
Lead Information Security Analyst, Third-Party Security and Data Breach Expert (T&I) (Telework/Hybrid)
CBC/Radio-Canada
⚡ Früh bewerben Montreal, QC Hybrid
● Neu 👁 Gesehen ✓ Beworben vor 5 Std.
CR
Lead Information Security Analyst, Continuous AI Risk Management Expert (T & I) (Telework/Hybrid)
CBC/Radio-Canada
⚡ Früh bewerben Montreal, QC Hybrid
● Neu 👁 Gesehen ✓ Beworben vor 1 Tg.
CR
Lead Information Security Analyst, Data Protection Specialist (T & I) (Telework/Hybrid)
CBC/Radio-Canada
⚡ Früh bewerben Montreal, QC Hybrid
● Neu 👁 Gesehen ✓ Beworben vor 1 Tg.
Mujininc
Cybersecurity Engineer
Mujininc
⚡ Früh bewerben Tokyo, Japan (MJHQ) Vor Ort
● Neu 👁 Gesehen ✓ Beworben vor 1 Std.
State Street
Cybersecurity Automation Engineer ,Assistant Vice President
State Street
⚡ Früh bewerben Kilkenny, Ireland Vor Ort
● Neu 👁 Gesehen ✓ Beworben vor 2 Std.
NA
Senior Analyst, Engineer - Group Security
NAB
⚡ Früh bewerben Tower A The Hallmark Building,... Vor Ort
● Neu 👁 Gesehen ✓ Beworben vor 2 Std.
Booz Allen Hamilton
Cybersecurity, Engineering, and Technology Implementation Support Engineer
Booz Allen Hamilton
⚡ Früh bewerben North Charleston, SC Vor Ort $86,800–$198,000
● Neu 👁 Gesehen ✓ Beworben vor 5 Std.
Bass Pro Shops
Cybersecurity Analyst- Onsite
Bass Pro Shops
⚡ Früh bewerben Springfield, MO (Bass Pro Shop... Vor Ort
● Neu 👁 Gesehen ✓ Beworben vor 5 Std.
Roblox
Senior Security GRC Analyst
Roblox
⚡ Früh bewerben San Mateo, CA, United States Vor Ort $209,250–$271,710
● Neu 👁 Gesehen ✓ Beworben vor 5 Std.

Registrieren für Vorschläge, die auf die von Ihnen geöffneten Jobs und gespeicherten Suchen zugeschnitten sind.

Mehr Jobs bei CBC/Radio-Canada

Alle Jobs bei CBC/Radio-Canada ansehen →

Jetzt bewerben
🤖

Moment — langsam

JobsRadar wurde für echte Menschen gebaut, die eine schwere Zeit bei der Jobsuche haben — nicht für automatisierte Anfragen. Sie klicken viel zu schnell und sind jetzt vorübergehend blockiert.

Kommen Sie später wieder. Wenn Sie wirklich auf Jobsuche sind, stehen wir hinter Ihnen — verhalten Sie sich einfach wie ein Mensch.

Catch your next role the second it’s posted.

Create a free account and we’ll watch the boards for you — the instant a job matches your search, it lands in your inbox or Telegram. No digging, no refreshing.

Create free account

Free forever · takes 30 seconds · already have one?

Verschaffe dir einen Vorsprung bei der Jobsuche.

Tritt unserem Telegram-Kanal bei für das, was dir hilft, die Stelle zu bekommen — Gehaltsbenchmarks, den wöchentlichen Marktpuls und neue Feature-Drops. Kein Spam, nur Signal.

Dem Kanal beitreten — kostenlos