Senior Manager Vulnerability and Threat Assessment – Global Security
Company | Royal Bank of Canada |
---|---|
Location | Toronto, ON, Canada |
Salary | $Not Provided – $Not Provided |
Type | Full-Time |
Degrees | Bachelor’s |
Experience Level | Senior, Expert or higher |
Requirements
- Proven Expertise in Vulnerability Management: Demonstrated experience in owning and evolving vulnerability prioritization frameworks and external attack surface management strategies. Hands-on experience with vulnerability scanning tools (e.g., Tenable, Qualys, Rapid7, CrowdStrike).
- Strong Leadership and Project Management Skills: Proven ability to lead and deliver complex projects, including planning, execution, and stakeholder management. Experience managing and mentoring teams to achieve high performance.
- Deep Knowledge of Information Security: Strong understanding of security frameworks, governance practices, and vulnerability assessment methodologies. Working knowledge of developer tools, environments, and CI/CD architectures.
- Exceptional Communication and Collaboration Skills: Ability to effectively communicate complex technical concepts to diverse audiences, including senior leadership. Strong consultancy, facilitation, negotiation, and presentation skills.
- Passion for Cybersecurity: A relentless curiosity and enthusiasm for staying ahead of the curve in the ever-changing world of cybersecurity.
Responsibilities
- Own and Evolve the Vulnerability Prioritization Framework: Lead the design, implementation, and continuous improvement of a robust vulnerability prioritization framework that ensures the most critical risks are addressed first. Develop and maintain metrics to measure the effectiveness of the framework and communicate its impact to stakeholders.
- Drive External Attack Surface Management: Oversee the identification, monitoring, and mitigation of risks associated with the organization’s external attack surface. Collaborate with cross-functional teams to ensure visibility and remediation of vulnerabilities across internet-facing assets.
- Lead and Manage Strategic Projects: Spearhead vulnerability management initiatives, ensuring alignment with organizational goals and industry best practices. Manage end-to-end project lifecycles, from planning and execution to delivery, while ensuring timelines and objectives are met.
- Be a Subject Matter Expert in Vulnerability Management: Provide expert guidance on vulnerability assessment concepts, tools, and methodologies, including hands-on experience with industry-leading tools like Tenable, Qualys, Rapid7, and CrowdStrike. Stay ahead of emerging threats and trends, continuously refining strategies to address the evolving threat landscape.
- Collaborate and Influence Across Teams: Partner with diverse stakeholders, including technology teams, suppliers, and leadership, to drive vulnerability management initiatives. Act as a trusted advisor, providing clear and actionable insights to support decision-making.
- Promote a Culture of Excellence: Lead, motivate, and inspire the team to achieve high performance while fostering a culture of inclusivity, innovation, and continuous improvement.
Preferred Qualifications
- Bachelor’s degree in computer science, IT, or a related discipline.
- Cybersecurity certifications (e.g., CISSP, CCSP, CISM, CRISC, GCIH).
- Experience with cloud security concepts and tools (e.g., Aqua Security, Prisma, Wiz, Snyk).
- Knowledge of Lean Six Sigma principles.
- Hands-on experience with JIRA, Confluence, Mural, and/or Lucidchart.