Sr. Engineer - Vulnerability Management
Manage the end-to-end vulnerability management lifecycle across enterprise infrastructure, cloud environments, and networks. Drive automation for remediation workflows and collaborate with cross-functional teams to ensure security SLAs are met.
- Hybrid
- Toronto, ON
- Posted Aug 6, 2026
- Apply by Sep 5, 2026
- 1 position
Job summary
OnX is a leading Canadian technology solutions provider helping organizations modernize, secure, and optimize their IT environments. We partner with clients across industries to deliver innovative infrastructure, cloud, security, and managed services solutions that drive business success. We are seeking a highly skilled Sr. Engineer - Vulnerability Management to join our growing Cybersecurity team. In this role, you will be responsible for identifying, assessing, prioritizing, and driving remediation of security vulnerabilities across enterprise infrastructure, applications, cloud environments, and networks. You will play a critical role in strengthening the organization's security posture by leading vulnerability lifecycle management, automating remediation processes, and partnering across infrastructure, cloud, platform engineering, and application teams. What You'll Do Manage the end-to-end vulnerability management lifecycle, including identification, assessment, prioritization, remediation validation, and reporting. Perform vulnerability assessments across operating systems, applications, cloud platforms, containers, and network environments. Operate and optimize vulnerability scanning tools and security assessment frameworks. Drive automation initiatives using Python and PowerShell to improve remediation workflows and reporting. Analyze threat intelligence, exploit data, CVSS scores, and emerging vulnerabilities to support risk-based prioritization. Collaborate with Infrastructure, Cloud, Platform Engineering, DevSecOps, SOC, and Application teams to ensure remediation SLAs are achieved. Support security incidents by evaluating vulnerability impact, exploitability, and contributing to root cause analysis. Manage vulnerability exceptions, false-positive handling, and risk acceptance processes. Create executive-level reports and dashboards highlighting exposure trends and remediation progress. Required Skills & Experience Technical Skills Qualys VMDR Microsoft Defender Vulnerability Management Nessus Rapid7 Linux Administration Windows Administration Python Scripting PowerShell Scripting Vulnerability Assessment & Management Security Automation Cybersecurity Expertise Cloud Security Application Security Network & Endpoint Security Security Operations Threat Detection & Incident Response Identity & Access Management (IAM) Data Protection & Encryption Vulnerability Remediation Programs Risk-Based Vulnerability Prioritization Preferred Certifications Certified Ethical Hacker (CEH) Additional cybersecurity certifications such as Security+, CISSP, GIAC, or cloud security certifications are a plus. Qualifications Bachelor's degree in Computer Science, Information Technology, Engineering, Telecommunications, or a related technical field. 6-8 years of overall IT/Security experience. Minimum 5+ years of hands-on experience in Vulnerability Management and Security Operations. Strong understanding of enterprise infrastructure, cloud security, DevSecOps, and remediation practices. What Makes You Successful Strong analytical and problem-solving skills. Excellent collaboration and communication abilities. Ownership mindset with strong attention to detail. Ability to work cross-functionally with technical and business stakeholders. Passion for cybersecurity, automation, and continuous improvement. Why Join OnX? Work with modern infrastructure and cloud technologies. Collaborate with experienced technology professionals across Canada. Gain exposure to enterprise-scale environments and strategic initiatives. Competitive compensation and benefits package. Professional development and certification support. Flexible work options depending on role requirements. CAD $72,000 – $96,000 base salary (not including bonus or commission) “The compensation range in this posting reflects the Company’s good‑faith estimate at the time of publication. The applicable base pay range for any individual will be determined based on the candidate’s designated primary work location as well as factors including role scope and responsibilities, required qualifications, and the individual’s experience, education, skills, knowledge, and performance. Certain positions may also be eligible for additional compensation such as discretionary merit increases, bonuses, or sales‑based variable compensation in accordance with applicable plans and role requirements. Diversity & Inclusion OnX is an equal opportunity employer committed to creating an inclusive environment for all employees. We celebrate diversity and are dedicated to fostering a workplace where everyone can thrive regardless of race, religion, gender, age, disability, sexual orientation, or any other protected characteristic.
What you’ll do
Manage the end-to-end vulnerability management lifecycle across enterprise infrastructure, cloud environments, and networks. Drive automation for remediation workflows and collaborate with cross-functional teams to ensure security SLAs are met.
Requirements
Requires a Bachelor's degree and 6-8 years of IT/Security experience, with at least 5 years specifically in Vulnerability Management. Proficiency in scanning tools like Qualys or Nessus and scripting languages like Python and PowerShell is essential.
Benefits
• Competitive compensation • Bonus • Commission • Professional development • Certification support • Flexible work options
Other relevant skills
Identified from the job description. Confirm important requirements above.
- Qualys VMDR
- Microsoft Defender Vulnerability Management
- Nessus
- Rapid7
- Linux Administration
- Windows Administration
- Python Scripting
- PowerShell Scripting
- Vulnerability Assessment
- Security Automation
- Cloud Security
- Application Security
- Network Security
- Endpoint Security
- Threat Detection
- Incident Response
Job areas
- Security & Safety
- Technology
- Software
- Engineering
- Consulting
Additional details
- Minimum education
- Bachelor’s degree
- Minimum experience
- 5+ years
- Apply by
- Sep 5, 2026
- Posting language
- English
- Working hours
- 40 hours per week
- Seniority
- Mid-Senior level
