Location: Ottawa, ON (On-site)
Duration: 39 weeks
Security Clearance: Secret
Responsibilities
- Plan, design, configure, integrate, test, and deploy the Tenable Nessus vulnerability scanning capability into production, and provide in-service support.
- Design, configure, integrate, implement, and maintain or upgrade Tenable Nessus services and components across unclassified and classified networks.
- Deploy and support Tenable Nessus components, including the Tenable Core Virtual Appliance (Oracle Linux), Security Center, Nessus Agent Manager, active scanners, Nessus Network Monitor, and Windows and Linux agents.
- Investigate, analyze, and provide verbal and written recommendations on Tenable Nessus capabilities, modules, configuration options, architecture, upgrades, and feature enhancements.
- Draft Requests for Change (RFCs) and provide input and advice on RFCs related to the deployment and configuration of Tenable Nessus.
- Draft and contribute input and advice to Security Assessment and Authorization (SA&A) documentation related to the deployment and configuration of Tenable Nessus.
- Review, modify, and create technical implementation documentation and diagrams, including interconnectivity with other services and tools.
- Identify and recommend integrations between Tenable Nessus and other services using vendor integration modules, native APIs, or custom scripting, including SIEM, SCCM, and Elasticsearch, Logstash, and Kibana.
- Examine and implement opportunities to automate Tenable Nessus tasks, data replication, and vulnerability management workflows across classified networks.
- Identify and report risks to Tenable Nessus instances, components, and scanning data arising from vendor updates and upgrades, infrastructure changes, supply chain vulnerabilities, and cyber threats.
- Review, design, and develop engineering process documentation, including solution architectures, build and configuration documents, test plans, standard operating procedures, and implementation plans.
- Develop and deliver training and awareness materials relevant to Tenable Nessus vulnerability assessment capabilities, and participate in stakeholder meetings, working groups, and teleconferences.
Qualifications
- 6+ years of combined training and progressive hands-on experience in cybersecurity and vulnerability management, including significant experience with Tenable Nessus platforms within an enterprise vulnerability management program.
- Experience deploying, configuring, maintaining, and optimizing vulnerability scanning infrastructure, including developing and tuning scan policies to enhance scan accuracy and coverage.
- Ability to independently conduct advanced vulnerability analysis using CVSS scoring and risk-based prioritization methodologies, perform root cause analysis, and provide detailed remediation guidance across network, endpoint, and cloud environments.
- Experience supporting the full vulnerability management lifecycle, including scanning, analysis, remediation, validation, and reporting, and contributing to incident response activities through the effective use of vulnerability data.
- 6+ years of combined training and progressive hands-on experience in the analysis of complex cybersecurity issues, including designing and improving vulnerability management solutions and providing expert-level technical advice within enterprise security environments.
- Experience investigating and resolving complex, non-standard security vulnerabilities and system issues, and translating vulnerability findings into actionable, risk-based remediation plans aligned with recognized security frameworks and standards, such as NIST, DoD, and FedRAMP.
- Experience designing, enhancing, and optimizing vulnerability management processes, scanning strategies, and tool configurations to improve detection coverage, reduce false positives, and increase overall scan fidelity.
- Experience collaborating with security operations, infrastructure, and application teams to coordinate and drive remediation efforts.
- Experience providing technical mentoring and guidance to junior analysts and engineers, while maintaining current knowledge of emerging threats, vulnerabilities, attack techniques, and evolving cybersecurity best practices.
AI Disclosure: We do not use artificial intelligence (AI) tools to screen, assess, or select applicants at any stage of our recruitment process. All applications are reviewed by our recruitment team.
OXARO is committed to fostering an inclusive, equitable and respectful workplace where every individual feels valued and empowered to contribute their best. We believe that diversity drives innovation and strengthens our ability to serve our clients and communities. We are dedicated to ensuring a fair and unbiased recruitment process and welcome applications from members of the four designated groups under the Employment Equity Act: women, Indigenous peoples, persons with disabilities and members of visible minorities.
Accommodations are available upon request for candidates taking part in all aspects of the recruitment process.
We sincerely thank all applicants for their interest in this opportunity. While we appreciate every application, only those selected for an interview will be contacted.