About this role
Job Title: Vulnerability Management Engineer Job Description We are seeking a hands-on Software Supply Chain Security Engineer specializing in vulnerability management to identify, investigate, prioritize, and remediate security issues across software products and the development environment. In this role, you go beyond generating security scan reports by deeply analyzing findings from security scanning and AI-assisted tools, determining whether vulnerabilities represent legitimate risks or false positives, and partnering with engineering and security teams to drive practical remediation strategies. You will work directly with scanning tools, source code, software dependencies, and development teams, independently investigating complex findings, tuning tool configurations, and ensuring vulnerabilities are resolved effectively. This position offers the opportunity to help secure software behind advanced AI, cloud, and networking technologies while growing your expertise in DevSecOps and software supply chain security. Responsibilities
- Review and analyze vulnerabilities identified by software composition analysis, static analysis, dependency scanning, and other security tools.
- Investigate findings beyond the initial scan output to determine exploitability, severity, business impact, and remediation priority.
- Distinguish legitimate vulnerabilities from false positives, duplicate findings, and issues that are not applicable to the product environment.
- Identify the source and technical cause of vulnerabilities within application code, open-source components, dependencies, or build configurations.
- Partner with software development, security, DevOps, and product teams to develop and implement effective remediation plans.
- Participate directly in vulnerability remediation, including updating dependencies, modifying configurations, recommending code changes, or identifying compensating controls.
- Interpret detailed security reports and translate technical findings into clear, actionable recommendations for technical and non-technical stakeholders.
- Configure and tune security scanning tools to improve detection quality, reduce false positives, and align with the organizations security requirements.
- Track and manage a high volume of vulnerabilities through investigation, prioritization, remediation, validation, and closure.
- Help integrate security scanning and vulnerability management practices into development and CI/CD workflows.
- Evaluate findings generated by AI-assisted security tools and validate their accuracy and relevance.
- Document technical findings, remediation decisions, risk assessments, and accepted exceptions in a clear and organized manner.
- Collaborate across security, software development, DevOps, and product teams while maintaining the ability to work independently on complex issues.
Essential Skills
- 5+ years of experience in DevSecOps or software security, with a focus on vulnerability analysis and remediation.
- Hands-on experience with security scanning and analysis tools, including Black Duck or similar software composition analysis tools.
- Strong programming experience with at least one of Python, C, C++, or Go for investigating and remediating vulnerabilities in code and dependencies.
- Practical experience with software supply chain security, including open-source dependencies, SBOMs, SPDX, or CycloneDX.
- Familiarity with CVE, CWE, CVSS, exploitability analysis, and risk-based vulnerability prioritization.
- Experience integrating security scanning into CI/CD pipelines using tools such as GitHub Actions, GitLab CI, Jenkins, Azure DevOps, or similar platforms.
- Ability to configure and tune security tools, troubleshoot scan results, and systematically reduce false positives.
- Knowledge of Linux environments, build systems, package managers, and dependency management in modern software development.
- Experience upgrading, replacing, or patching vulnerable software components in complex software ecosystems.
- Strong organization, documentation, and communication skills to clearly articulate findings and remediation plans.
- Ability to work independently while effectively collaborating with security, software development, DevOps, and product teams.
Additional Skills & Qualifications
- Experience with software supply chain security practices and tools, including SBOM generation and management using standards such as SPDX or CycloneDX.
- Exposure to AI-assisted security scanning, code analysis, or vulnerability remediation tools and workflows.
- Familiarity with embedded software, firmware, C/C++, or systems-level development is an asset.
- Understanding of software build systems and CI/CD pipelines, including configuration, automation, and integration of security checks.
- Knowledge of common vulnerability databases and frameworks, including CVE, CWE, and CVSS, and the ability to apply them in risk assessments.
- Experience in DevSecOps practices, including integrating security into development and operations processes.
- Experience working with software composition analysis, static analysis, and dependency scanning tools to manage open-source and third-party risk.
- Ability to interpret complex technical security reports and translate them into clear, actionable recommendations.
- Comfort working with modern cloud, networking, and AI-related technologies from a security and vulnerability management perspective.
Job Type & Location
This is a Contract position based out of Ottawa, ON.
Pay and Benefits
The pay range for this position is $60.00 - $80.00/hr. Individual compensation offered for this position within this range will depend on many factors, including qualifications, skills, relevant experience, job knowledge, geographic location, internal equity, and other pertinent job-related factors.
Workplace Type
This is a fully onsite position in Ottawa,ON.
À propos d'Actalent
Actalent est un leader mondial dans les services dingénierie et de sciences ainsi que dans les solutions de talents. Nous aidons des entreprises visionnaires à faire progresser leurs initiatives dingénierie et de science grâce à laccès à des experts spécialisés qui favorisent léchelle, linnovation et la rapidité de mise sur le marché. Avec un réseau de près de 20 000 consultants et 5 000 clients à travers les États-Unis, le Canada, lAsie et lEurope, Actalent dessert de nombreuses entreprises du Fortune 500. Nous sommes fiers dêtre lune des 500 meilleures firmes de conception de lEngineering News-Record (ENR) pour nos services de conception en ingénierie et un lauréat du prix ClearlyRated Best of Staffing® tant pour le service client que pour les talents.
Actalent est un employeur souscrivant au principe de légalité des chances et accepte toutes les candidatures sans tenir compte de la race, du sexe, de lâge, de la couleur, de la religion, des origines nationales, du statut dancien combattant, dun handicap, de lorientation sexuelle, de lidentité sexuelle, des renseignements génétiques ou de toute autre caractéristique protégée par la loi.
Si vous souhaitez faire une demande daccommodement raisonnable, tel que la modification ou lajustement du processus de demande demploi ou dentrevue à cause dun handicap, veuillez envoyer un courriel à [email protected] pour connaître dautres options daccommodement.
Ordonnance sur légalité des chances de San Francisco:
Conformément à lOrdonnance sur légalité des chances de San Francisco, pour tous les postes situés dans la ville et le comté de San Francisco, nous examinerons les candidatures des personnes qualifiées ayant un casier judiciaire ou des antécédents criminels.
Utilisation de lintelligence artificielle (IA):
Nous pouvons utiliser lintelligence artificielle (IA) pour soutenir certaines étapes de notre processus dembauche, notamment la recherche, la présélection et lévaluation des candidatures. LIA aide à analyser les candidatures et les qualifications, mais les décisions finales sont prises par notre équipe de recrutement. En soumettant votre candidature, vous reconnaissez et acceptez que celle-ci puisse être examinée à laide doutils dIA.
About Actalent
Actalent is a global leader in engineering and sciences services and talent solutions. We help visionary companies advance their engineering and science initiatives through access to specialized experts who drive scale, innovation and speed to market. With a network of almost 20,000 consultants and 5,000 clients across the U.S., Canada, Asia and Europe, Actalent serves many of the Fortune 500. We are proud to be an Engineering News-Record (ENR) Top 500 Design Firm for our engineering design services and a ClearlyRated Best of Staffing® winner for both client and talent service.
The company is an equal opportunity employer and will consider all applications without regard to race, sex, age, color, religion, national origin, veteran status, disability, sexual orientation, gender identity, genetic information or any characteristic protected by law.
If you would like to request a reasonable accommodation, such as the modification or adjustment of the job application process or interviewing process due to a disability, please email [email protected] for other accommodation options.
San Francisco Fair Chance Ordinance: Pursuant to the San Francisco Fair Chance Ordinance, for all positions located in the city and county of San Francisco, we will consider for employment qualified applicants with arrest and conviction records.
Use of Artificial Intelligence (AI): We may use Artificial Intelligence (AI) to support parts of our hiring process, including sourcing, screening, and evaluating candidates. AI helps assess applications and qualifications, but final decisions are made by our hiring team. By applying, you acknowledge and agree that your application may be reviewed using AI tools.