Kitchener (ON), Canada
Senior IT Cyber Security Specialist
Senior IT Security Specialist
Location: Kitchener, Ontario (Hybrid)
Are you passionate about cybersecurity and reducing organizational risk through proactive vulnerability management? We are seeking a Senior IT Security Specialist, Vulnerability Operations to play a critical role in identifying, assessing, prioritizing, and managing vulnerabilities across Sonova's global technology environment.
This hands-on cybersecurity role is responsible for driving the vulnerability management lifecycle, partnering with technical and business stakeholders to ensure risks are effectively communicated, monitored, and remediated. You'll leverage automation, threat intelligence, and AI-assisted capabilities to strengthen Sonova's security posture and continuously improve vulnerability operations.
What You'll Do
- Lead vulnerability management activities, including scanning, analysis, risk assessment, reporting, and remediation tracking across enterprise environments.
- Partner with application owners, infrastructure teams, service providers, and security stakeholders to prioritize and address vulnerabilities based on business risk.
- Drive remediation efforts by coordinating patch management activities and supporting teams through critical vulnerability resolution.
- Utilize threat intelligence, exploitability data, and business context to prioritize security risks and improve decision-making.
- Leverage automation and AI-assisted tools to enhance vulnerability analysis, prioritization, and operational efficiency.
- Monitor and manage Sonova's external attack surface to identify emerging exposure risks and strengthen security defenses.
- Develop and deliver vulnerability management training and guidance to technical stakeholders and business partners.
- Create executive and operational reporting on vulnerability trends, risk exposure, remediation progress, and compliance status.
- Collaborate with internal and external partners to improve vulnerability management processes, technologies, and security practices.
- Support security investigations and compliance-related activities when required.
What You'll Bring
Education
- Degree in Computer Science, Information Technology, Cybersecurity, or a related field, or equivalent experience
One or more of the following certifications is preferred:
- GIAC (GCIH or similar), CISA, CompTIA Security+, Certified Ethical Hacker (CEH), CCNA, Comparable cybersecurity certifications
Experience
- Hands-on experience in vulnerability management, cybersecurity operations, or security risk management
- Experience working with vulnerability management tools such as Nessus, Qualys, or similar platforms
- Experience coordinating remediation efforts across multiple technical teams
- Familiarity with cloud environments, including IaaS, PaaS, and SaaS platforms
- Experience working with external vendors and managed security service providers
Technical Skills
- Strong understanding of vulnerability management frameworks and best practices
- Knowledge of security standards and frameworks, including OWASP, NIST, and CIS Benchmarks
- Solid understanding of networking concepts, including TCP/IP, DNS, VPNs, and related protocols
- Experience with Windows, Linux, Unix, and macOS environments
- Familiarity with web application security tools and vulnerabilities, including Burp Suite and OWASP ZAP
- Experience with patch management processes and platforms
- Proficiency with collaboration and workflow tools such as Jira, Confluence, Microsoft Teams, and Slack
Skills & Competencies
- Strong analytical and problem-solving abilities
- Ability to evaluate risk and communicate complex technical concepts to both technical and non-technical audiences
- Strong decision-making and prioritization skills
- Highly organized, detail-oriented, and process-driven
- Self-motivated with a continuous learning mindset
- Collaborative, service-oriented, and skilled at building trusted relationships
- Passion for continuous improvement and operational excellence
Language
- Strong written and verbal communication skills in English
A minimum of 200Mb/sec download and 10Mb/sec upload speed internet connectivity is required to support any remote/hybrid employee functionality at Sonova
Don't meet all the criteria? If you’re willing to go all in and learn we'd love to hear from you!
We are looking forward to receiving your application via our online job application platform. For this position only direct applications will be considered. Sonova does not recruit via app, telegram, carrier pigeon or any other format that does not include speaking with an actual human. If you are offered a job without speaking with someone please contact Sonova Human Resources
What we offer:
-
- Exciting and challenging work environment
- Collaborative culture
- Opportunities for continuous self-improvement
- Opportunities for flexible hybrid model work environment
- A company that values diversity and inclusion
- Rich benefits plan including wellness benefit, paramedical (massage therapist, naturopath, etc.) and competitive compensation including variable component and employer match on pension contributions
- Mentorship program and career development plans
*Plan rules/offerings dependent upon group Company/location.
This role's pay range is $124,000 – $150,000. This role is also bonus eligible.
Sonova Canada is now a certified Great Place to Work® May 2024- May 2025.