Morningstar Logo

Morningstar

Senior Analyst, Vulnerability Management

Posted 3 Days Ago
Be an Early Applicant
Hybrid
Toronto, ON
90K-133K Annually
Mid level
Hybrid
Toronto, ON
90K-133K Annually
Mid level
The role involves analyzing cybersecurity vulnerabilities, providing remediation strategies, creating reports, mentoring junior staff, and collaborating on risk management.
The summary above was generated by AI
About the Role
We are looking for a colleague to join our Remediation Operations team. The role is responsible for analyzing data collected from various cybersecurity defense tools to mitigate risks and partner with relevant stakeholders to support remediation operations.
Job Responsibilities
  • Analyze technical vulnerabilities to determine the real impact to Morningstar systems. Review security vulnerabilities across a variety of technologies and environments to determine high risk vulnerabilities to business assets.
  • Provides technical vulnerability analysis and remediation options.
  • Staff the Enterprise-wide vulnerability management program, collaborating with partners to coach and support remediation operations while providing technical guidance and tracking resolution progress.
  • Give real, actionable remediation advice above and beyond what the tools and testers provide.
  • Create reports related to vulnerability management KPIs.
  • Generate detailed security reports and metrics to communicate risk status and remediation progress to key stakeholders.
  • Assist with documenting and regularly reviewing relevant processes and procedures.
  • Train, mentor and guide junior colleagues.

Qualifications
  • A bachelor's degree in computer science or related field.
  • Previous experience in information security (3+ years), with a minimum of 1 year in vulnerability management area.
  • Knowledge of risk management processes.
  • Previous experience with vulnerability assessment tools and techniques, vulnerability data sources, system threats and vulnerabilities.
  • Basic understanding of attacker tactics, techniques, and procedures.
  • Ability to understand code and configuration as it relates to security vulnerabilities.
  • Capability to recognize and categorize types of vulnerabilities.
  • Understanding of enterprise-scale infrastructure, technologies, and applications, both on-premises and in the public cloud.
  • Strong communication skills.
  • Ability to teach, influence, and adapt as new information becomes available.
  • Enthusiasm to learn and gain hands-on experience across different security domains.
  • Commitment to working as part of team to deliver a significant and measurable impact on security vulnerability risk.

Nice to have
  • Knowledge of encryption algorithms, tools and techniques.
  • Knowledge of programming language structures and logic.
  • Understanding of cybersecurity laws and regulations, models and frameworks.
  • Experience with cyber defense and hardening tools and techniques.
  • Previous experience in penetration testing tools, principles and practices.

Base Salary Compensation Range
$90,489.00-132,711.00
Incentive Target Percentage
12.5% Annual
Morningstar's hybrid work environment gives you the opportunity to collaborate in-person each week as we've found that we're at our best when we're purposely together on a regular basis. In most of our locations, our hybrid work model is four days in-office each week. A range of other benefits are also available to enhance flexibility as needs change. No matter where you are, you'll have tools and resources to engage meaningfully with your global colleagues.
100_MstarResCanad Morningstar Research, Inc. (Canada) Legal Entity

Top Skills

Cybersecurity Tools
Encryption Algorithms
Programming Languages
Vulnerability Assessment Tools

Similar Jobs at Morningstar

2 Days Ago
Hybrid
Toronto, ON, CAN
90K-133K Annually
Senior level
90K-133K Annually
Senior level
Enterprise Web • Fintech • Financial Services
Develop and maintain web applications, collaborate on features, write efficient code, troubleshoot issues, and deploy in AWS.
Top Skills: AWSCSSHTMLJavaScriptNode.jsNuxt.JsTypescriptVue
3 Days Ago
Hybrid
Toronto, ON, CAN
72K-105K Annually
Mid level
72K-105K Annually
Mid level
Enterprise Web • Fintech • Financial Services
The role involves full stack development, collaborating in cross-functional teams, and managing cloud infrastructure, focusing on user experience and code quality.
Top Skills: AngularAWSCi/CdDockerElasticsearchEs6+GitJavaScriptMssqlMySQLNode.jsPostgresPythonSQLVue
6 Days Ago
Hybrid
Toronto, ON, CAN
113K-162K Annually
Expert/Leader
113K-162K Annually
Expert/Leader
Enterprise Web • Fintech • Financial Services
The Principal Software Engineer will lead the Toronto engineering team, mentoring engineers and overseeing core architectural decisions for full-stack JavaScript applications.
Top Skills: AWSJavaScriptNode.jsNuxt 3Restful ApisTypescriptViteVueWebpack

What you need to know about the Los Angeles Tech Scene

Los Angeles is a global leader in entertainment, so it’s no surprise that many of the biggest players in streaming, digital media and game development call the city home. But the city boasts plenty of non-entertainment innovation as well, with tech companies spanning verticals like AI, fintech, e-commerce and biotech. With major universities like Caltech, UCLA, USC and the nearby UC Irvine, the city has a steady supply of top-flight tech and engineering talent — not counting the graduates flocking to Los Angeles from across the world to enjoy its beaches, culture and year-round temperate climate.

Key Facts About Los Angeles Tech

  • Number of Tech Workers: 375,800; 5.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Snap, Netflix, SpaceX, Disney, Google
  • Key Industries: Artificial intelligence, adtech, media, software, game development
  • Funding Landscape: $11.6 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Strong Ventures, Fifth Wall, Upfront Ventures, Mucker Capital, Kittyhawk Ventures
  • Research Centers and Universities: California Institute of Technology, UCLA, University of Southern California, UC Irvine, Pepperdine, California Institute for Immunology and Immunotherapy, Center for Quantum Science and Engineering

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account