Payments Canada is at the forefront of the Canadian payment ecosystem. Our purpose is to make payments easier, smarter and safer for all Canadians. Every day we are working diligently to ensure your payments are cleared and settled. In 2025 alone, our systems cleared approximately $103 trillion or $411.9 billion every business day! If you are passionate about payments and want to help ensure that these financial transactions in Canada are carried out safely and securely, working with us is for you!
| Who we are
We are a public purpose, non-profit organization situated at the center of Canada’s payment ecosystem. We own and operate payment systems that process hundreds of billions of dollars’ worth of payment transactions every business day. We convene ecosystem participants to discuss their multiple and diverse interests and ideas and to navigate industry-level challenges. We adhere to a set of values that are our north star:
Inspire trust, build community and enable change.
Payments Canada — where our country connects
| Our culture
With our people in mind, we have created a culture that fosters authenticity, collaboration, innovation and development. We empower one another, make meaningful contributions that not only impact the organization, but our country! We develop and nurture meaningful connections that drive innovation in our ecosystem. We are Payments Canada!
Do you want to make payments easier, smarter and safer for Canada? Join us today!
You need to work here if
- You love working with passionate, ambitious and collaborative colleagues.
- You want to be challenged and lead unique initiatives.
- You want to grow, develop and become a subject matter expert in your field.
- You want your work to make an impact in your community and country.
Come and join us — where payments meet purpose!
| What we are looking for
Reporting to the Director, Cyber Security & Operations, the Senior Analyst, Vulnerability Operations plays a vital, strategic role in safeguarding Payments Canada's modern infrastructure. The main responsibility of the Senior Analyst, Vulnerability Operations is to lead and mature the cyber vulnerability management program. This is not a siloed, backend technical role; it requires a highly personable technical leader who can translate complex vulnerability data (including CVEs, KEVs, and AI-specific exploits) into strategic business risks. The ideal candidate balances deep technical acumen with exceptional thought leadership to guide both internal teams and external financial sector partners.
The core mission of this role is to lead, scale, and mature our cyber vulnerability management program from traditional infrastructure monitoring to an agile framework capable of defending against threats in an AI world. Specifically, the incumbent will be responsible for managing vulnerabilities across applications, as well as on premise and cloud-based infrastructure.
Responsibilities of the position includes but is not limited to the following:
Research, Analysis & Thought Leadership
- Conduct in-depth vulnerability research and analysis.
- Produce timely, consolidated, multi-source vulnerability intelligence reports (e.g., vulnerability assessments, briefings,).
- Conduct deep-dive research into emerging vulnerability trends, specifically focusing on the intersection of cybersecurity and Frontier AI (e.g., adversarial machine learning, LLM vulnerabilities, and AI supply chain risks).
- Translate highly technical vulnerability findings into clear, risk-quantified business narratives for executive leadership and board-level consumption.
Vulnerability Management & Operations
- Monitor vulnerabilities through a variety of tools and sources and rank them according to relevance to Payments Canada.
- Collaborate with internal stakeholders to define vulnerability operations requirements.
- Own, design, and mature the end-to-end vulnerability management lifecycle, evaluating and optimizing SLAs for remediation across corporate and payment systems.
- Evolve traditional risk-ranking methodologies by combining CVE and KEV scores with real-world threat intelligence and AI-specific threat modeling (e.g., MITRE ATLAS).
- Establish automated workflows and monitoring plans to ingest, filter, and prioritize massive data streams of threat and vulnerability data efficiently.
- Report any imminent vulnerabilities to the organization in a timely manner.
- Coordinate the response, including reporting, on vulnerabilities to multiple levels of stakeholders.
Engagement with the Organization & External partners
- Provide cyber-focused guidance and vulnerability operations support to internal stakeholders.
- Facilitate regular, cross-functional risk alignment workshops to help product owners understand the security posture of their applications.
- Disseminate reports to inform decision makers about the cyber vulnerability position of the organization. Collaborate with external teams in the Financial and Critical Infrastructure sectors.
- Maintain relationships with external partners who are involved in cyber planning or information sharing groups.
- Provide subject-matter expertise and support to planning/developmental working groups as appropriate.
Continuous improvement of Security Practices & Processes
- Construct vulnerability monitoring plans and matrices using established guidance and procedures.
- Regularly audit and adapt the vulnerability monitoring cadence to proactively meet shifting organizational priorities and regulatory demands.
- Gather and analyze feedback from internal stakeholders to continually improve the efficiency, accuracy, and actionability of vulnerability reporting.
- Champion automation across the collection and processing pipelines to reduce alert fatigue.
- Adjust the monitoring plan to address identified issues/challenges and to align with organizational requirements.
Technical Competencies
- Proficiency in expressing technical discoveries through creation of reports, briefing notes that are both succinct and comprehensible.
- Experience in advanced threat modeling frameworks (e.g., STRIDE, PASTA) expanded to account for systemic AI risks.
- Advanced proficiency in threat infrastructure tools and analytic methodologies to chart complex threat campaigns.
- Knowledge of enterprise IT networks, cybersecurity ecosystems, and roles and responsibilities.
- Knowledge of common computer/network infections (virus, Trojan, etc.) and methods of infection (ports, attachments, etc.)
- Knowledge of security capabilities and how those affect exploitation and reduce vulnerability.
- Knowledge of criteria for evaluating collection products.
- Knowledge of best practices for automation to support the collection and processing of large amounts of threat data/information.
- Skilled in using multiple analytic tools, databases, and techniques (e.g., Analyst’s Notebook, A-Space, Anchory, M3, divergent/convergent thinking, link charts, matrices, etc.).
- Skilled in writing, reviewing and editing cyber-related products.
- Skilled at articulating a needs statement/requirement and integrating new and emerging collection capabilities, accesses and/or processes into the monitoring and reporting plan.
- Skilled at preparing and delivering reports, presentations, and briefings, including the use of visual aids or presentation technology.
- Skilled in identifying monitoring and reporting gaps.
- Proficiency in expressing technical discoveries through creation of reports, briefing notes that are both succinct and comprehensible.
Personal Competencies
- Skilled in using critical thinking and an investigative mindset for research and analysis.
- Demonstrates strong communication, team work, emotional intelligence and business acumen.
- Strong curiosity and drive for solving problems.
| What you need to be successful
- Requires a four (4) year degree, or a relevant two (2) year diploma or equivalent combined with two (2) years of additional experience.
- Minimum of five (5) years’ experience in IT support, system administration, or security operations is considered good to have.
- Minimum of three (3) years’ experience in vulnerability management.
- Eligibility to obtain and maintain a Government of Canada Reliability Status Clearance and can successfully complete enhanced background checks that may be carried out by Payments Canada.
- Ability to work outside of regular working hours based on operational requirements.
- Willing to travel periodically to meet with external partners or attend industry events and conferences.
| You will really stand out with
- Industry certification (CISSP, GCTI, CTIA) is considered an asset.
- Experience as CTI Analyst, SOC Analyst, or Vulnerability Management Analyst is preferred and considered an asset.
| Salary range
- Our target starting rate for this role is $100,300 with flexibility based on your experience and qualifications. The full salary range and benefits package are detailed below.
Please submit your application by September 18, 2026.
| What's in it for you?
- Flexible, hybrid (remote/office) environment.
- Competitive compensation package, including annual variable bonus and defined contribution pension plan with employer matching percentage (if eligible).
- Comprehensive health and dental benefit coverage, including mental health coverage, life insurance and a health spending account for you and your dependents (Permanent and temporary employees with contracts 12 months and over).
- Paid time off: minimum four weeks paid vacation, sick and personal days, December holiday shutdown and cultural holiday observance days.
- 26 weeks of paid maternity and parental leave top-up (if eligible)
- Rewards and recognition program.
- Access to office gym facilities.
- Internal and external professional development opportunities.
- Fun team and organizational events.
- Monthly all staff forums led by our Executive Leadership Team.
| Our Commitment to Fair Hiring
At Payments Canada, we are dedicated to fair, transparent and inclusive hiring. We are an equal opportunity employer and value diversity at our company. Our recruitment process uses automated tools, but not generative AI, to objectively screen and evaluate applications and confirm that a candidate’s qualifications meet job requirements.
It is important to remember that these tools support, but do not replace, human decision-making. Our trained recruitment professionals and hiring managers always make the final hiring decisions.
| Our diversity, inclusion and equity commitment
At Payments Canada, we are committed to making everyone feel they can be themselves and thrive at work. We will continue to build on a foundation of respect and appreciation for diversity in all forms and collectively create an inclusive and equitable culture where our differences are valued.
We are committed to employment equity and actively encourage applications from women, Aboriginal people, persons with disabilities and visible minorities. If selected for an interview, please advise us if you require special accommodation by emailing
[email protected].
We thank all applicants for their interest in this opportunity. Preference will be given to Canadian citizens and permanent residents. Only selected candidates will be contacted for an interview.