This would be an excellent opportunity for the right infosec person; I’ve heard good things about them from a family member

#fedihired

https://connexuscu.wd1.myworkdayjobs.com/en-US/ConnexusCareers/job/Remote/Vulnerability-Management-Analyst_JR1609

Vulnerability Management Analyst

Connexus Credit Union - Who We Are: Serving members across all 50 states, Connexus Credit Union is a member-focused cooperative that is proud to return profits to member-owners through high yields for checking accounts and deposit products, as well as competitive rates on our loans. We are a remote first employer with the majority of our employees residing in the upper Midwest. As an employer we foster collaboration and high performance to achieve excellence. We holistically care for and develop our employees to thrive personally and professionally. We are proud to share our success with our employees and those we serve. Connexus offers an Amazing Benefits package: 25 days of paid time off and 10 paid holidays 16 hours of paid Volunteer Time Off 401K Retirement with up to 6% employer match Excellent Health, Dental, Vision insurance, including multiple plan options Health Savings Account with generous employer contributions Employer paid Life insurance, Short-Term and Long-Term Disability Tuition Reimbursement from $4,000 - $7,000 per calendar year Robust Learning and Development program that includes an annual professional development stipend Responsibilities: Conduct regular vulnerability scanning of networks, servers, endpoints, cloud environments, and applications using approved tools. Analyze scan results to identify false positives, determine exploitability, and assess business and regulatory risk. Prioritize vulnerabilities based on CVSS scores, threat intelligence, asset criticality, and financial institution risk impact. Track vulnerabilities through remediation, validation, and closure using ticketing or governance platforms. Perform re-scans to validate remediation effectiveness. Ensure vulnerability management practices align with: FFIEC Cybersecurity Assessment Tool (CAT) NCUA or banking regulatory guidance GLBA Safeguards Rule Internal Information Security and Risk Management policies Prepare documentation, metrics, and evidence for internal audits, regulatory exams, and third-party assessments. Support risk acceptance decisions by documenting compensating controls and residual risk. Partner with IT infrastructure, application development, cloud, and network teams to remediate identified risks. Translate technical vulnerabilities into clear business risk language for leadership and non-technical stakeholders. Provide guidance on secure configuration, patching, and vulnerability mitigation strategies. Participate in security incident response activities when vulnerabilities are exploited or pose imminent risk. Monitor emerging threats, zero-day vulnerabilities, and industry advisories relevant to financial services. Contribute to vulnerability management policies, standards, and procedures. Assist with penetration testing coordination and result analysis. Collect, organize, and maintain security control evidence and artifacts for monthly continuous monitoring deliverables and assessment/authorization activities, ensuring alignment with required frameworks. Maintain accurate system inventory and authorization boundary documentation to ensure scanning scope aligns with approved system boundaries. Analyze scan results for false positives, document justifications, and prepare deviation requests with supporting risk assessments. Participate in change management processes to ensure continuous monitoring activities align with system changes and maintain compliance posture. Support and maintain enterprise vulnerability management tools (such as Tenable, Nessus, Burp, Qualys, Rapid7, Wiz, Prisma, Microsoft Defender), ensuring timely updates and patches. Run regular and on-demand scans across operating systems, databases, web applications, and containers, then work with technical teams to create tickets for remediation. Track and document vendor dependencies, operational requirements, and open vulnerabilities, producing clear monthly reports and updates. Contribute to improving internal standards and processes, including maintaining documentation, training materials, and standard operating procedures. Run the daily vulnerability management program operations, work closely with the patch management analyst in identifying and patching vulnerabilities, and actively participate in weekly vulnerability management team meetings. Comply with all Federal Regulations as they pertain to your job duties, including BSA. Position Requirements: This position is Remote. Bachelor's degree or commensurate experience is Required. 3+ years professional work experience in vulnerability management, security operations, or IT risk within a regulated environment is Required. Hands-on experience with vulnerability scanning tools, such as: Tenable (Nessus, Tenable.io), Qualys, Rapid7 or similar platforms is Required. Prior financial industry regulations and frameworks (FFIEC, NCUA, GLBA, NIST) is Required. Strong knowledge of vulnerability scanning technologies and methods, including scoring systems (CVSS, CMSS) and risk prioritization frameworks is Required. Global Information Assurance Certification (GIAC), GIAC Security Essentials Certification (GSEC) or Enterprise Vulnerability Assessor Certification (GEVA) is Required. Connexus Credit Union's Employer Recognitions: 2026 Best Place to Work in IT, Computer World Equal Opportunity Employer/Disabled/Veterans/41 CFR 60–1.4, 41 CFR 60-1.35 Let’s face it – everything has changed: where we do our work, how we communicate and collaborate, what we expect of our employer. Connexus Credit Union embraces that change and is continually designing new ways to put our people first. We invite you to be part of a fast-growing, dynamic work environment built for balance, growth, and job satisfaction. A career with Connexus Credit Union means access to exceptional benefits. Check out our Candidate Information Guide to see the ways we support you. Candidate Information Guide Connexus requires that remote employees must reside in one of the following states to be considered for any of our remote positions: FL, IL, IN, IA, MI, MN, MO, OH, TX, WI.

I find myself at a point where I'm encountering irreconcilable differences between my moral, ethical, and technical objections to the use of LLMs, and my employer's leadership's desire to force the use of LLMs into every aspect of day to day operations. As a result, I find myself #OpenToWork .

I have decades of experience in the #SysAdmin / #SRE / #DevOps / #CICD / #CloudComputing range of skills. Currently acting as a subject matter expert on #Kubernetes , #Terraform , and #Observability . Mostly supporting #GCP platforms these days, but I am comfortable pivoting to other #cloud platforms like #AWS or even #OnPrem . Can do #ProjectManagement and #TeamLeadership. Experienced in #DevSecOps and #FedRAMP processes.

I would strongly prefer to deal with no LLM tooling at all, but will settle for having to use it less than in the current environment.

Location: #Canada (remote), #WaterlooRegion (Ontario) (hybrid).

#FediHire #FediHired #GetFediHired

@arichtman Have I mentioned I'm looking to get #FediHired? Seriously, though, I'm actually close to my breaking point. My physical and mental health are suffering, I'm sleeping poorly, my temper is way too short, and I'm just this close from walking away from it with nothing else lined up.

@Typozon

You should add the hashtag #fedihired to this as people use it for looking for and posting jobs.

One day, the Gen AI bubble will burst and tech companies will hire highly experienced human beings with impressive bodies of work to do research and writing about cybersecurity. (We will probably need to deal with all the tech debt and vulns from slop code.)

Until then, I need to pay my rent.

Please share. ❤️ #fediHire #Fedihired #infosec

https://zeroes.ca/@kimcrawley/116285004344640581

Please boost! Please share! #fedihire #fedihired #jobs #infosec #noai

I am Kim Crawley and I research and write about all areas of cybersecurity. I do it the "old fashioned" way by actually using my brain and doing the work... No Gen AI! Fuck Gen AI! I hate Gen AI! I founded Stop Gen AI!

I've worked for:

- Siemens (Digital Industries World)
- BlackBerry Cylance
- Kaspersky
- Hack The Box
- O'Reilly Media
- Wiley Tech
- AT&T Cybersecurity

My portfolio is here: https://kimcrawley.com

- Whitepapers
- Blogs
- Documentation
- Books
- Threat analysis
- Enterprise cybersecurity instruction and consulting

I'm in Tribe of Hackers.

I cowrote The Pentester Blueprint.

I'm writing Technofascism Survival Guide now, successful Kickstarter is still taking late pledges for $12 USD eBooks: https://www.kickstarter.com/projects/kimcrawley/technofascism-survival-guide

Email me: kim(dot)crawley(at)stopgenai.com

Signal: crowgirl.84

Or reply here.

Canadian job leads, I'm not affiliated with any of these companies:

Sonova is hiring a WordPress Technical Platform Owner in Kitchener, Ontario. "The WordPress Technical Platform Owner provides technical leadership for Sonova’s WordPress platform and website portfolio, ensuring strong architecture, performance, security, and scalability. This role serves as the technical owner of the platform, working closely with internal teams and external vendors to deliver high-quality, reliable web solutions aligned with business needs." No salary range listed. Apply at https://jobs.sonova.com/job/Kitchener-%28ON%29-WordPress-Technical-Platform-Owner-ON/1376162133/.

Postmedia is hiring a senior PHP/WordPress developer remote within Toronto, Ontario. "The Senior PHP/WordPress Developer is a high-impact technical role responsible for the architecture, development, and stability of our enterprise-scale WordPress VIP (WPVIP) ecosystem." Salary range is $85,000 - $95,000. More details and apply at https://jobs.dayforcehcm.com/en-CA/postmedia/PostmediaCareers/jobs/8885.

CGS Immersive is hiring for two different roles in Saint John. Backend developer, and Frontend developer. Salary range not listed. See these open roles and other jobs they are hiring for at https://cgsimmersive.com/careers.

Halifax Public Libraries is hiring a Manager, Research & Process Improvement in Dartmouth, NS. "The Manager, Research & Process Improvement is responsible for the provision of data and analytics expertise, services, metrics, and tracking frameworks. The Manager, Research & Process Improvement works together with Managers across all districts, Senior Leadership, and the regional and district teams to support planning and evaluation of library services and programs, with a focus on supporting data-driven decision making and evaluation of library services and programs." Salary range is $87,890.14 - $102,819.04. Job details at https://sjobs.brassring.com/TGnewUI/Search/Home/Home?partnerid=25749&siteid=5762#jobDetails=769794_5762.

Marketbridge has three openings that are for those who are eligible to work in Canada without visa sponsorship. Those openings are Marketing Account Supervisor, Director - Global Content Strategy, and Manager - SEO. Salary range is listed at the bottom of each job description. See these openings (might be best to not search for the exact title I have listed here) at https://marketbridge.com/careers/.

#WPJobs #WPCareers #WordPressJobs #CanadaJobs #CanadianJobs #DevJobs #WebDevJobs #WordPress #FediHired #GetFediHired #hiring #RemoteJobs #FediJobs #ITJobs #JobAlert #TechJobs #ToJobs #TorontoJobs #CalgaryJobs #WinnipegJobs #RemoteWork #FediHire #Job #Jobs #JobOpenings #OpenRoles

WordPress Technical Platform Owner

WordPress Technical Platform Owner

Well, the axe finally dropped and I’m looking for work. I’d like to get #fedihired!

I’m a full stack web developer that backed his way into coding full time. I’ve led small teams and been the sole dev on several projects. I’ve got 7 years experience with Angular/.NET/PLSQL.

If you know anyone that might be interested in someone with strong organizational skills, and the ability to pick up new languages quickly, hit me up.

I'm looking for full-time work!

I work at the intersection of social and technical systems, and specialize in building up people, programs, partnerships, and organizations around open source.

I have a deep track record in complex community relations, am fluent in the nuts and bolts of many technologies, and have spanned governance, org development, nonprofit and people management, comms, marketing, events, and beyond.

Let's fly! 

#FediHired #GetFediHired #OpenSource #FOSS

Are you based in #Australia?
Work with #Indigenous #Languages?
Want to shepherd the nation's work with the International Decade of Indigenous Languages?

Now hiring: #EO role

https://idil-australia.au/resources/we-are-hiring

#FediHired
#GetFediHired

IDIL Australia 2022-2032 - We are Hiring

IDIL Australia leads the national response to the International Decade of Indigenous Languages (2022–2032), supporting Aboriginal and Torres Strait Islander communities to protect, revitalise and celebrate First Languages across Australia.

IDIL Australia 2022-2032