Morningstar logo
Senior Analyst, Vulnerability Management
full-timeToronto$90k - $132k

Summary

Location

Toronto

Salary

$90k - $132k

Type

full-time

Claim this Company

Are you the employer? Manage your company page directly.

Explore Jobs

About this role

About the Role

We are looking for a colleague to join our Remediation Operations team. The role is responsible for analyzing data collected from various cybersecurity defense tools to mitigate risks and partner with relevant stakeholders to support remediation operations.

Job Responsibilities

  • Analyze technical vulnerabilities to determine the real impact to Morningstar systems. Review security vulnerabilities across a variety of technologies and environments to determine high risk vulnerabilities to business assets.

  • Provides technical vulnerability analysis and remediation options.

  • Staff the Enterprise-wide vulnerability management program, collaborating with partners to coach and support remediation operations while providing technical guidance and tracking resolution progress.

  • Give real, actionable remediation advice above and beyond what the tools and testers provide.

  • Create reports related to vulnerability management KPIs.

  • Generate detailed security reports and metrics to communicate risk status and remediation progress to key stakeholders.

  • Assist with documenting and regularly reviewing relevant processes and procedures.

  • Train, mentor and guide junior colleagues.

Qualifications

  • A bachelor’s degree in computer science or related field.

  • Previous experience in information security (3+ years), with a minimum of 1 year in vulnerability management area.

  • Knowledge of risk management processes.

  • Previous experience with vulnerability assessment tools and techniques, vulnerability data sources, system threats and vulnerabilities.

  • Basic understanding of attacker tactics, techniques, and procedures.

  • Ability to understand code and configuration as it relates to security vulnerabilities.

  • Capability to recognize and categorize types of vulnerabilities.

  • Understanding of enterprise-scale infrastructure, technologies, and applications, both on-premises and in the public cloud.

  • Strong communication skills.

  • Ability to teach, influence, and adapt as new information becomes available.

  • Enthusiasm to learn and gain hands-on experience across different security domains.

  • Commitment to working as part of team to deliver a significant and measurable impact on security vulnerability risk.

Nice to have

  • Knowledge of encryption algorithms, tools and techniques.

  • Knowledge of programming language structures and logic.

  • Understanding of cybersecurity laws and regulations, models and frameworks.

  • Experience with cyber defense and hardening tools and techniques.

  • Previous experience in penetration testing tools, principles and practices.

Base Salary Compensation Range

$90,489.00-132,711.00

Incentive Target Percentage

12.5% Annual

Morningstar's hybrid work environment gives you the opportunity to collaborate in-person each week as we've found that we're at our best when we're purposely together on a regular basis. In most of our locations, our hybrid work model is four days in-office each week. A range of other benefits are also available to enhance flexibility as needs change. No matter where you are, you'll have tools and resources to engage meaningfully with your global colleagues.

100_MstarResCanad Morningstar Research, Inc. (Canada) Legal Entity

Other facts

Tech stack
Vulnerability Analysis,Risk Mitigation,Remediation Operations,Technical Vulnerability Analysis,Security Vulnerabilities Review,Vulnerability Management Program,Actionable Remediation Advice,KPI Reporting,Security Reporting,Process Documentation,Mentoring,Risk Management Processes,Vulnerability Assessment Tools,Attacker Tactics Techniques and Procedures,Code Understanding,Enterprise Infrastructure Understanding

About Morningstar

Morningstar, Inc. is a leading provider of independent investment insights in North America, Europe, Australia, and Asia. The Company offers an extensive line of products and services for individual investors, financial advisors, asset managers and owners, retirement plan providers and sponsors, institutional
investors in the debt and private capital markets, and alliances and redistributors. Morningstar provides data and research insights on a wide range of investment offerings, including managed investment products, publicly listed companies, private capital markets, debt securities, and real-time global market data. Morningstar also offers investment management services through its investment advisory subsidiaries, with approximately $369 billion in AUMA as of Sept. 30, 2025. The Company operates through wholly-owned subsidiaries in 32 countries.

Team size: 10,001+ employees
LinkedIn: Visit
Industry: Financial Services

What you'll do

  • The role involves analyzing data from cybersecurity defense tools to mitigate risks and partnering with stakeholders to support remediation operations. Responsibilities include analyzing technical vulnerabilities, providing remediation options, and staffing the enterprise-wide vulnerability management program.

Join Clera's Talent Pool

Get matched with similar opportunities at top startups

This role is hosted on Morningstar's careers site.
Join our talent pool first to get notified about similar roles that match your profile.

Frequently Asked Questions

What does Morningstar pay for a Senior Analyst, Vulnerability Management?

Morningstar offers a competitive compensation package for the Senior Analyst, Vulnerability Management role. The salary range is USD 90k - 133k per year. Apply through Clera to learn more about the full compensation details.

What does a Senior Analyst, Vulnerability Management do at Morningstar?

As a Senior Analyst, Vulnerability Management at Morningstar, you will: the role involves analyzing data from cybersecurity defense tools to mitigate risks and partnering with stakeholders to support remediation operations. Responsibilities include analyzing technical vulnerabilities, providing remediation options, and staffing the enterprise-wide vulnerability management program..

Why join Morningstar as a Senior Analyst, Vulnerability Management?

Morningstar is a leading Financial Services company. The Senior Analyst, Vulnerability Management role offers competitive compensation.

Is the Senior Analyst, Vulnerability Management position at Morningstar remote?

The Senior Analyst, Vulnerability Management position at Morningstar is based in Toronto, Canada. Contact the company through Clera for specific work arrangement details.

How do I apply for the Senior Analyst, Vulnerability Management position at Morningstar?

You can apply for the Senior Analyst, Vulnerability Management position at Morningstar directly through Clera. Click the "Apply Now" button above to start your application. Clera's AI-powered platform will help match your profile with this opportunity and guide you through the application process. You can also learn more about Morningstar on their website.