Cyber Security Consultant

HireOn Tech

Toronto

On-site

CAD 90,000 - 130,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

HireOn Tech is seeking a Threat Modeling, Cybersecurity professional in Toronto to assess security risks associated with application design and code. You will help govern threat modeling programs and security design practices across DevSecOps initiatives.

The role involves developing governance documentation, coordinating with information security leadership, and producing management reports on residual risk and controls effectiveness.

Qualifications

  • Experience with threat modeling frameworks (CAPEC, ATT&CK, STRIDE).
  • Experience with application security controls (Web, API, Mobile, AI).
  • Familiarity with information security management frameworks (NIST 800-53, CSF, OWASP ASVS).
  • Experience with DevSecOps and secure design patterns.

Responsibilities

  • Conduct security risk assessments of applications focusing on design and code.
  • Develop and manage threat modeling governance processes for security design & DevSecOps.

Skills

Threat modeling frameworks
Security controls & DevSecOps
Full stack knowledge
IAM (OAuth 2.0, OIDC, JWT)
Cloud security
Cryptography controls

Tools

NIST 800-53
OWASP ASVS
CSF

Job description

We are currently hiring for the following opportunity that may align with your expertise: please let me know if you are interested or open to the job market so you can reply over the same email or you can directly reach me at mohan@hireontech.com / 214 7719902.

Role - Threat Modeling, Cybersecurity
JD
Title: Threat Modeling, Cybersecurity
  • Conducts security risk assessments of applications with respect to design and implementation of system and application code.
  • Develop and manage security governance processes and procedures for the threat modeling program and application security design & DevSecOps programs.
  • Assist in the development of threat modeling governance documentation.
  • Works with information security leadership to develop strategies and plans to enforce threat modeling and address identified control gaps.
  • Develops reports for management concerning residual risk and non-compliance.
  • Monitor and track compliance with application owners to ensure implementation of security controls as planned.
  • Review issued security controls with application owners to ensure identified requirements are implemented.
  • Validate implementation of security controls against outputs of scanning tools to enable auditability and verifiability.
  • Assist application owners in filing appropriate security standard exceptions as identified through threat modeling.
  • Develop, Maintain, update and enhance secure design patterns and secure coding standards.
  • Develop, Maintain, update and enhance threat libraries.
  • Socialize secure design patterns and secure coding standards with engineering teams.
  • Assist application teams with threat modeling consultancy questions.
  • Consistently enable strong developer and customer experience when liaising with application teams. Uphold Blue Box values when liaising with application teams.
  • Develop innovative attack techniques to foil protective design and in-place mitigations.
  • Participate in the development of strategies for information security processes and programs.
  • Support the investment decision process by developing business cases and cost benefit analysis
  • Create reports and other materials to assist in prioritizing activities related to various threats to applications.
  • Recommend resource types and skillsets required to resolve project and process issues.
  • Document current and desired future state capabilities, incorporating industry leading technologies that enhance AXP's ability to manage IT risk and protect data
  • Provide ongoing awareness and education of industry efforts and statistics relevant to information security.
  • Develop and define IT and information security standardized metrics and criteria.
  • Facilitates improvement solutions by working with all levels across Technology to determine security technology solutions that align with business strategies, IT strategic directions and compliance obligations.
  • Facilitates Agile events that help the team deliver value incrementally and iteratively
  • Supports the Program Increment (PI) execution through facilitating team level events and partners with the RTE.
  • Supports the team in achieving the PI objectives.
  • Provides consultation and advice to assess information security risks and mitigate controls to protect corporate intellectual capital, and other sensitive data.
Preferred Qualifications:
  • Experience with threat modeling frameworks, attack vectors and vulnerability analysis: CAPEC, ATT&CK, STRIDE.
  • Experience with application security controls (Web, API, Mobile, AI).
  • Experience with common information security management and application frameworks: NIST 800-53, CSF, OWASP ASVS.
  • Experience with Application Security design and DevSecOps
  • Full stack knowledge of application architectures including Single Page Applications, REST APIs, SOAP APIs, Mobile Applications.
  • Knowledge or familiarity with database architectures including Oracle, SQL, DB2 and NoSQL Databases
  • Experience with Cloud security, architecture, design, implementation, and operations
  • Exposure to IAM Controls (OAuth 2.0, OIDC, JWT)
  • Strong familiarity with Cryptography Controls (Data at rest, in motion).
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Offensive Security Lead - Penetration Testing
Offensive Security Lead - Penetration Testing

RSM Canada • Canada

On-site
CAD 80,000 - 100,000
Cyber Security Analyst
Cyber Security Analyst

Arsenault • Ottawa

On-site
CAD 85,000 - 110,000
Senior Cybersecurity Test Architect
Senior Cybersecurity Test Architect

Myticas Consulting • Ottawa

On-site
CAD 120,000 - 160,000
Cyber Security Architect
Cyber Security Architect

Resonaite • Mississauga

On-site
CAD 100,000 - 130,000
Cybersecurity Solution Architect
Cybersecurity Solution Architect

Insight Global • Vancouver

On-site
CAD 90,000 - 120,000
Senior Security Analyst
Senior Security Analyst

Mindlance • Toronto

On-site
CAD 90,000 - 120,000
Analyst, Cybersecurity (Control Design)
Analyst, Cybersecurity (Control Design)

Dollarama • Mount Royal

On-site
CAD 100,000 - 150,000
Information Security Specialist – Attack Surface Reduction
Information Security Specialist – Attack Surface Reduction

Jobtailor • Toronto

On-site
CAD 120,000 - 160,000
Threat Modeling Cybersecurity Specialist
Threat Modeling Cybersecurity Specialist

HireOn Tech • Toronto

On-site
CAD 90,000 - 130,000
InfoRisk Managememt Analyst
InfoRisk Managememt Analyst

Dexian • Toronto

Remote
CAD 85,000 - 105,000