Enable job alerts via email!

Threat, Risk Assessment and Pentest Advisor

NexGedia Enterprise

Halifax

Remote

CAD 90,000 - 120,000

Full time

Yesterday
Be an early applicant

Boost your interview chances

Create a job specific, tailored resume for higher success rate.

Job summary

A leading company is seeking a Threat, Risk Assessment and Pentest Advisor for a major initiative in Halifax. The role involves ensuring cybersecurity best practices, facilitating workshops, and conducting thorough risk assessments. Candidates should have extensive experience in cybersecurity and risk management, with strong documentation skills and familiarity with NIST controls.

Qualifications

  • 3+ years managing large initiatives and facilitating security assessments.
  • 8+ years IT-related experience in cybersecurity, risk management, and infrastructure.
  • Familiarity with ISO/IEC 27001:2013 ISMS framework.

Responsibilities

  • Ensure alignment with corporate Cybersecurity best practices.
  • Plan and facilitate workshops for threat assessment.
  • Notify application owners of critical cybersecurity risks.

Skills

Cybersecurity and Risk Management assessment methodologies
Strong writing skills
Intrusion and penetration testing
NIST Recommended Security Controls

Job description

Role: Threat, Risk Assessment and Pentest Advisor

Start date: June 12, 2024

End date: March 31, 2025

Duration: 1,567.50 billable hours

Location of Work (Address or City, Province): Halifax, NS

Remote Work be considered? Yes

Description

One of our clients is looking for a Threat, Risk Assessment and Pentest Advisor to work on a major initiative.

Responsibilities
  • Ensure alignment with corporate Cybersecurity best practices and guidelines.
  • Plan, coordinate, organize and facilitate workshops to identify and assess threats, vulnerabilities, and controls against service assets.
  • Participate in workshops to elicit, document, and prioritize related tasks and projects.
  • Review and analyze results from other available and relevant Threat and Risk Assessments (TRAs) or security scans, conducted as part of the TRA deliverable.
  • The TRA vendor determines if the specific control found within the ‘GNS TRA NIST Checklist’, relative to the specific control baseline, is satisfactory. If not satisfactory, it is documented as a risk within the TRA template.
  • Immediately notify application owner(s) of any identified critical cybersecurity risk against any digital service as soon as identified during the TRA.
Knowledge and Experience
  • Must have up-to-date familiarity and experience with NIST Recommended Security Controls for Federal Information Systems and Organizations (800-53 - version 5) in conducting or participating in assessing digital services.
  • Must have three or more (3+) years of experience managing large initiatives, facilitating groups, gaining consensus, and engaging stakeholders in security assessments.
  • Experience conducting TRAs for large-scale organizations with at least 3000 employees.
  • Minimum of 8 years of IT-related experience within one or more of the following fields:
The Following Fields
  • Cybersecurity and Risk Management assessment methodologies
  • IT Infrastructure/Networks
  • Identity, Credential and Access Management
  • Application Design/Development/Testing
  • Enterprise Architecture
  • Privacy
  • Telecommunications
  • SaaS, IaaS, and PaaS Digital Service Delivery Models
  • Experience with ISO/IEC 27001:2013 ISMS framework
  • Experience performing intrusion and penetration testing
  • Strong writing skills to produce accurate and comprehensive documentation
  • The Penetration Tester will use industry best-practice methodologies and tools to identify, analyze, evaluate, and document Penetration Testing risks.
  • Review and analyze results from other relevant Penetration Tests or security scans.
  • Identify the specific PNS function responsible for remediation.
Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.