Enable job alerts via email!

Security Specialist Threat Risk Assessment 9054-0415

Foilcon

Toronto

Hybrid

CAD 70,000 - 110,000

Full time

23 days ago

Boost your interview chances

Create a job specific, tailored resume for higher success rate.

Job summary

An established industry player is seeking a Security Specialist to assess and mitigate risks within information systems. This hybrid role combines in-office collaboration with remote flexibility, allowing you to implement vital security measures and conduct thorough assessments. You will work closely with various teams to ensure compliance with security standards and protect sensitive information. The ideal candidate will possess strong analytical and problem-solving skills, alongside a deep understanding of security architecture. If you are passionate about safeguarding information and thrive in a dynamic environment, this opportunity is perfect for you.

Qualifications

  • Strong understanding of security architecture and methodologies.
  • Experience in conducting Threat Risk Assessments and security evaluations.

Responsibilities

  • Assess internal and external threats to information systems.
  • Implement security measures to mitigate security threats.
  • Review security measures to ensure effectiveness.

Skills

Security Architecture
Cyber Security Methodology
Threat Risk Assessment
Analytical Skills
Problem-Solving Skills
Communication Skills
Interpersonal Skills
Decision-Making Skills

Education

Relevant Degree in Information Technology or Security

Tools

Security Audit Procedures
Vulnerability Analysis Tools
Intrusion Detection Systems

Job description

Security Specialist Threat Risk Assessment 9054-0415

Join to apply for the Security Specialist Threat Risk Assessment 9054-0415 role at Foilcon

HM Note: This hybrid contract role is three (3) days in office. Candidates resume must include first and last name.

Description
Responsibilities:
  1. Assesses internal and external threats and vulnerabilities of information systems and resources and the likelihood of these threats and resulting impacts. Where possible, reduce risks through system or organizational design.
  2. Implement security measures to prevent or mitigate, detect and respond to security threats and vulnerabilities to information systems and resources at the program and enterprise levels.
  3. Periodically review security measures to ascertain that the security measures are still sufficient and continue to operate as expected.
  4. Defines, evaluates, and assesses security architecture requirements for systems environments and IT projects.
  5. Ensures the incorporation of IT security and contingency measures in the development of systems.
  6. Advises on the identification, analysis, and resolution of specific security factors, risks, vulnerabilities; protection of personal privacy issues; and appropriate industry and international security standards.
  7. Carry out information and information technology (I&IT) security projects and tasks in the Ontario Public Service as assigned by Corporate Security or cluster I&IT management.
General Skills
  1. Strong understanding and expertise in security architecture.
  2. Experience in the application of Cyber Security methodology and tools to define scope, critical business processes and functions, identify critical assets and dependencies in reports to clients (TRA or other security assessments).
  3. Experience and ability to plan and facilitate Threat Risk Assessment and/or other workshops with business clients.
  4. Experience and ability to apply Harmonized Threat Risk Assessment (HTRA) or equivalent methodology.
  5. Knowledge of techniques to secure information assets and the planning, design, and implementation of security technologies.
  6. Proven techniques to discover gaps or weaknesses in security architecture to identify and mitigate known security threats or inherent weaknesses.
  7. Knowledge and understanding of relevant legislation and corporate directives related to the security and confidentiality of information (e.g. Freedom of Information and Protection of Privacy Act) in order to identify and assess areas of concern and risk.
  8. Solid knowledge of current security and contingency technology and techniques (e.g. digital signature, encryption, access controls, fire-walls, authentication, virus protection, etc.); and a proven working knowledge of security audit procedures and protocols.
  9. Experience in developing enterprise architecture deliverables (e.g. models).
  10. Experience in providing specialized security support at the specified experience level.
  11. Experience in establishing secure environments at a network, operating system or application level.
  12. Experience with implementing security on complex and distributed systems.
  13. Experience in conducting in depth analysis and provide recommendations with all required sign-off in the prescribed timelines as given (TRA reports or other security assessment reports).
  14. Experience and knowledge to provide security requirements for procurement documents and participate in security evaluations as part of the procurement process.
  15. Ability to assess Information Security Risk, Business Continuity Planning and Business Impact Analysis technical issues for any of the technical environments and delivery channels across the Ontario Provincial Government including Mainframe, Unix and Windows.
  16. Awareness of emerging IT trends and directions, especially as related to security.
  17. Excellent analytical, problem-solving, and decision-making skills; written and verbal communication skills; interpersonal and negotiation skills.
  18. A team player with a track record for meeting deadlines, managing competing priorities and client relationship management experience.
Desirable Skills
  1. Experience in developing enterprise architecture deliverables (e.g. models) based on Ontario Government Enterprise Architecture processes and practice.
  2. Knowledge and understanding of Information Management principles, concepts, policies and practices.
  3. Experience in business recovery and disaster recovery planning.
  4. Experience in performing threat and risk assessment.
  5. Experience in public key infrastructure development and operation.
  6. Experience in security design as part of systems development projects.
  7. Experience in intrusion detection systems.
  8. Experience in mitigation tools for malicious software.
  9. Experience in vulnerability analysis and penetration testing.
  10. Experience in network monitoring.
  11. Experience in security policy development.
  12. Experience in developing and delivering security education.
  13. Experience in forensic investigation.
Skills
Experience and Skill Set Requirements
General: 30%
  1. Knowledge of, and experience with, business transformation, process improvement and change management.
  2. Excellent analytical, problem-solving, and decision-making skills.
  3. Excellent interpersonal, negotiation, and stakeholder-management skills.
  4. Ability to prioritize workload, demonstrate critical thinking, identify problems, develop and implement solutions.
  5. Strong customer service orientation to ensure needs of Clients are effectively met.
  6. Ability to work independently, meet deadlines, and manage stakeholder expectation.
  7. Ability to work well within teams and multi-task, along with a proven track record for meeting strict deadlines.
  8. Excellent written and oral communication skills, including group facilitation skills; experience in preparing reports, proposals, briefing materials, presentations, and other communications to all levels of the organization.
  9. Eligible to work in Ontario, Canada, and ability to obtain and maintain security clearances.
  10. Ability to handle and secure sensitive information, detailing the due-diligence around storage/modification of received documents, records retention policies, identity management, and other controls in-place used to protect OPS information.
  11. Ensure security background checks and due-diligence for their resources to ensure trustworthiness and integrity.
  12. Knowledge and experience with the security & IT policies/standards of the Ontario government (e.g. Standards, Policies, Directives).
  13. Experience with operational optimization in a unionized Public Sector environment.
  14. Knowledge of Public Sector structure and policies, including:
  15. Relevant public policy objectives, principles, and constraints.
  16. Organizational culture/unionized Public Sector environment.
  17. Application of relevant legislation and policies (e.g., Conflict of Interest, Freedom of Information and Protection of Privacy Act (FIPPA), etc.).
Experience: 30%
Demonstrated Experience Delivering The Following
  1. organization maturity risk assessments.
  2. industry standard risk assessments.
  3. cyber security health checks.
  4. strategic cyber maturity advice.
  5. security-by-design advice.
  6. Demonstrated Experience with the following phases of risk assessments.
  7. Scoping.
  8. Asset Classification.
  9. Threats.
  10. Vulnerabilities.
  11. Risks & Residual Risks post-mitigation responses.
  12. Demonstrated Experience conducting assessments on I&IT solutions against industry controls (e.g. NIST, ISF, ISO), GO-ITS standards and policies.
  13. Demonstrated Experience analysing technical documentation, conducting interviews to gather further/gap information, and to prepare a risk assessment, calculate qualitative risk values, and residual risk.
  14. Demonstrated Experience drafting and finalising executive risk reports.
Communication and Writing: 10%
  1. Strong communication skills to prepare documentation, including but not limited to; reports, reviews, assessments.
  2. Ability to present ideas and suggestions clearly and effectively and in a user friendly manner; maintain a high level of customer service to both internal and external clients.
  3. Ability to communicate designs and development in clear and understandable manner.
Must Have
Demonstrated Experience delivering the following:
  1. organization maturity risk assessments.
  2. industry standard risk assessments.
  3. cyber security health checks.
  4. strategic cyber maturity advice.
  5. security-by-design advice.
Demonstrated Experience conducting assessments on I&IT solutions against industry controls (e.g. NIST, ISF, ISO), GO-ITS standards and policies.
Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.

Similar jobs

Security Specialist Threat Risk Assessment 9054-0415

Dheya

Toronto

Hybrid

CAD 80,000 - 120,000

23 days ago