Enable job alerts via email!

Senior Security Threat Risk Assessment Specialist

Creative Solutions Services, LLC

Old Toronto

Hybrid

CAD 60,000 - 80,000

Full time

30+ days ago

Boost your interview chances

Create a job specific, tailored resume for higher success rate.

Job summary

An established industry player seeks a Senior Security Threat Risk Assessment Specialist to enhance their security posture. This role involves assessing vulnerabilities, implementing robust security measures, and ensuring compliance with industry standards. You will work closely with various stakeholders to identify risks and develop strategies to mitigate them. The ideal candidate will have extensive experience in security architecture and risk management, along with excellent communication skills to convey complex information clearly. Join a forward-thinking company that values innovation and collaboration, and make a significant impact on their security initiatives.

Qualifications

  • 5+ years of experience in information security risk management.
  • Proven track record in security architecture and risk assessment.

Responsibilities

  • Assess and mitigate internal and external threats to information systems.
  • Implement security measures and conduct periodic reviews.

Skills

Security Architecture
Cyber Security Methodology
Threat Risk Assessment
Vulnerability Analysis
Network Security
Incident Response
Disaster Recovery Planning
Analytical Skills
Communication Skills
Problem-solving Skills

Education

Bachelor's Degree in Information Security or related field
Certifications in Cyber Security (e.g., CISSP, CISM)

Tools

Cybersecurity Tools
Risk Management Frameworks
Security Audit Procedures

Job description

Senior Security Threat Risk Assessment Specialist

Contract Duration: 6 Months

Pay range: C$750 to $800/day

Hybrid: Required to come to the office upon request (once every two weeks).

Job Responsibilities:
  1. Assess internal and external threats and vulnerabilities of information systems and resources and the likelihood of these threats and resulting impacts.
  2. Where possible, reduce risks through system or organizational design.
  3. Implement security measures to prevent or mitigate, detect, and respond to security threats and vulnerabilities to information systems and resources at the program and enterprise levels.
  4. Periodically review security measures to ascertain that the security measures are still sufficient and continue to operate as expected.
  5. Perform reviews whenever security incidents occur or business processes change.
  6. Define, evaluate, and assess security architecture requirements for systems environments and IT projects.
  7. Ensure the incorporation of IT security and contingency measures in the development of systems.
  8. Advise on the identification, analysis, and resolution of specific security factors, risks, and vulnerabilities; protection of personal privacy issues; and appropriate industry and international security standards.
  9. Carry out information and information technology security projects and tasks in the Ontario Public Service as assigned by Corporate Security or cluster management.
Experience and Skill Set Requirements:
General Skills:
  1. Strong understanding and expertise in security architecture.
  2. Experience in the application of Cyber Security methodology and tools to define scope, critical business processes, and functions, identify critical assets and dependencies in reports to clients (TRA or other security assessments).
  3. Experience and ability to plan and facilitate Threat Risk Assessment and/or other workshops with business clients.
  4. Experience and ability to apply Harmonized Threat Risk Assessment (HTRA) or equivalent methodology.
  5. Knowledge of techniques to secure information assets and the planning, design, and implementation of security technologies.
  6. Proven techniques for identifying gaps or weaknesses in security architecture to mitigate known security threats or inherent weaknesses.
  7. Knowledge and understanding of relevant legislation and corporate directives related to the security and confidentiality of information (e.g. Freedom of Information and Protection of Privacy Act).
  8. Solid knowledge of current security and contingency technology and techniques (e.g. digital signature, encryption, access controls, firewalls, authentication, virus protection, etc.); and a proven working knowledge of security audit procedures and protocols.
  9. Experience in developing enterprise architecture deliverables (e.g. models).
  10. Experience in providing specialized security support at the specified experience level.
  11. Experience in establishing secure environments at a network, operating system, or application level.
  12. Experience with implementing security on complex and distributed systems.
  13. Experience in conducting in-depth analysis and providing recommendations with all required sign-offs in the prescribed timelines (TRA reports or other security assessment reports).
  14. Experience and knowledge to provide security requirements for procurement documents and participate in security evaluations as part of the procurement process.
  15. Ability to assess Information Security Risk, Business Continuity Planning, and Business Impact Analysis technical issues for any of the technical environments and delivery channels across the Ontario Provincial Government including Mainframe, Unix, and Windows.
  16. Awareness of emerging IT trends and directions, especially those related to security.
  17. Excellent analytical, problem-solving, and decision-making skills; written and verbal communication skills; interpersonal and negotiation skills.
  18. A team player with a track record for meeting deadlines, managing competing priorities, and client relationship management experience.
Desirable Skills:
  1. Experience in developing enterprise architecture deliverables (e.g. models) based on Ontario Government Enterprise Architecture processes and practice.
  2. Knowledge and understanding of Information Management principles, concepts, policies and practices.
  3. Experience in business recovery and disaster recovery planning.
  4. Experience in performing threat and risk assessment.
  5. Experience in public key infrastructure development and operation.
  6. Experience in security design as part of systems development projects.
  7. Experience in intrusion detection systems.
  8. Experience in mitigation tools for malicious software.
  9. Experience in vulnerability analysis and penetration testing.
  10. Experience in network monitoring.
  11. Experience in security policy development.
  12. Experience in developing and delivering security education.
  13. Experience in forensic investigation.
Cyber Risk Assessment - 40%
  1. Understanding of threat modeling and risk assessment methodologies.
  2. Ability to identify vulnerabilities and potential impacts on organizational assets.
  3. Knowledge of risk management frameworks like NIST SP 800-30.
  4. Proficiency in using cybersecurity tools and software for vulnerability scanning and risk analysis.
  5. Familiarity with network security, endpoint security, and application security.
  6. Awareness of relevant laws, regulations, and standards (e.g., GDPR, HIPAA, ISO 27001).
  7. Ability to ensure that risk assessments align with regulatory requirements.
Cyber Security Architecture - 40%
  1. Expertise in designing secure network architectures, including firewalls, IDS/IPS, and VPNs.
  2. Knowledge of cloud security architectures and best practices.
  3. Proficiency in security technologies such as encryption, authentication, and access control.
  4. Familiarity with security protocols and standards (e.g., TLS, SSL, IPsec).
  5. Knowledge of incident response and disaster recovery planning.
  6. Understanding of industry best practices and frameworks (e.g., NIST, CIS Controls).
  7. Ability to ensure architectural designs comply with regulatory requirements.
Executive IT Communication - 20%
  1. Ability to present complex technical information in a clear and concise manner to non-technical executives.
  2. Proficiency in creating impactful presentations and reports.
  3. Skills in engaging with stakeholders to understand their concerns and requirements.
  4. Ability to build strong relationships with executive leadership and board members.
Must Haves:
  1. 5+ years of information security risk management experience.
  2. 3+ years of security architecture experience.
  3. 3+ years of security risk assessment experience.

#LI-GTT

#LI-Hybrid

24-11695

Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.

Similar jobs

Privacy Impact Assessment Specialist 0309-1212

Foilcon

Toronto

Remote

CAD 70,000 - 110,000

Today
Be an early applicant

Property Risk Assessment Consultant, Ontario, and Atlantic Canada (Evergreen)

Northbridge Financial

Toronto

Remote

CAD 60,000 - 100,000

30+ days ago

Property Risk Assessment Consultant, Ontario, and Atlantic Canada (Evergreen)

Northbridge Financial

Montreal

Remote

CAD 60,000 - 100,000

30+ days ago

Property Risk Assessment Consultant, Ontario, and Atlantic Canada (Evergreen)

Northbridge Financial

Nova Scotia

Remote

CAD 60,000 - 100,000

30+ days ago

Solution Assessment Consultant Bilingual

ApeironSumus

Remote

CAD 60,000 - 80,000

30+ days ago

Annonce de recherche consultant: Evaluation finale du Projet d’Appui à la Santé Sexuelle et Rep[...]

Cooperation Canada

Montreal

Remote

CAD 60,000 - 100,000

30+ days ago