Security Analyst Control Testing

2 weeks ago


Old Toronto, Canada Maarut Inc Full time
RQ07825 - Security Specialist - Penetration Testing - Senior

Conducts penetration tests, web application vulnerability assessments, code reviews and network vulnerability assessments of all environments or applications related to the OPS province-wide I&IT infrastructure and information resources.

Defines, evaluates, and assesses security architecture requirements for systems environments and IT projects.

Ensures the incorporation of IT security and contingency measures in the development of systems.

Advises on the identification, analysis, and resolution of specific security factors, risks, vulnerabilities; protection of personal privacy issues; and appropriate industry and international security standards.

Carry out information and information technology (I&IT) security projects and tasks in the Ontario Public Service as assigned by Corporate Security or cluster I&IT management.

General Skills:

  • Experience in vulnerability assessment/penetration testing of web applications by identifying, analyzing and exploiting common vulnerabilities contained in web applications by using manual techniques and automated tools appropriate for enterprise use.
  • Experience performing penetration tests and red team assessments.
  • Experience with vulnerability assessment methodologies, tools and techniques used to conduct network vulnerability assessments and penetration testing.
  • Knowledge of techniques to secure information assets and the planning, design, and implementation of security technologies.
  • Proven techniques to discover gaps or weaknesses in security architecture to identify and mitigate known security threats or inherent weaknesses.
  • Strong understanding and expertise in security architecture.
  • Knowledge and understanding of relevant legislation and corporate directives related to the security and confidentiality of information (e.g. Freedom of Information and Protection of Privacy Act) in order to identify and assess areas of concern and risk.
  • Solid knowledge of current security and contingency technology and techniques (e.g. digital signature, encryption, access controls, fire-walls, authentication, virus protection, etc.); and a proven working knowledge of security audit procedures and protocols.
  • Experience in establishing secure environments at a network, operating system or application level.
  • Experience with implementing security on complex and distributed systems.
  • Experience in writing reports to a large audience both at an executive/non-technical management level and technical resources.
  • Awareness of emerging IT trends and directions, especially as related to security.
  • Excellent analytical, problem-solving, and decision-making skills; written and verbal communication skills; interpersonal and negotiation skills.
  • A team player with a track record for meeting deadlines, managing competing priorities and client relationship management experience.

Requirements

Experience and Skill Set Requirements:

Must Haves:

  • Current penetration test experience or directly relatable experience (red side experience).
  • Demonstrated experience in identifying, analyzing, and exploiting common vulnerabilities using both manual techniques and automated tools for web and network pen testing and vulnerability assessments.

Skill Set Requirements:

Penetration Test Experience:

  • Demonstrated experience in leading penetration tests, web application vulnerability assessments, code reviews and network vulnerability assessments in a large environment with diverse systems; and in common attacks, common web application vulnerabilities, exploits and best practices for remediation.
  • Knowledge of IT security methodologies, tools, techniques, security design and architecture, threat/risk concepts and practices, and encryption technologies.
  • Ability to acquire and interpret corporate I&IT security strategy, programs, the government’s trust model, and privacy legislation.

Technical Expertise:

  • Experience with multiple operating systems, programming and scripting languages, platforms, and network services and protocols.
  • Understanding of emerging I&IT trends, best practices and developments in common attacks, common web application vulnerabilities, exploits and best practices for remediation.

Analytical and Problem Solving Skills:

  • Demonstrated analytical and problem solving skills to determine alternative and innovative solutions where guidelines or policies exist but may not address new and emerging I&IT trends.
  • Ability to conceptualize, interpret and evaluate security exposures across multiple domains.

Communication and Relationship Building Skills:

  • Experience with writing reports aimed at both the executive/non-technical management level, and technical analyst level.
  • Oral and written communication, mediation, negotiation, consultative and advisory skills.
  • Skills to provide training in the use of commercial security assessment tools and scanners.
  • Stakeholder management, partnership and relationship building skills to initiate and nurture strong working relationships with internal and external colleagues.

Leadership and Project Management Skills:

  • Proven ability to provide leadership, advice and direction on business risk planning and coordination.
  • Demonstrated project methodology and management skills to provide project planning and technical leadership on concurrent projects.
#J-18808-Ljbffr
  • Security Test Analyst

    6 months ago


    Toronto, Canada AstraNorth Full time

    **Responsibilities and Duties**: - This role will support all testing and validation activities for projects under Information Security portfolio and work closely with the PMs and BAs to complete all deliverables. - To read all the documents and understand what needs to be tested - Inform the PMs and BAs about what all resources will be required for...


  • Old Toronto, Canada RBC Full time

    b>The Identity and Access Management (IAM) Onboarding Team is looking for a Senior Cyber Security Analyst to work towards onboarding applications to RBC’s Identity and Access Management solutions in accordance with the IAM onboarding strategy and IAM goals. li>Learn architectural patterns relevant to RBC’s IAM services.Identify and report security risks...


  • Toronto, ON, Canada Amazech Solutions Full time

    We are looking for a Quality Analyst with Peoplesoft testing experience to work out of Toronto, ON Significant knowledge and experience of testing PeopleSoft 9.Technical and functional knowledge of Peoplesoft especially on Fluid UI, Self Service, Core HR, Payroll; Oracle DB and SQL skills Experience executing functional tests, non-functional tests...

  • Info Security Analyst

    4 weeks ago


    Toronto, Canada Robertson and Company Full time

    Our client is a top financial institution with significant North American holdings. They have operations across most major verticals, including institutional & corporate, wealth management, private client, commercial banking, treasury, and retail banking. Introduction: Robertson is seeking a skilled Info Security Analyst to join our client. Contract Dates:...

  • QA Analyst Lead

    6 months ago


    Toronto, Canada Condo Control Full time

    Do you thrive in a dynamic, innovative environment helping companies achieve (and exceed!) their goals? Do you love sharing your knowledge and working cross-functionally? If so, we have a fantastic opportunity for you to join our team. Our main office is conveniently located right above the College subway station at Yonge & College. You will be working...

  • Security Analyst

    6 months ago


    Toronto, Canada Aviso Wealth Full time

    **Aviso Wealth**: **The Opportunity**: We’re looking for a Security Analyst to join or Information Security team. This role can be mostly remote, however we will on occasion require you to come onsite to our office at 151 Yonge St, Toronto, ON. Reporting to the Senior Manager of Information Security, the Security Analyst is responsible for ensuring the...


  • Toronto, Canada GTT, LLC Full time

    Job Title: Information Security AnalystLocation: Toronto, ONEmployment Type: ContractDuration: 12 MonthsWork Type: Hybrid (Onsite 2 days/week)Salary Range: $85 - $100/HourJob Description:Are you a seasoned Information Security Analystwith a passion for safeguarding sensitive information? We're seeking a talented individual to join our dynamic team in...

  • IT Risk

    7 days ago


    Old Toronto, Canada Scotiabank Full time

    Join a purpose driven winning team, committed to results, in an inclusive and high-performing culture.The Scotiabank IT Risk Management team plays an important role in the Bank’s Three Lines of Defense Framework, providing First Line of Defense for Scotiabank and the Bank for all technology risk domains, including Cyber Security, Data Privacy, Software...

  • IT Risk

    1 week ago


    Old Toronto, Canada Scotiabank Full time

    Join a purpose driven winning team, committed to results, in an inclusive and high-performing culture.The Scotiabank IT Risk Management team plays an important role in the Bank’s Three Lines of Defense Framework, providing First Line of Defense for Scotiabank and the Bank for all technology risk domains, including Cyber Security, Data Privacy, Software...


  • Toronto, Canada BMO Financial Group Full time

    250 Yonge Street Toronto Ontario,M5B 2L7 Executes testing to provide insights and recommendations on test results, findings, identified issues, re-performance testing, and continuous improvement insights. Executes testing, monitoring and operational activities of various complexity based on assigned portfolio ensuring adherences to established service...


  • Toronto, Canada Robertson & Company Ltd. Full time

    *** THIS ROLE IS WITH OUR CLIENT IN THE BANKING INDUSTRY***Title: Info Security Analyst VDuration: 12 months (with possibility of extension or conversion)TYPE: Hybrid (2 days in Toronto)MUST HAVE:6+ years of Control testing experience. Effectiveness control testing experience. JIRA, ServiceNow, Agile methodology 6+ years of Info Sec Analyst experience ...


  • Toronto, Canada Questrade Financial Group Full time

    Questrade Financial Group (QFG) of Companies is committed to helping our customers become much more financially successful and secure. We are everything a traditional financial institution is not. At QFG, you will be constantly moving forward, bringing the future of fintech into existence. You will be a part of a collaborative team that cares deeply about...


  • Old Toronto, Canada Finance Professionals Inc. Full time

    p>JOB DESCRIPTIONLocation: Hybrid (Downtown, Toronto)Duration: 6 monthsOur client, a leading financial institution in Downtown Toronto, is looking for a Manager Privacy Testing to lead and deliver timely and accurate testing reviews that opine on the adequacy of 1LOD systems, controls, and processes to manage privacy risk in Canada and the Caribbean....


  • Toronto, Canada First National Full time

    We are hiring an Application Security Analyst, Information Security! The Role: We're seeking an Application Security Analyst well-versed in risk analysis, vulnerability assessment methodologies, and information security concepts. Your role involves supporting security risk assessments for both internally developed and third-party/open-source...

  • Security Analyst

    6 months ago


    Toronto, Canada HTS Engineering - Heat Transfer Solutions Full time

    HTS Engineering Ltd. is the largest independent commercial HVAC manufacturers’ rep in North America, with 20 locations in the US and Canada. HTS has a vibrant look and brand promise -- one that reflects our company-wide commitment to ensure the individual success of all those involved in a project’s HVAC system selection, design, purchase, installation...

  • Security Analyst

    6 months ago


    Toronto, Canada HTS Engineering - Heat Transfer Solutions Full time

    Founded in 2015 in Toronto, Canada, KORE Solutions is a subsidiary company of HTS and an innovative technology solutions and services provider with a strong focus on the HVAC manufacturer’s representative industry. With a variety of offerings including business intelligence software, help service support, and more, KORE delivers end-to-end solutions that...


  • Toronto, Canada Questrade Financial Group Full time

    Questrade Financial Group (QFG) of Companies is committed to helping our customers become much more financially successful and secure. We are everything a traditional financial institution is not. At QFG, you will be constantly moving forward, bringing the future of fintech into existence. You will be a part of a collaborative team that cares deeply about...


  • Toronto, Canada Astek Full time

    The Astek GroupFounded in France in 1988, Astek is a global player in engineering and technology consulting. With its expertise in various industrial and tertiary sectors, Astek supports its international clients in the intelligent deployment of their products and services, as well as in the implementation of their digital transformation.Since its inception,...


  • Toronto, Canada Astek Full time

    The Astek GroupFounded in France in 1988, Astek is a global player in engineering and technology consulting. With its expertise in various industrial and tertiary sectors, Astek supports its international clients in the intelligent deployment of their products and services, as well as in the implementation of their digital transformation.Since its inception,...

  • Security Specialist

    3 weeks ago


    Toronto, Canada Softline Technology Full time

    Description **Responsibilities**: Defines, evaluates, and assesses security architecture requirements for systems environments and IT projects. Ensures the incorporation of IT security and contingency measures in the development of systems. Advises on the identification, analysis, and resolution of specific security factors, risks, vulnerabilities;...