RQ09054 - Security Specialist - Threat Risk Assessment - Senior
5 days ago
RQ09054 - Security Specialist - Threat Risk Assessment - Senior Job Openings RQ09054 - Security Specialist - Threat Risk Assessment - Senior About the job RQ09054 - Security Specialist - Threat Risk Assessment - Senior Description: Responsibilities Assesses internal and external threats and vulnerabilities of information systems and resources and the likelihood of these threats and resulting impacts. Where possible, reduce risks through system or organizational design. Implement security measures to prevent or mitigate, detect and respond to security threats and vulnerabilities to information systems and resources at the program and enterprise levels. Periodically review security measures to ascertain that the security measures are still sufficient and continue to operate as expected. Such reviews must also be performed whenever security incidents occur or business processes change. Defines, evaluates, and assesses security architecture requirements for systems environments and IT projects. Ensures the incorporation of IT security and contingency measures in the development of systems. Advises on the identification, analysis, and resolution of specific security factors, risks, vulnerabilities; protection of personal privacy issues; and appropriate industry and international security standards. Carry out information and information technology (I&IT) security projects and tasks in the Ontario Public Service as assigned by Corporate Security or cluster I&IT management. General Skills (30%) Strong understanding and expertise in security architecture Experience in the application of Cyber Security methodology and tools to define scope, critical business processes and functions, identify critical assets and dependencies in reports to clients (TRA or other security assessments) Experience and ability to plan and facilitate Threat Risk Assessment and/or other workshops with business clients Experience and ability to apply Harmonized Threat Risk Assessment (HTRA) or equivalent methodology Knowledge of techniques to secure information assets and the planning, design, and implementation of security technologies. Proven techniques to discover gaps or weaknesses in security architecture to identify and mitigate known security threats or inherent weaknesses. Knowledge and understanding of relevant legislation and corporate directives related to the security and confidentiality of information (e.g. Freedom of Information and Protection of Privacy Act) in order to identify and assess areas of concern and risk Solid knowledge of current security and contingency technology and techniques (e.g. digital signature, encryption, access controls, fire‑walls, authentication, virus protection, etc.); and a proven working knowledge of security audit procedures and protocols. Experience in developing enterprise architecture deliverables (e.g. models) Experience in providing specialized security support at the specified experience level. Experience in establishing secure environments at a network, operating system or application level. Experience with implementing security on complex and distributed systems. Experience in conducting in depth analysis and provide recommendations with all required sign‑off in the prescribed timelines as given (TRA reports or other security assessment reports) Experience and knowledge to provide security requirements for procurement documents and participate in security evaluations as part of the procurement process. Ability to assess Information Security Risk, Business Continuity Planning and Business Impact Analysis technical issues for any of the technical environments and delivery channels across the Ontario Provincial Government including Mainframe, Unix and Windows. Awareness of emerging IT trends and directions, especially as related to security. Excellent analytical, problem‑solving, and decision‑making skills; written and verbal communication skills; interpersonal and negotiation skills A team player with a track record for meeting deadlines, managing competing priorities and client relationship management experience Experience (30%) Organization maturity risk assessments Cyber security health checks Strategic cyber maturity advice Security‑by‑design advice Demonstrated Experience with the following phases of risk assessments Risks & Residual Risks post‑mitigation responses Demonstrated Experience conducting assessments on I&IT solutions against industry controls (e.g. NIST, ISF, ISO), GO-ITS standards and policies Demonstrated Experience analysing technical documentation, conducting interviews to gather further/gap information, and to prepare a risk assessment, calculate qualitative risk values, and residual risk Demonstrated Experience drafting and finalising executive risk reports. Communication and Writing (10%) Strong communication skills to prepare documentation, including but not limited to; reports, reviews, assessments Ability to present ideas and suggestions clearly and effectively and in a user friendly manner; maintain a high level of customer service to both internal and external clients Ability to communicate designs and development in clear and understandable manner Must Have Demonstrated Experience delivering the following: Organization maturity risk assessments Cyber security health checks Strategic cyber maturity advice Security‑by‑design advice Demonstrated Experience conducting assessments on I&IT solutions against industry controls (e.g. NIST, ISF, ISO), GO-ITS standards and policies #J-18808-Ljbffr
-
Toronto, Canada Rubicon Path Full timeRQ09054 - Security Specialist - Threat Risk Assessment - Senior Job Openings RQ09054 - Security Specialist - Threat Risk Assessment - Senior About the job RQ09054 - Security Specialist - Threat Risk Assessment - Senior Description: Responsibilities Assesses internal and external threats and vulnerabilities of information systems and resources and the...
-
Toronto, Canada Foilcon Full timeSecurity Specialist Threat Risk Assessment Skills Required: Threat Risk Assessment Incident Response Planning Security Compliance Standards (ISO 27001, NIST) Vulnerability Assessment Tools (e.g. Nessus, Qualys) Risk Management Frameworks Stakeholder Engagement Communication Skills Project Management Principles HM Note: This hybrid contract role is three (3)...
-
Senior Threat Risk Architect – InfoSec
4 days ago
Toronto, Canada Rubicon Path Full timeA leading security consultancy in Toronto is seeking a Senior Security Specialist to assess threats and implement security measures. The ideal candidate will have expertise in security architecture and experience conducting Threat Risk Assessments. Responsibilities include identifying vulnerabilities, advising on security factors, and ensuring compliance...
-
Senior Threat Risk Architect – InfoSec
2 days ago
Toronto, Canada Rubicon Path Full timeA leading security consultancy in Toronto is seeking a Senior Security Specialist to assess threats and implement security measures. The ideal candidate will have expertise in security architecture and experience conducting Threat Risk Assessments. Responsibilities include identifying vulnerabilities, advising on security factors, and ensuring compliance...
-
Senior Security Specialist
4 weeks ago
Toronto, Canada StafinGo Full timeChief Operating Officer | Consultant | Human Resources | Recruiting | Canada, USA & India Senior Security Specialist – Governance, Risk & Compliance (GRC) / Cyber Defence Location: Toronto, ON (Hybrid – up to 3 days onsite) Contract Length: 2-3 months to start (with potential extension) Sector: Public Sector / Healthcare A leading public-sector...
-
Senior Security Specialist
3 weeks ago
Toronto, Canada StafinGo Full timeChief Operating Officer | Consultant | Human Resources | Recruiting | Canada, USA & India Senior Security Specialist – Governance, Risk & Compliance (GRC) / Cyber Defence Location: Toronto, ON (Hybrid – up to 3 days onsite) Contract Length: 2-3 months to start (with potential extension) Sector: Public Sector / Healthcare A leading public-sector...
-
Senior Manager, Vulnerability
3 days ago
Toronto, Canada RBC Full timeWhat is the opportunity? Senior Manager, Vulnerability & Threat Assessment plays a pivotal role in safeguarding RBC’s digital ecosystem by proactively identifying, prioritizing, and tracking vulnerabilities and emerging threats remediation. This opportunity allows you to lead critical initiatives, such as managing Zero-Day vulnerabilities, driving...
-
Senior Manager, Vulnerability
15 hours ago
Toronto, Canada RBC Full timeWhat is the opportunity?Senior Manager, Vulnerability & Threat Assessment plays a pivotal role in safeguarding RBC’s digital ecosystem by proactively identifying, prioritizing, and tracking vulnerabilities and emerging threats remediation. This opportunity allows you to lead critical initiatives, such as managing Zero-Day vulnerabilities, driving executive...
-
Senior Security Specialist
6 days ago
Toronto, Ontario, Canada StafinGo Full timeSenior Security Specialist – Governance, Risk & Compliance (GRC) / Cyber DefenceLocation:Toronto, ON (Hybrid – up to 3 days onsite)Contract Length: 2-3 months to start(with potential extension)Sector:Public Sector / HealthcareA leadingpublic-sector organization in Ontariois seeking a highly experiencedSenior Security Specialistto support multiple...
-
Senior Security Specialist
3 days ago
Toronto, Canada KingSett Capital Inc. Full timeThe Senior Security Specialist is a key member of the Cybersecurity team, responsible for developing, implementing, and maintaining security protocols to protect the organization’s data, systems, and infrastructure. This role requires advanced technical expertise, a strategic mindset, and the ability to lead security initiatives across various departments....