Senior Security Threat Risk Assessment Specialist
3 months ago
- Contract Duration 6 Months
- Pay range - C$750 to $800/day
- Hybrid: Required to come to the office upon request (once every two weeks).
- Senior Security Threat Risk Assessment Specialist assesses internal and external threats and vulnerabilities of information systems and resources and the likelihood of these threats and resulting impacts.
- Where possible, reduce risks through system or organizational design.
- Implement security measures to prevent or mitigate, detect, and respond to security threats and vulnerabilities to information systems and resources at the program and enterprise levels.
- Periodically review security measures to ascertain that the security measures are still sufficient and continue to operate as expected.
- Such reviews must also be performed whenever security incidents occur or business processes change.
- Defines, evaluates, and assesses security architecture requirements for systems environments and IT projects.
- Ensures the incorporation of IT security and contingency measures in the development of systems.
- Advises on the identification, analysis, and resolution of specific security factors, risks, and vulnerabilities; protection of personal privacy issues; and appropriate industry and international security standards.
- Carry out information and information technology security projects and tasks in the Ontario Public Service as assigned by Corporate Security or cluster management
Experience and Skill Set Requirements:
General Skills:
- Strong understanding and expertise in security architecture
- Experience in the application of Cyber Security methodology and tools to define scope, critical business processes, and functions, identify critical assets and dependencies in reports to clients (TRA or other security assessments)
- Experience and ability to plan and facilitate Threat Risk Assessment and/or other workshops with business clients
- Experience and ability to apply Harmonized Threat Risk Assessment (HTRA) or equivalent methodology
- Knowledge of techniques to secure information assets and the planning, design, and implementation of security technologies.
- Proven techniques for Client gaps or weaknesses in security architecture to identify and mitigate known security threats or inherent weaknesses.
- Knowledge and understanding of relevant legislation and corporate directives related to the security and confidentiality of information (e.g. Freedom of Information and Protection of Privacy Act) in order to identify and assess areas of concern and risk
- Solid knowledge of current security and contingency technology and techniques (e.g. digital signature, encryption, access controls, firewalls, authentication, virus protection, etc.); and a proven working knowledge of security audit procedures and protocols.
- Experience in developing enterprise architecture deliverables (e.g. models)
- Experience in providing specialized security support at the specified experience level.
- Experience in establishing secure environments at a network, operating system, or application level.
- Experience with implementing security on complex and distributed systems.
- Experience in conducting in-depth analysis and providing recommendations with all required sign-offs in the prescribed timelines as given (TRA reports or other security assessment reports)
- Experience and knowledge to provide security requirements for procurement documents and participate in security evaluations as part of the procurement process
- Ability to assess Information Security Risk, Business Continuity Planning, and Business Impact Analysis technical issues for any of the technical environments and delivery channels across the Ontario Provincial Government including Mainframe, Unix, and Windows.
- Awareness of emerging IT trends and directions, especially those related to security.
- Excellent analytical, problem-solving, and decision-making skills; written and verbal communication skills; interpersonal and negotiation skills
- A team player with a track record for meeting deadlines, managing competing priorities, and client relationship management experience
Desirable Skills:
- Experience in developing enterprise architecture deliverables (e.g. models) based on Ontario Government Enterprise Architecture processes and practice
- Knowledge and understanding of Information Management principles, concepts, policies and practices
- Experience in business recovery and disaster recovery planning.
- Experience in performing threat and risk assessment.
- Experience in public key infrastructure development and operation.
- Experience in security design as part of systems development projects.
- Experience in intrusion detection systems.
- Experience in mitigation tools for malicious software.
- Experience in vulnerability analysis and penetration testing.
- Experience in network monitoring.
- Experience in security policy development.
- Experience in developing and delivering security education.
- Experience in forensic investigation.
- Knowledge and understanding of Information Management principles, concepts, policies and practices
Cyber Risk Assessment - 40%
- Understanding of threat modeling and risk assessment methodologies.
- Ability to identify vulnerabilities and potential impacts on organizational assets.
- Knowledge of risk management frameworks like NIST SP 800-30
- Proficiency in using cybersecurity tools and software for vulnerability scanning and risk analysis.
- Familiarity with network security, endpoint security, and application security.
- Awareness of relevant laws, regulations, and standards (e.g., GDPR, HIPAA, ISO 27001).
- Ability to ensure that risk assessments align with regulatory requirements
Cyber Security Architecture - 40%
- Expertise in designing secure network architectures, including firewalls, IDS/IPS, and VPNs.
- Knowledge of cloud security architectures and best practices.
- Proficiency in security technologies such as encryption, authentication, and access control.
- Familiarity with security protocols and standards (e.g., TLS, SSL, IPsec).
- Knowledge of incident response and disaster recovery planning.
- Understanding of industry best practices and frameworks (e.g., NIST, CIS Controls).
- Ability to ensure architectural designs comply with regulatory requirements.
Executive IT Communication - 20%
- Ability to present complex technical information in a clear and concise manner to non-technical executives.
- Proficiency in creating impactful presentations and reports.
- Skills in engaging with stakeholders to understand their concerns and requirements.
- Ability to build strong relationships with executive leadership and board members
Must Haves:
- 5+ years of information security risk management experience
- 3+ years of security architecture experience
- 3+ years of security risk assessment experience
#gttca #LI-GTT #LI-Hybrid #gttjobs 24-11695
-
Threat Risk Assessment Specialist
6 months ago
Toronto, Canada Questrade Financial Group Full timeQuestrade Financial Group (QFG) of Companies is committed to helping our customers become much more financially successful and secure. We are everything a traditional financial institution is not. At QFG, you will be constantly moving forward, bringing the future of fintech into existence. You will be a part of a collaborative team that cares deeply about...
-
Security Specialist
3 months ago
Toronto, Canada Softline Technology Full timeDescription Responsibilities Assesses internal and external threats and vulnerabilities of information systems and resources and the likelihood of these threats and resulting impacts. Where possible, reduce risks through system or organizational design. Implement security measures to prevent or mitigate, detect and respond to security threats and...
-
Threat Risk Assessment Analyst
6 months ago
Toronto, Canada ThoughtStorm Inc Full timeThe proposed resources must have a minimum of two years of experience conducting Threat Risk Assessments in Ontario and/or Canada and in a health care context based on PHIPA or other provincial health legislation. Deliverable - Participate in a kick-off/scoping meetings - provide a list of documents required from client required for conducting the TRA -...
-
Threat Risk Assessment Analyst
6 months ago
Toronto, Canada Thought storm Full time**Location - GTA** **Duration - 12 Months** The proposed resources must have a minimum of two years of experience conducting Threat Risk Assessments in Ontario and/or Canada and in a health care context based on PHIPA or other provincial health legislation. Deliverable - Participate in a kick-off/scoping meetings - provide a list of documents required...
-
Senior Security Threat Specialist
3 months ago
Toronto, Canada Norton Rose Fulbright Full timeRole The senior security threat specialist is a position in the global information security function at Norton Rose Fulbright. The role is responsible for proactively managing the threat landscape at the firm. Primary responsibilities include vulnerability management and threat management (including threat hunting). Other tasks include threat...
-
Cybersecurity Threat Assessment Specialist
3 weeks ago
Old Toronto, Canada Maarut Inc Full timeJob Description:We are seeking a highly skilled Cybersecurity Threat Assessment Specialist to join our team at Maarut Inc.About the Role:The Cybersecurity Threat Assessment Specialist will be responsible for conducting penetration tests, web application vulnerability assessments, code reviews, and network vulnerability assessments of all environments or...
-
Information Security Specialist
6 months ago
Toronto, Canada TD Bank Full time**Information Security Specialist (Cyber Threat Matrix)**: - 425216BR **Job Category - Primary** - Technology Solutions **Work Location** - 310-320 Front Street West Corporate **Employment Type** - Regular **City** - Toronto **Time Type** - Full Time **Province/State** - Ontario **Hours** - 37.5 **Workplace Model** - Hybrid **Pay...
-
Physical Threat Intelligence Analyst
4 weeks ago
Toronto, Ontario, Canada Scotiabank Full timeAt Scotiabank, we are committed to protecting our employees, business operations, and assets across the globe. As a Physical Threat Intelligence Analyst - Risk Assessment Expert, you will play a critical role in our Corporate Security team by analyzing existing and emerging physical threats and risks.Job SummaryWe are seeking an experienced analyst with...
-
Security Risk Specialist
6 days ago
Toronto, Ontario, Canada CorGTA Full timeAt CorGTA, we are seeking a highly skilled Security Risk Specialist to join our team.About the Role:We are looking for a seasoned Security Analyst with 6+ years of experience in security analysis. The ideal candidate will have a strong background in security governance, policies, cybersecurity frameworks, security standards, and regulatory compliance.Key...
-
Group Risk Specialist
4 months ago
Toronto, Canada TD Bank Full time**Work Location**: Canada **Hours**: 37.5 **Line of Business**: Risk Management **Pay Details**: **Department Overview** **The independent Operational Risk Management (ORM) team works in partnership with the business units and corporate groups of TD Bank Group to further the understanding and management of operational risk across the enterprise.** **The...
-
Senior Specialist Threat Intelligence
1 month ago
Toronto, Canada David Joseph & Company Full timeJOB SUMMARY:To support the execution of the Chief Information Security Officer's (CISO) mandate, cyber vision and strategy, providing technical and business advice, support and services on Threat Management cyber programs and initiatives to all City divisions, agencies and corporations. To define, develop and support Threat Management cyber programs and...
-
Information Security Risk Management Specialist
4 weeks ago
Toronto, Ontario, Canada Foilcon Full timeAbout the RoleFoilion is seeking an experienced Information Security Risk Management Specialist to join our team. As a key member of our security team, you will be responsible for assessing and mitigating internal and external threats to our information systems and resources.
-
Threat Intelligence Lead
1 month ago
Toronto, Ontario, Canada David Joseph & Company Full timeAbout the RoleWe are seeking a highly skilled Cyber Threat Intelligence Specialist to join our team at David Joseph & Company.The ideal candidate will have a strong background in Threat Intelligence, with experience in leading the development and deployment of cyber threat intelligence capabilities and methods.The successful candidate will be responsible for...
-
Cyber Security Risk Management Specialist
4 weeks ago
Old Toronto, Canada S M Software Solutions Inc Full timeS M Software Solutions Inc is seeking a highly skilled Cyber Security Risk Management Specialist to join our team in Toronto, Ontario.The estimated salary for this position is $120,000 - $180,000 per year, depending on experience.About the JobAs a Cyber Security Risk Management Specialist, you will be responsible for assessing internal and external threats...
-
Enterprise Threat Modeling Specialist
2 weeks ago
Old Toronto, Canada Equitable Group Full timeTransforming Banking through Cybersecurity ExpertiseAs a pioneering bank, Equitable Group is pushing the boundaries of traditional banking. With over 670,000 customers across Canada and assets under management exceeding $125 billion, we're committed to driving change in Canadian banking to enrich people's lives.About the Role:We're seeking an exceptional...
-
Cybersecurity Risk Management Specialist
4 weeks ago
Toronto, Ontario, Canada Randstad Canada Full timeJob Description:As a Cybersecurity Risk Management Specialist at Randstad Canada, you will play a key role in identifying and mitigating potential security threats to our clients' information systems. Your expertise in risk management and compliance will be essential in ensuring that our clients' security policies and controls are aligned with industry best...
-
Analyst I, Cyber Threat and Vulnerability Management
3 months ago
Toronto, Canada Toronto District School Board Full time**Permanent, full-time position - Toronto, ON** Reporting to the Senior Analyst, IT Security Threat Management, the Analyst I, Cyber Threat and Vulnerability Management, will assist the Senior Analyst to ensure that the Cyber Threat and Vulnerability Management functions are managed and carried out. The Analyst I, Cyber Threat and Vulnerability...
-
Senior Threat Modeling Analyst
2 weeks ago
Toronto, Canada EQ Bank | Equitable Bank Full timeJoin a ChallengerBeing a traditional bank just isn’t our thing. We are big believers in innovating the banking experience because we believe Canadians deserve better options, and we challenge ourselves and our teams to creatively transform what’s possible in banking. Our team is made up of inquisitive and agile minds that find smarter ways of doing...
-
Senior Threat Modeling Analyst
2 weeks ago
Toronto, Canada EQ Bank | Equitable Bank Full timeJoin a ChallengerBeing a traditional bank just isn’t our thing. We are big believers in innovating the banking experience because we believe Canadians deserve better options, and we challenge ourselves and our teams to creatively transform what’s possible in banking. Our team is made up of inquisitive and agile minds that find smarter ways of doing...
-
Toronto, Canada KPMG Canada Full timeAbout KPMG CanadaKPMG Canada is a leading professional services firm that helps businesses thrive in an ever-changing world. We are committed to creating a workplace culture that values diversity, equity, and inclusion.Job DescriptionWe are seeking an experienced Advanced Threat Intelligence Lead for Cyber Security to join our team in Toronto, Ontario. The...