08 Aug
|
GovTech Talent Solutions
|
Ontario
08 Aug
GovTech Talent Solutions
Ontario
Project Overview
This engagement involved driving the end-to-end execution of a Threat Risk Assessment (TRA) to evaluate the security posture of the information system, application, infrastructure, and business process. The objective is to identify potential threats, assess vulnerabilities, and determine the likelihood and impact of various risk scenarios affecting confidentiality, integrity, and availability.
Key Responsibilities
Drive end-to-end Threat Risk Assessment (TRA) initiatives across systems, processes, and assets.
Develop and apply threat models to assess organizational security posture, including creating threat modeling diagrams (STRIDE, attack trees) to visualize data flows and threat vectors.
Collaborate with stakeholders to align assessments with business objectives and risk tolerance.
Analyze vulnerabilities and assess threats to determine likelihood and potential impact.
Deliver comprehensive TRA Report outlining identified threats, vulnerabilities, risks, and proposed mitigation strategies.
Create and maintain Risk Register documenting all identified risks with severity, likelihood, ratings, owners, and mitigation actions.
Propose actionable mitigation strategies and develop detailed Mitigation and Remediation Plan with timelines and responsibilities.
Ensure alignment with regulatory requirements, industry standards, and organizational security policies, and document compliance mapping (NIST, ISO 27001, SOC 2).
Communicate findings effectively to both technical teams and executive leadership, including preparing Executive Summary and Presentation Deck.
Support audit and compliance activities as needed.
Contribute to the continuous improvement of risk management frameworks and methodologies.
Stay informed on emerging threats, vulnerabilities, and security best practices.
Compile Asset Inventory and Classification listing in-scope assets categorized by value and sensitivity.
Summarize Vulnerability Assessment Results from tools like Nessus or OpenVAS.
Perform Gap Analysis identifying discrepancies against industry standards and regulatory requirements.
Produce Risk Assessment Matrix mapping likelihood and impact of risks.
Qualifications & Requirements
REQUIRED
Must be able to work up to 3 days onsite per week
5–7 years of experience in Risk Management & Assessment, conducting threat risk assessments using frameworks like ISO 31000, NIST RMF, or FAIR.
3–5 years of practical knowledge in Threat Modeling with techniques like STRIDE, PASTA, MITRE ATT&CK;, including developing data flow diagrams and attack vectors.
5+ years in Information Security Governance, with strong understanding of security policies, standards, and controls aligned with ISO 27001, NIST CSF, and CIS Controls.
5+ years in Communication & Reporting, skilled in writing technical and executive-level reports, risk registers, and presenting to stakeholders.
Proficiency in risk assessment matrices.
Proactive mindset and situational awareness to anticipate and adapt to emerging threats.
NICE TO HAVE
Demonstrated expertise in enterprise risk analysis, applying risk management frameworks like ISO 31000, FAIR, and NIST RMF.
Hands-on experience conducting structured threat analysis using methodologies like STRIDE, PASTA, MITRE ATT&CK;, including threat model creation and attack surface mapping.
Strong command of cybersecurity governance practices, developing and enforcing security policies and standards, aligning controls with ISO 27001, NIST CSF, CIS Controls.
Proven ability to translate technical risk findings into business language, producing executive summaries, risk reports,
and stakeholder presentations, managing communication between teams and leadership.
EVALUATION CRITERIA
Threat Modeling: 5-7 years of hands-on experience with threat modeling techniques such as STRIDE, PASTA, and MITRE ATT&CK;, including the development of data flow diagrams and identification of attack vectors to inform secure design decisions and guide risk mitigation strategies across systems and applications. - 20 points
TRA Report: 5–7 years of experience conducting comprehensive threat and risk assessments using frameworks such as ISO 31000, NIST RMF, and FAIR, with a strong focus on identifying vulnerabilities, analyzing potential impacts, and delivering actionable risk mitigation strategies to stakeholders. - 20 points
Gap Analysis: 5–7 years of extensive experience with security controls and architecture, with a strong ability to identify gaps between the current security posture and industry standards, best practices, and regulatory requirements. - 20 points
Team Player: Demonstrates strong collaboration skills by working effectively with colleagues across functions, openly sharing information, supporting others to achieve shared goals, and contributing to a positive, respectful team setting. - 30 points
Presentation Deck: Over 5 years of experience authoring technical and executive-level reports, developing risk registers, and delivering presentations to stakeholders and senior leadership. - 10 points
Key Skills & Competencies
Threat Risk Assessment, ISO 31000, NIST RMF, FAIR, Threat Modeling, STRIDE, DREAD, PASTA, MITRE ATT&CK;, Data Flow Diagrams, Attack Vectors, Risk Analysis, Risk Assessment Matrices, Information Security Governance, ISO 27001, NIST CSF, CIS Controls, Vulnerability Assessment, Gap Analysis, Mitigation, Remediation, Compliance Mapping, Nessus, OpenVAS, Security Architecture, Security Controls, Risk Registers, PHIPAA, SOC 2, Data Classification
#J-18808-Ljbffr
📌 -009872 -Security Specialist - Senior for DxH (Ontario)
🏢 GovTech Talent Solutions
📍 Ontario