09 Aug
|
BITS Recruiting
|
Ontario
09 Aug
BITS Recruiting
Ontario
Senior Security Specialist (Threat Risk Assessment)
Location: Hybrid – Toronto, ON (University Ave., up to 3 days onsite at manager's discretion)
Contract: September 1, 2026 – March 31, 2027
Duration: 151 Business Days
Hours: Monday–Friday (Full-Time)
Incorp Rate: $95-$105
About the Role Our client is seeking an experienced Senior Security Specialist to lead end-to-end Threat Risk Assessments (TRAs) across enterprise systems, applications, infrastructure, and business processes. In this role, you will identify security risks, evaluate vulnerabilities, and provide practical recommendations to strengthen the organization's overall security posture.
Working closely with business and technical stakeholders, you will apply industry-standard risk management and threat modeling frameworks to assess security risks, document findings, and present recommendations to both technical teams and executive leadership.
Key Responsibilities Lead end-to-end Threat Risk Assessments (TRAs) for enterprise systems, applications, and infrastructure.
Define assessment scope with business and technical stakeholders.
Conduct risk assessments using frameworks such as ISO 31000, NIST RMF, or FAIR .
Perform threat modeling using methodologies such as STRIDE, PASTA, and MITRE ATT&CK; .
Review system architecture, data flows, and existing security controls.
Identify threats, vulnerabilities, and potential business impacts.
Develop risk registers and track remediation activities.
Prepare detailed risk assessment reports with mitigation recommendations.
Present findings to technical teams, project stakeholders, and executive leadership.
Ensure compliance with organizational policies, security standards, and regulatory requirements, including PHIPA .
Support audit and compliance initiatives.
Contribute to the continuous improvement of security governance and risk management processes.
Stay current on emerging cybersecurity threats, vulnerabilities, and best practices.
Must-Have Qualifications 5–7 years of experience conducting Threat Risk Assessments (TRA) using ISO 31000, NIST RMF, or FAIR .
3–5 years of hands-on experience with threat modeling methodologies such as STRIDE, PASTA, or MITRE ATT&CK; .
5+ years of experience in Information Security Governance , including security policies, standards, and controls aligned with ISO 27001, NIST CSF, and CIS Controls .
Strong understanding of cybersecurity risk assessment methodologies and risk analysis.
Experience creating risk registers, executive reports, and technical documentation.
Excellent communication skills with the ability to present technical findings to both technical and executive audiences.
Preferred Qualifications Experience working within the Ontario Public Sector or Healthcare environment.
Knowledge of PHIPA and healthcare information security requirements.
Experience supporting security audits, compliance initiatives, and governance programs.
Solid analytical and problem-solving skills.
Ability to manage multiple priorities in a fast-paced environment.
#J-18808-Ljbffr
📌 Senior Security Specialist (Ontario)
🏢 BITS Recruiting
📍 Ontario