10 Aug
|
SereneAid
|
Halifax Regional Municipality
10 Aug
SereneAid
Halifax Regional Municipality
Client:Government of Nova Scotia – Cyber Security & Digital Solutions (CSDS)Project:Land Modernization Initiative (LMI)Location:Halifax, Nova Scotia (Remote with optional onsite work)Contract Duration:July 20, 2026 – May 31, 2027Engagement Type:Competitive-SourcedWork Arrangement:Remote (with occasional collaboration with CSDS stakeholders)Project OverviewThe Government of Nova Scotia is seeking experienced cybersecurity professionals to support the Land Modernization Initiative (LMI), a major transformation program modernizing the Province's Land Registry services.The selected consultants will work closely with the CSDS/LMI Technical Manager, Cyber Security and Risk Management (CSRM) team, and business stakeholders to conduct:Penetration Testing (PT)Security risk analysisVulnerability assessmentsSecurity recommendations and remediation guidanceThe initial engagement focuses on the MVS 1.0 release, with potential future work supporting releases 1.1, 1.2, and 1.3.RequirementsKey ResponsibilitiesScopeIdentify and document security threats, vulnerabilities, and risks across the Nova Scotia Land Registry ecosystem.Assess people, processes, technologies, communications, and information assets.Evaluate likelihood and business impact of identified risks.Recommend mitigation strategies and security controls.Perform assessments using the NIST SP 800-53 Revision 5 High Baseline framework.Review security certifications and reports including:ISO/IEC 27001ISO/IEC 42001SOC 2 Type IIPCI DSSActivitiesConduct workshops and stakeholder interviews.Review system architecture, integrations, and data flows.Analyze operational effectiveness of security controls.Assess compliance across applicable NIST control families.Document threat actors, attack vectors, vulnerabilities,
and risk treatments.Produce executive and technical reports.Present findings to senior leadership and project stakeholders.Penetration Testing (PT)ScopeWeb ApplicationsAPIsCloud EnvironmentsNetworksMobile ApplicationsTesting MethodologiesWhite Box TestingGrey Box TestingBlack Box TestingActivitiesExecute penetration testing using industry best practices.Identify, validate, and document vulnerabilities.Analyze prior security testing results.Conduct remediation verification and retesting.Produce executive and technical reports.Immediately escalation Critical vulnerabilities using CVSS standards.Participate in ongoing security assessments and risk management activities.Threat Risk Assessment DeliverablesDraft TRA ReportFinal TRA ReportCompleted TRA ChecklistExecutive PresentationPenetration Testing DeliverablesExecutive PresentationRemediation Validation / Retest ResultsMandatory Qualifications (Required)Candidates who do not meet the following requirements should not be submitted.Mandatory ExperienceMinimum 3 years of experience conducting Threat Risk Assessments (TRAs) on digital systems.At least one proposed resource must have completedtwo (2) or more TRAs on digital systems within the last three (3) years.Experience conducting TRAs within Canadian public sector environments.Experience working with:NIST SP 800-53ISO/IEC 27001ISO/IEC 42001SOC 2 Type IIPCI DSSExperience assessing:Cloud environments (AWS, Azure)Network infrastructureEnterprise applicationsAbility to work with business, security, and technical teams.Mandatory DocumentationCriminal Record Check completed within the last six (6) months.Penetration Testing RequirementsMandatory ExperienceMinimum 3 years of experience conducting penetration testing.At least one proposed resource must have completedtwo (2) or more penetration tests within the last twelve (12)
months.Experience conducting penetration testing in Canadian public sector organizations.Robust experience testing:Web applicationsAPIsCloud environmentsNetworksMandatory CertificationsAt least one proposed resource must hold one of the following:OSCP (Offensive Security Certified Professional)CREST CRT (Registered Penetration Tester)At least one proposed resource should hold one of the following:CEH MasterGPENMandatory DocumentationCriminal Record Check completed within the last six (6) months.Preferred QualificationsThe following are considered strong assets:Security CertificationsCISSPCISMCRISCOSCPCREST CRTCEH MasterGPENGovernment ExperiencePrevious experience performing Threat Risk Assessments for Canadian government organizations.Previous experience conducting Penetration Testing for Canadian government organizations.Direct experience supporting the Government of Nova Scotia.Familiarity with Government of Nova Scotia cybersecurity standards, risk frameworks, and governance processes.Technical SkillsCandidates should demonstrate expertise in:Penetration Testing MethodologiesISO/IEC 27001ISO/IEC 42001SOC 2 Type IIPCI DSSVulnerability AssessmentSecurity Architecture ReviewRisk Analysis and Treatment PlanningSecurity Control AssessmentCloud Security (AWS / Azure)Application SecurityNetwork SecuritySecurity Reporting and Executive PresentationsCVSS Scoring FrameworkEvaluation HighlightsCandidates and vendors will be evaluated based on:TRA experience and expertisePenetration testing experienceNIST and security framework knowledgeTier 1 and Tier 2 security certificationsPublic sector cybersecurity experienceGovernment of Nova Scotia experienceClient referencesThis opportunity is ideal for senior cybersecurity consultants with proven expertise in both Threat Risk Assessments and Penetration Testing within government and highly regulated environments. The successful team will play a critical role in securing one of Nova Scotia's most significant digital modernization initiatives. #J-18808-Ljbffr
📌 Threat Risk Assessment (Tra) Specialist / Penetration Testing (Pt) Specialist – Senior
🏢 SereneAid
📍 Halifax Regional Municipality