11 Aug
|
Innosystech
|
Toronto
11 Aug
Innosystech
Toronto
Job Title: Security Specialist - Senior
Location: Toronto, Ontario, Canada
Work Model: Hybrid
Duration: 7 months
Extension: 1 Time
Must Haves
- Risk Management & Assessment 5 7 years - Proven experience in conducting threat risk assessments using frameworks like ISO 31000, NIST RMF, or FAIR.
- Threat Modeling 3 5 years - Practical knowledge of threat modeling techniques (e.g., STRIDE, PASTA, MITRE ATT&CK;), including development of data flow diagrams and attack vectors.
- Information Security Governance 5+ years-Strong understanding of security policies, standards, and controls aligned with ISO 27001, NIST CSF, and CIS Controls.
- Communication & Reporting 5+ years-skilled in writing technical and executive-level reports, risk registers, and presenting to stakeholders and leadership.
Description / Responsibilities / Skills
Background Information
- This engagement involves driving the end-to-end execution of a Threat Risk Assessment (TRA) to evaluate the security posture of the information system, application, infrastructure, and business process.
- The objective is to identify potential threats, assess vulnerabilities, and determine the likelihood and impact of various risk scenarios affecting confidentiality, integrity, and availability.
- Reviewing system architecture, data flows, and existing controls.
- Assessing compliance with relevant regulatory and organizational security requirements.
Must haves
- Expertise in identifying, evaluating, and prioritizing threats and vulnerabilities across physical, cyber, and operational domains.
- Strong analytical skills to assess potential impacts and likelihoods of various threat scenarios.
- Proficiency risk assessment matrices
- Familiarity with legal, regulatory, and compliance requirements, ensuring assessments align with organizational and industry standards (e.g., PHIPAA - Personal Health Information Protection Act).
- Proactive mindset and situational awareness to anticipate and adapt to emerging threats in a dynamic risk environment.
Responsibilities
- Collaborate with stakeholders to align assessments with business objectives and risk tolerance.
- Analyze vulnerabilities and assess threats to determine likelihood and potential impact.
- Maintain risk registers and track remediation efforts.
- Ensure alignment with regulatory requirements, industry standards, and organizational security policies.
- Support audit and compliance activities as needed.
- Contribute to the continuous improvement of risk management frameworks and methodologies.
- Stay informed on emerging threats, vulnerabilities, and security best practices.
Evaluation Criteria
- Gap Analysis: 5 7 years of extensive experience with security controls and architecture, with a strong ability to identify gaps between current security posture and industry standards, best practices, and regulatory requirements. 20 Points
- Team Player: Demonstrates strong collaboration skills by working effectively with colleagues across functions, openly sharing information, supporting others to achieve shared goals. 30 Points
Additional Terms
- The resource will ensure full knowledge transfer is provided to the Agency team before end of engagement.
- The resource must provide all related documentation as part of knowledge transfer protocol.
- A walkthrough of any demos, development, etc. will be required before the end of the engagement.
- Agency systems cannot be accessed from outside the province of Ontario without prior written approval.
- Assignment Type: Hybrid; resource required to work onsite as per Hiring Manager sole discretion.
Deliverables
- TRA (Threat, Risk Assessment) Report: A comprehensive document outlining identified threats, vulnerabilities, risks, and proposed mitigation strategies, tailored to the organization's context.
- Risk Register: A structured log of all identified risks, including severity, likelihood, risk rating, responsible owners, and mitigation actions.
- Threat Modeling Diagrams: Visual representations of systems, data flows, and potential threat vectors using models like STRIDE or attack trees.
- Risk Assessment Matrix: A visual tool mapping the likelihood and impact of risks to prioritize them effectively.
- Asset Inventory & Classification:
A list of assets in scope categorized by value and sensitivity.
- Vulnerability Assessment Results: A summary of technical vulnerabilities discovered during the assessment, often with outputs from tools like Nessus or OpenVAS.
- Gap Analysis: Identification of discrepancies between current security posture and industry standards, best practices, or regulatory requirements.
- Mitigation & Remediation Plan: Detailed action plans with timelines and responsibilities for reducing identified risks to acceptable levels.
- Executive Summary: A high-level summary tailored for senior leadership, focusing on key findings, business impact, and strategic recommendations.
- Compliance Mapping: Documentation showing how risks and controls align with regulatory or standards frameworks (e.g., NIST, ISO 27001, SOC 2).
Experience & Skill Set Requirements
Evaluation Criteria
- Threat Modeling: - 5-7 years of hands-on experience with threat modeling techniques such as STRIDE, PASTA, and MITRE ATT&CK;, including the development of data flow diagrams and identification of attack vectors to inform secure design decisions and guide risk mitigation strategies across systems and applications. 20 Points
- TRA Report: - 5 7 years of experience conducting comprehensive threat and risk assessments using frameworks such as ISO 31000, NIST RMF, and FAIR, with a solid focus on identifying vulnerabilities, analyzing potential impacts, and delivering actionable risk mitigation strategies to stakeholders. 20 Points
- Gap Analysis: - 5 7 years of extensive experience with security controls and architecture, with a strong ability to identify gaps between the current security posture and industry standards, best practices, and regulatory requirements. 20 Points
- Team Player: - Demonstrates strong collaboration skills by working effectively with colleagues across functions, openly sharing information, supporting others to achieve shared goals, and contributing to a positive, respectful team environment. 30 Points
- Presentation Deck: - Over 5 years of experience authoring technical and executive-level reports, developing risk registers, and delivering presentations to stakeholders and senior leadership. 10 Points
- Total: 100 Points
📌 Security Specialist (Toronto)
🏢 Innosystech
📍 Toronto