11 Aug
|
SereneAid
|
Halifax Regional Municipality
11 Aug
SereneAid
Halifax Regional Municipality
Government of Nova Scotia – Cyber Security & Digital Solutions (CSDS) Project: Location: Halifax, Nova Scotia (Remote with optional onsite work) Contract Duration: July 20, 2026 – May 31, 2027 Remote (with occasional collaboration with CSDS stakeholders) Project Overview The Government of Nova Scotia is seeking experienced cybersecurity professionals to support the Land Modernization Initiative (LMI), a major transformation program modernizing the Province’s Land Registry services. The selected consultants will work closely with the CSDS/LMI Technical Manager, Cyber Security and Risk Management (CSRM) team, and business stakeholders to conduct: Penetration Testing (PT) Security risk analysis Identify and document security threats, vulnerabilities, and risks across the Nova Scotia Land Registry ecosystem. Assess people, processes, technologies, communications, and information assets.
Evaluate likelihood and business impact of identified risks. Recommend mitigation strategies and security controls. Review system architecture, integrations, and data flows. Analyze operational effectiveness of security controls.
Assess compliance across applicable NIST control families. Document threat actors, attack vectors, vulnerabilities, and risk treatments. Produce executive and technical reports. Present findings to senior leadership and project stakeholders.
Penetration
Testing (PT) Web Applications Networks Testing Methodologies White Box Testing Grey Box Testing Black Box Testing Execute penetration testing using industry best practices. Analyze prior security testing results. Produce executive and technical reports. Immediately escalation Critical vulnerabilities using CVSS standards. Participate in ongoing security assessments and risk management activities.
Threat Risk Assessment Deliverables
Draft TRA Report Penetration Testing Deliverables Minimum 3 years of experience conducting Threat Risk Assessments (TRAs) on digital systems. At least one proposed resource must have completed two (2) or more TRAs on digital systems within the last three (3) years .
Experience conducting TRAs within Canadian public sector environments. Cloud environments (AWS, Azure) Network infrastructure Ability to work with business, security, and technical teams.
Criminal Record
Check completed within the last six (6) months.
Penetration Testing Requirements
Minimum 3 years of experience conducting penetration testing. At least one proposed resource must have completed two (2) or more penetration tests within the last twelve (12) months .
Experience conducting penetration testing in Canadian public sector organizations.
Strong experience testing: Web applications Networks CREST CRT (Registered Penetration Tester) Criminal Record Check completed within the last six (6) months.
The following are considered strong assets: Previous experience performing Threat Risk Assessments for Canadian government organizations. Previous experience conducting Penetration Testing for Canadian government organizations. Familiarity with Government of Nova Scotia cybersecurity standards, risk frameworks, and governance processes.
Technical Skills Penetration Testing Methodologies Risk Analysis and Treatment Planning Security Control Assessment Cloud Security (AWS / Azure) Network Security Penetration testing experience Public sector cybersecurity experience This chance is ideal for senior cybersecurity consultants with proven expertise in both Threat Risk Assessments and Penetration Testing within government and highly regulated environments. The successful team will play a critical role in securing one of Nova Scotia's most significant digital modernization initiatives. #
📌 Threat Risk Assessment (TRA) Specialist / Penetration Testing (PT) Specialist - Senior
🏢 SereneAid
📍 Halifax Regional Municipality