Security Specialist - Threat Risk Assessment - Senior - C$90 - C$100 An Hour (Toronto)

Security Specialist - Threat Risk Assessment - Senior - C$90 - C$100 An Hour (Toronto)

12 Aug
|
Russell Tobin
|
Toronto

12 Aug

Russell Tobin

Toronto

Job Title: Security Specialist - Threat Risk Assessment - SeniorLocation: Toronto, Onsite 56 WellesleyDuration: 12+ Months (Possible Extension) Pay Rate: CAD 90- 100/Hour Role OverviewSenior Information Security and Privacy Specialist responsible for designing, implementing, and operating an enterprise Information Security Management System (ISMS) aligned to ISO/IEC 27001:2013 and ISO/IEC 27799; leads security and privacy impact assessments, vulnerability and penetration testing programs, and ongoing ISMS performance monitoring while acting as the primary liaison between security/privacy teams, technical implementers, and business stakeholders in healthcare environments.Required Tech Stack Standards & Frameworks: ISO/IEC 27001, ISO/IEC 27799, ISO/IEC 17799, NIST CSF, OWASP.GRC & ISMS Tools: Archer, ServiceNow GRC, OneTrust, RSA Archer, MetricStream.Security Operations: SIEM (Splunk, Azure Sentinel, QRadar), centralized logging, log analytics.Vulnerability & Pen Testing: Nessus, Qualys, Burp Suite, Metasploit, SAST/DAST tools.Identity & Access: IAM, RBAC, SSO, MFA, PKI, certificate management.Data Protection: DLP, encryption (TDE, TLS), tokenization, data masking, secure key management (Azure Key Vault/HSM).Integration & Interfaces: SFTP, REST/SOAP APIs, HL7 (for healthcare integrations), secure file transfer.Cloud & Infrastructure: Azure/AWS security controls, network segmentation, firewalls, load balancers.Testing & Automation: CI/CD security gates, automated privacy/accessibility scans, vulnerability scanning automation.Business Systems: MIS, HRIS, clinical systems, OLIS/LIS interfaces, and associated middleware/ETL tools.Documentation & Collaboration: SharePoint, Confluence, MS Project, Excel, Word, PowerPoint.Must HavesMinimum 5+ years operating as a privacy expert with demonstrable experience leading end‑to‑end operational risk assessments and privacy risk remediation in healthcare systems.Proven track record developing, implementing and operating ISMS and privacy risk programs based on ISO/IEC 17799 / 27001 / 27799 including annual planning, audits, and continuous improvement.Hands‑on experience conducting Privacy Impact Assessments (PIAs), Threat and Risk Analyses (TRAs), and translating findings into technical and process remediation.Practical experience implementing privacy controls for personal health information, including de‑identification, data masking, consent management,



and HIC role mapping.Experience running vulnerability assessments and coordinating penetration testing with remediation tracking and verification.Familiarity with healthcare privacy legislation and regulatory requirements and how they apply to system design and operations.Ability to act as primary security/privacy liaison across technical teams, business owners, and external vendors.Minimum 2+ years experience in the healthcare sector or with health information systems (MIS/HRIS/clinical systems).Roles and ResponsibilitiesDesign, implement and maintain the ISMS: define control set, document policies/procedures, map controls to ISO/IEC 27001/27799, and drive continuous improvement cycles.Develop and execute the annual information security plan, monitor ISMS KPIs, prepare monthly status reports, and coordinate the annual ISO/IEC 27001 audit and corrective action program.Lead end‑to‑end operational risk assessments: select risk methodology, identify privacy/compliance gaps, prioritize dependencies, and recommend remediation or simplification strategies.Conduct and validate Privacy Impact Assessments (PIAs) and Threat Risk Analyses (TRAs) at conceptual, logical and physical levels; translate outcomes intotechnical requirements and mitigation tasks.Implement and operate vulnerability management and penetration testing programs: schedule scans, manage findings, coordinate remediation, and verify fixes with re‑scans.Build and maintain security and privacy audit management frameworks, including audit schedules, evidence collection, control testing, and audit reporting.Serve as primary point of contact between Security/Privacy resources, technical implementation teams, and business stakeholders; coordinate communications, escalations, and decision tracking.Work with operations leads to define and enforce security standards, privacy controls, compliance obligations (PHIPA/FIPPA/HPPA awareness), and business risk acceptance criteria.Provide operational security support for MIS and HRIS applications: secure configurations, access reviews,



patching coordination, backup/restore validation, and incident response readiness.Implement data protection controls for personal health information: encryption in transit/at rest, tokenization/masking for non‑prod environments, and consent/disclosure logging.Integrate privacy and accessibility (AODA/WCAG) checks into development and deployment pipelines; ensure training materials and user interfaces meet accessibility requirements.Automate privacy and security gates in CI/CD pipelines to validate role assignments, audit logging, encryption, and vulnerability thresholds prior to promotion.Develop incident response and breach notification playbooks aligned to legislative timelines and HIC responsibilities; coordinate forensic evidence preservation and regulatory reporting.Maintain configuration and change control for security artifacts, manage security exceptions, and chair change/security review boards for system changes.Deliver stakeholder briefings, training, and documentation (runbooks, SOPs, technical standards) to operational teams and business owners; lead knowledge transferand handover activities.If this prospect matches your experience and career goals, please share your most updated resume for consideration.As a certified minority-owned business, Pride Global and its affiliates - including Russell Tobin, Pride Health, and Pride Now - are committed to creating a diverse environment and are proud to be an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, gender, gender identity or expression, sexual orientation, national origin, genetics, pregnancy, disability, age, veteran status, or other characteristics.Russell Tobin is a leading minority-owned professional and technical recruitment and staffing advisory organization. We are comprised of specialized practices focusing on a variety of skill sets and industries. Having a depth and breadth of industry expertise, our subject matter experts are able to provide tailored and swift sourcing solutions to fulfill client hiring needs. In other words, we connect top talent with companies. We are the staffing arm of the Pride Global network, a minority-owned integrated human capital solutions firm, with additional offerings in vendor management, payroll programs, and business process optimization.#RTA

📌 Security Specialist - Threat Risk Assessment - Senior - C$90 - C$100 An Hour (Toronto)
🏢 Russell Tobin
📍 Toronto

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: security specialist - threat risk assessment - senior - c$90 - c$100 an hour (toronto) / toronto