31 Aug
|
COFOMO
|
Montreal
Here is a brief overview of the tasks and responsibilities:Support projects in the definition and integration of security requirements; Participate in architecture workshops and solution design reviews; Analyze functional, application, technological and cloud architectures from a security perspective; Identify threats, vulnerabilities, risk scenarios, and impacts associated with proposed solutions; Recommend appropriate security controls based on context and risk level; Produce opinions, recommendations, analyses and deliverables related to the security architecture; Advise teams inthe choice and implementation of security mechanisms; Collaborate with security governance advisors to ensure consistent application of security policies, standards and frameworks; Participate in the handling of deviations and residual risks and document associated recommendations; Provide an advisory function to project managers, technical specialists, analysts and product/service managers; Contribute to the improvement of the organization's security patterns, standards, architecture patterns, and practices; Participate in pre-release security reviews when required.The profile we are looking for is as follows:Have a minimum of ten (10)
years of relevant experience in computer security; Have significant experience in security architecture consulting or equivalent functions; Be able to perform security risk analyses and identify appropriate mitigation measures; Be able to analyze solution architectures and make recommendations for required security controls; Have experiencein developing or revising security architecture guidelines and recommendations; security folders; risk analysis;security requirements; of recommendations and advisories; derogations or risk acceptances; Be able to translate governance guidance, policies and security standards into technical requirements applicable to projects; Experience in hybrid environments including: SaaS services; Microsoft Azure;Microsoft Windows Server environments ; Oracle Linux orenterprise Linux environments; Microsoft SQL Server; On-premise infrastructures and applications; Have a valuable understanding of identity and access control architectures, including authentication, authorization, least privilege, privileged accounts, and identity federation; Have a good understanding of the security issues specific to cloud environments: identity management, segmentation, network exposure, encryption, logging, secret management and shared responsibilities; Be able to evaluate the security of SaaS solutions and contribute to vendor and cloud service evaluations; Work jointly with teams responsible for enterprise architecture, infrastructure, networking, development, operations, and security governance; Be able to identify discrepancies between a proposed solution and the organization's security requirements and propose compensatory measures when required.
📌 It Security Advisor (Senior) (Montreal)
🏢 COFOMO
📍 Montreal