02 Sep
|
COFOMO
|
Montreal
Here is a brief overview of the tasks and responsibilities:
- Support projects in the definition and integration of security requirements;
- Participate in architecture workshops and solution design reviews;
- Analyze functional, application, technological and cloud architectures from a security perspective;
- Identify threats, vulnerabilities, risk scenarios, and impacts associated with proposed solutions;
- Recommend appropriate security controls based on context and risk level;
- Produce opinions, recommendations, analyses and deliverables related to the security architecture;
- Advise teams in the choice and implementation of security mechanisms;
- Collaborate with security governance advisors to ensure consistent application of security policies, standards and frameworks;
- Participate in the handling of deviations and residual risks and document associated recommendations;
- Provide an advisory function to project managers, technical specialists, analysts and product/service managers;
- Contribute to the improvement of the organization's security patterns, standards, architecture patterns, and practices;
- Participate in pre-release security reviews when required.
The profile we are looking for is as follows:
- Have a minimum of ten (10) years of relevant experience in computer security;
- Have significant experience in security architecture consulting or equivalent functions;
- Be able to perform security risk analyses and identify appropriate mitigation measures;
- Be able to analyze solution architectures and make recommendations for required security controls;
- Have experience in developing or revising security architecture guidelines and recommendations;
- security folders;
- risk analysis;
- security requirements;
- of recommendations and advisories;
- derogations or risk acceptances;
- Be able to translate governance guidance, policies and security standards into technical requirements applicable to projects;
- Experience in hybrid environments including: SaaS services;
- Microsoft Azure;
- Microsoft Windows Server environments ;
- Oracle Linux or enterprise Linux environments;
- Microsoft SQL Server;
- On-premise infrastructures and applications;
- Have a good understanding of identity and access control architectures, including authentication, authorization, least privilege, privileged accounts, and identity federation;
- Have a valuable understanding of the security issues specific to cloud environments: identity management, segmentation, network exposure, encryption, logging, secret management and shared responsibilities;
- Be able to evaluate the security of SaaS solutions and contribute to vendor and cloud service evaluations;
- Work jointly with teams responsible for enterprise architecture, infrastructure, networking, development, operations, and security governance;
- Be able to identify discrepancies between a proposed solution and the organization's security requirements and propose compensatory measures when required.
📌 IT Security Advisor (Senior) (Montreal)
🏢 COFOMO
📍 Montreal