02 Sep
|
COFOMO
|
Montreal
Here is a brief overview of the tasks and responsibilities: Support projects in the definition and integration of security requirements; Participate in architecture workshops and solution design reviews; Analyze functional, application, technological and cloud architectures from a security perspective; Identify threats, vulnerabilities, risk scenarios, and impacts associated with proposed solutions; Recommend appropriate security controls based on context and risk level; Produce opinions, recommendations, analyses and deliverables related to the security architecture; Advise teams in the choice and implementation of security mechanisms; Collaborate with security governance advisors to ensure consistent application of security policies, standards and frameworks; Participate in the handling of deviations and residual risks and document associated recommendations; Provide an advisory function to project managers, technical specialists, analysts and product/service managers; Contribute to the improvement of the organization's security patterns, standards, architecture patterns, and practices; Participate in pre-release security reviews when required.
The profile we are looking for is as follows: Have a minimum of ten (10) years of relevant experience in computer security
• Have significant experience in security architecture consulting or equivalent functions
• Be able to perform security risk analyses and identify appropriate mitigation measures
• Be able to analyze solution architectures and make recommendations for required security controls
• Have experience in developing or revising security architecture guidelines and recommendations; security folders; risk analysis; security requirements; of recommendations and advisories; derogations or risk acceptances
• Be able to translate governance guidance, policies and security standards into technical requirements applicable to projects;
Experience in hybrid environments including: SaaS services
• Microsoft Azure
• Microsoft Windows Server environments
• Oracle Linux or enterprise Linux environments
• Microsoft SQL Server
• On-premise infrastructures and applications
• Have a valuable understanding of identity and access control architectures, including authentication, authorization, least privilege, privileged accounts, and identity federation
• Have a good understanding of the security issues specific to cloud environments: identity management, segmentation, network exposure, encryption, logging, secret management and shared responsibilities
• Be able to evaluate the security of SaaS solutions and contribute to vendor and cloud service evaluations
• Work jointly with teams responsible for enterprise architecture, infrastructure, networking, development, operations, and security governance
• Be able to identify discrepancies between a proposed solution and the organization's security requirements and propose compensatory measures when required.
📌 IT Security Advisor (Senior) (Montreal)
🏢 COFOMO
📍 Montreal