Security Advisor Specialist - Threat Modeling (Canada)

Security Advisor Specialist - Threat Modeling (Canada)

03 Oct
|
Intact Financial
|
Canada

03 Oct

Intact Financial

Canada

Together, we help people, businesses, and society prosper in good times and be resilient in bad times. In return, we promise to provide support, opportunities and performance-led financial rewards at a workplace where you can shape the future, win as a team and grow with us. Versatile wellbeing, including telemedicine, Wellness account and much more Annual bonus the target (subject to personal and company performance):

Win As A Team , we share our success with employees through our annual bonus plan and Employee Share Purchase Plan (ESPP) – with Intact matching 50% of your net shares. Our pension offerings provide flexibility and long-term security for our employees beyond their careers. We are one of the few companies offering the opportunity to receive guaranteed income for life via our defined benefit pension plan.

Salary for the candidate will be determined taking into consideration a number of factors including: experience, skills, qualifications, anticipated contribution to role, internal equity, etc. Serve as the primary Security point of contact for technology initiatives, providing security guidance throughout the project lifecycle and formal sign-off before go-live.

Develop and validate threat-modeling supporting materials, such as: data flows, architecture diagrams, network diagrams and process flows. Identify critical assets, trust boundaries, entry points, and dependencies.

assign inherent and residual risk ratings; and translate findings into prioritized security requirements, control objectives, mitigations, and go-live acceptance criteria.

Support the completion of critical security activities, including penetration testing, SAST, DAST, secure code reviews, third-party risk assessments, vulnerability assessments, and other assurance activities to support technology readiness.

Collaborate with product, architecture, development, engineering, cloud, and risk teams to review designs and technical decisions, facilitate threat-modeling workshops, and embed security into DevSecOps and project governance processes.





Manage Security Findings in platforms such as JIRA, including ownership, remediation, escalation, compensating controls, risk acceptance, and closure. Provide ad hoc security advice and document recommendations and follow-up actions.

Use threat modeling to su pport the three lines of risk management by helping first-line teams manage security risks, informing second-line oversight, and supporting third-line system audits.

Use post-incident lessons learned and threat intelligence to enhance threat modeling accuracy and recommendations.

Lead improvement and scale the threat-modeling capability through reusable methodologies, templates, patterns, guidance, tooling, training, and self-service workshops.

Stay ahead of emerging technology and frameworks, particularly across AI and modern application architectures to effectively support security risks management.

Communicate complex technical risks, recommendations, and risk-based decisions clearly to technical and non-technical stakeholders.

Teach and mentor immediate team members on threat modeling, secure design, risk management, and security practices. Bachelor’s degree in Computer Science, Engineering, or a related field - or an equivalent combination of education and experience.

At least ten (10) years of experience in Information Technology, including a minimum of five (5) years in Information Security. Demonstrated experience in one or more of the following areas: application or cloud security, security architecture, threat modeling, risk assessment, threat intelligence, incident response, SOC or SIEM operations, vulnerability management, red teaming, or penetration testing.

Strong understanding of application,



infrastructure, network, and data security across multi-cloud environments, including AWS, Azure, and GCP.

Familiarity with vulnerability management and DevSecOps principles, including secure design and CI/CD security.

Experience with scripting and automation to support threat modeling, security assessments, evidence collection, risk analysis, and the integration of security practices into development and delivery workflows is an asset.

Experience using threat-modeling tools, such as Microsoft Threat Modeling Tool, IriusRisk, Threat Dragon, or internally developed tools, is an asset.

Experience using diagramming tools, such as draw.io, Lucidchart, or Visio, or creating code-based diagrams using tools such as PlantUML, is an asset.

For candidates located in Quebec, bilingualism is required considering the necessity to interact on a regular basis with English-speaking colleagues across the country

No Canadian work experience required however must be eligible to work in Canada #At Intact, our Value of respect is founded on seeing diversity as a strength. We encourage applications from individuals who are members of equity-deserving groups, including but not limited to women, Indigenous peoples, persons with disabilities, Black people, and members of the 2SLGBTQI+ community. As part of Intact’s commitment to reconciliation, we acknowledge that we work, meet and travel across the land currently called Canada, originally inhabited by First Nations, Metis and Inuit people.

We have policies to ensure equal access and participation for people with disabilities, including providing workplace adjustments (accommodations). A copy of applicable policies is available on request. Please note that Intact does not provide sponsorship or other support for immigration-related matters including but not limited to employer-specific closed work permits.

If you are an employee of Intact or belairdirect, please apply for this role on Internal Career Site.

📌 Security Advisor Specialist - Threat Modeling (Canada)
🏢 Intact Financial
📍 Canada

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: security advisor specialist - threat modeling (canada) / canada