Threat Risk Assessment (TRA) Specialist / Penetration Testing (PT) Specialist - Senior
SereneAid
Threat Risk Assessment (TRA) Specialist / Penetration Testing (PT) Specialist – Senior
Client: Government of Nova Scotia – Cyber Security & Digital Solutions (CSDS)
Project: Land Modernization Initiative (LMI)
Location: Halifax, Nova Scotia (Remote with optional onsite work)
Contract Duration: July 20, 2026 – May 31, 2027
Engagement Type: Competitive-Sourced
Work Arrangement: Remote (with occasional collaboration with CSDS stakeholders)
Project Overview
The Government of Nova Scotia is seeking experienced cybersecurity professionals to support the Land Modernization Initiative (LMI), a major transformation program modernizing the Province’s Land Registry services.
The selected consultants will work closely with the CSDS/LMI Technical Manager, Cyber Security and Risk Management (CSRM) team, and business stakeholders to conduct:
- Threat Risk Assessments (TRA)
- Penetration Testing (PT)
- Security risk analysis
- Vulnerability assessments
- Security recommendations and remediation guidance
The initial engagement focuses on the MVS 1.0 release, with potential future work supporting releases 1.1, 1.2, and 1.3.
Requirements
Key Responsibilities
Threat Risk Assessment (TRA)
Scope
- Identify and document security threats, vulnerabilities, and risks across the Nova Scotia Land Registry ecosystem.
- Assess people, processes, technologies, communications, and information assets.
- Evaluate likelihood and business impact of identified risks.
- Recommend mitigation strategies and security controls.
- Perform assessments using the NIST SP 800-53 Revision 5 High Baseline framework.
- Review security certifications and reports including:
- ISO/IEC 27001
- ISO/IEC 42001
- SOC 2 Type II
- PCI DSS
Activities
- Conduct workshops and stakeholder interviews.
- Review system architecture, integrations, and data flows.
- Analyze operational effectiveness of security controls.
- Assess compliance across applicable NIST control families.
- Document threat actors, attack vectors, vulnerabilities, and risk treatments.
- Produce executive and technical reports.
- Present findings to senior leadership and project stakeholders.
Penetration Testing (PT)
Scope
Conduct penetration testing against:
- Web Applications
- APIs
- Cloud Environments
- Networks
- Mobile Applications
- Endpoints
Testing Methodologies
- White Box Testing
- Grey Box Testing
- Black Box Testing
Activities
- Execute penetration testing using industry best practices.
- Identify, validate, and document vulnerabilities.
- Analyze prior security testing results.
- Conduct remediation verification and retesting.
- Produce executive and technical reports.
- Immediately escalate Critical vulnerabilities using CVSS standards.
- Participate in ongoing security assessments and risk management activities.
Required Deliverables
Threat Risk Assessment Deliverables
- Draft TRA Report
- Final TRA Report
- Completed TRA Checklist
- Risk Response Form
- Executive Presentation
Penetration Testing Deliverables
- Final Penetration Testing Report
- Executive Presentation
- Remediation Validation / Retest Results
Mandatory Qualifications (Required)
Candidates who do not meet the following requirements should not be submitted.
Threat Risk Assessment Requirements
Mandatory Experience
- Minimum 3 years of experience conducting Threat Risk Assessments (TRAs) on digital systems.
- At least one proposed resource must have completed two (2) or more TRAs on digital systems within the last three (3) years .
- Experience conducting TRAs within Canadian public sector environments.
- Experience working with:
- NIST SP 800-53
- ISO/IEC 27001
- ISO/IEC 42001
- SOC 2 Type II
- PCI DSS
- Experience assessing:
- Cloud environments (AWS, Azure)
- Network infrastructure
- Enterprise applications
- Technology platforms
- Ability to work with business, security, and technical teams.
Mandatory Documentation
- Criminal Record Check completed within the last six (6) months.
Penetration Testing Requirements
Mandatory Experience
- Minimum 3 years of experience conducting penetration testing.
- At least one proposed resource must have completed two (2) or more penetration tests within the last twelve (12) months .
- Experience conducting penetration testing in Canadian public sector organizations.
- Strong experience testing:
- Web applications
- APIs
- Cloud environments
- Networks
- Enterprise systems
Mandatory Certifications
Tier 1 Certification (Required)
At least one proposed resource must hold one of the following:
- OSCP (Offensive Security Certified Professional)
- CREST CRT (Registered Penetration Tester)
Tier 2 Certification (Required)
At least one proposed resource should hold one of the following:
- CEH Master
- GPEN
- CompTIA PenTest+
Mandatory Documentation
- Criminal Record Check completed within the last six (6) months.
Preferred Qualifications
The following are considered strong assets:
Security Certifications
- CISSP
- CISM
- CRISC
- OSCP
- CREST CRT
- CEH Master
- GPEN
- CompTIA PenTest+
Government Experience
- Previous experience performing Threat Risk Assessments for Canadian government organizations.
- Previous experience conducting Penetration Testing for Canadian government organizations.
- Direct experience supporting the Government of Nova Scotia.
- Familiarity with Government of Nova Scotia cybersecurity standards, risk frameworks, and governance processes.
Technical Skills
Candidates should demonstrate expertise in:
- Threat Risk Assessment Methodologies
- Penetration Testing Methodologies
- NIST SP 800-53 Rev. 5
- ISO/IEC 27001
- ISO/IEC 42001
- SOC 2 Type II
- PCI DSS
- Cyber Risk Management
- Vulnerability Assessment
- Security Architecture Review
- Risk Analysis and Treatment Planning
- Security Control Assessment
- Cloud Security (AWS / Azure)
- Application Security
- Network Security
- Security Reporting and Executive Presentations
- CVSS Scoring Framework
Evaluation Highlights
Candidates and vendors will be evaluated based on:
- TRA experience and expertise
- Penetration testing experience
- NIST and security framework knowledge
- Tier 1 and Tier 2 security certifications
- Public sector cybersecurity experience
- Government of Nova Scotia experience
- Client references
- Pricing competitiveness
This opportunity is ideal for senior cybersecurity consultants with proven expertise in both Threat Risk Assessments and Penetration Testing within government and highly regulated environments. The successful team will play a critical role in securing one of Nova Scotia's most significant digital modernization initiatives.
$80.46k - $98.34k per year
...Senior Test Specialist, Mechanical or Electrical (Permanent) Halifax, NS Expected Salary: $80,458 to $98,337 To determine final salary, Babcock... ...What You Do Here Matters In a complex world marked by the threat of war, natural disasters, and geopolitical instability,...SeniorRiskPermanent employmentFor contractorsInternshipWork at office- ...service, workflow efficiencies, and professional clinical services (disease state management, medication reviews and adherence, health risk assessments, injections/vaccines etc.) Provide patient counselling and education for new therapy to patients/caregivers while tailoring to...RiskPts cardPart timeInternship
$3929.22 - $4911.52 per week
...Director, Financial Advisory Services, the Senior Risk & Compliance Advisor provides expert... ...development, implementation, and ongoing assessment of internal control frameworks (ICFR), including... ...enforcement mechanisms. Identify and assess financial and compliance risks and...SeniorRiskLong term contractPermanent employmentFull timeTemporary workInternshipWork at office- ...Halifax is looking for a strong Treasury specialist: Key Responsibilities Key Responsibilities... ...and areas for improvement to reduce risk and increase productivity •Support team... ...instructions spreadsheets, reviewing/testing bank access in banking platform, sending...SeniorRiskFull timeWork at office
- ...that encourages employees to collaborate and learn from each other, completely free of barriers. Your role: As a Senior Software Developer in Test (SDET), you will be part of a small, highly focused team responsible for delivery of highly scalable and robust services...SeniorFull timeContract work
- ...supplies, cleaning Drug order creation and receiving Schedule professional clinical services (i.e. medication reviews, health risk assessments, disease state managements etc.) BTC management Administrative Duties: cycle counts, narcotic counts, return to stocks, TML’...RiskPts cardPart timeInternshipFlexible hours
- ...any stage of this process. We may use Artificial Intelligence (AI) tools to support efficiencies in the candidate screening, assessment, and recruitment processes. These AI tools do not make hiring decisions on behalf of the Company, these decisions are made by our Hiring...Pts cardPart timeInternship
- Job Responsibility: The Cook is responsible for preparing and cooking a variety of dishes, ensuring that the food is of high quality, and following proper food-handling practices while maintaining a clean and organized kitchen. Objective: Ensure the provision of high-quality...Pts cardPart time
- Lawtons Home Health Care Department strives to provide the best possible service to all of our customers who are in need of various medical devises and assistance in a fast-paced retail envrioment. From Bracing to Mobility Devises; Ostomy Care to Compression Garmetns, this ...Pts cardPart timeNight shiftWeekend work
- ...As an Accuracy Control Specialist, you will play a key role in ensuring... ...identify and mitigate dimensional risks, drive continuous improvement,... ...and measurement results to assess dimensional performance,... ..., and ensuring Inspection and Test Plan (ITP) tolerances are achieved...RiskPermanent employmentFull timeTemporary workInternshipWork at office
$5000 per month
...the future of care—together. Here’s what you can expect from our recruitment process: Step 1: Connect with Our Talent Acquisition Specialist: Your journey begins with a personalized phone conversation. You’ll learn about Lifemark’s vision for the future of healthcare in...Pts cardPermanent employmentFull timeLocal areaRelocationMonday to fridayFlexible hours$81.13k - $141.24k per year
...now. We are currently seeking a Cyber Risk Consultant - Financial Services - Remote to... ...Toronto, Nova Scotia (CA-NS), Canada (CA). Senior Cyber Risk Consultant – Financial Services... ..., cybersecurity, and business leaders to assess cyber risks across new and existing...SeniorRiskLong term contractTemporary workWork at officeRemote workFlexible hours- ...for this position. This posting is for an existing vacancy. The Company uses artificial intelligence for the purpose of screening, assessing and/or selecting applicants for this position. / L’expérience et les connaissances d’un candidat ainsi que la région géographique dans...Pts cardHourly payPermanent employmentTemporary workPart timeInternshipNight shiftWeekend workDay shiftAfternoon shift
- ...ACCOUNTABILITIES CUSTOMER Use expert knowledge to handle complex, high risk claims that typically take over a year to resolve. Maybe... ...issues, trends, and evolving regulatory requirements and assess potential impacts Maintain a culture of risk management and control...RiskFull timeWork from home
- ...the Commissioning Manager, the Senior Commissioning Technologist is responsible for commissioning, testing and maintaining primary and secondary... ...and interpreting prints, risk management strategies and promoting... ...switches, breakers, CT’s and PT’s, NGR, and Capbank...SeniorRiskPts cardWeekly payLong term contractFull timeWork at officeTrial period
- ...Who We Are PLATO is Canada’s largest Indigenous-owned software testing and technology services company. For nearly 30 years, our expert... ...teamwork, and making an impact. Position Summary The Functional Test Analyst is responsible for ensuring the quality, reliability, and...Internship
$72.87k - $85.48k per year
...Opportunity The Opportunity The Procurement Specialist plays a critical role in leading and... ...procurement commercial and reputational risks. The role contributes to strengthening... ...Management & Compliance Identify and assess procurement commercial and reputational...RiskFull timeContract work$65k - $125k per year
Quality Engineering Lead (ETL/UI Testing) Position Description CGI is seeking an experienced... ...Development Lifecycle (SDLC), driving test strategy, automation, and quality... ...recruitment team, AI tools may be used to help assess applications though they never replace human...Permanent employmentFull timeWork at office- ...Director of CIOOS, the AI Innovation Specialist plays a key role in advancing... ...policy development, risk management, and ethical AI use... ...LLMOps practices (versioning, testing, monitoring). ~ Strong experience... ...LLMOps (gestion des versions, tests, surveillance). Solide...RiskDaily paidPermanent employmentFull timeApprenticeshipSummer workRemote workMonday to friday
$60k - $65k per year
...to live safely and independently. Our certified specialists provide client-centered rehabilitation, mobility... ...Responsibilities Performs Functional Low Vision Assessments, uses functional vision evaluation instruments to assess visual acuity, visual fields, contrast...Permanent employmentFull timeApprenticeshipFlexible hours$60k - $120k per year
Data Engineering Specialist Position Description We are seeking an experienced Data Engineer... ...unit, integration, and automated testing to ensure solution quality. • Produce technical... ...team, AI tools may be used to help assess applications though they never replace human...$2805.63 - $3410.48 per week
...Category Manager the Procurement Specialist supports strategic sourcing... ...diplomatic advice and guidance to senior management. Able to... ...identify, manage, and reduce risks or disputes, including those that... ...in Procurement We will assess these qualifications and competencies...SeniorRiskLong term contractFull timeContract workTemporary workCasual workInternshipWork at officeRemote workFlexible hours$75k - $145k per year
Senior AI Security Cloud Architect Position Description CGI is... ..., delivery teams, security specialists, and client executives, the Senior... ...security controls, conduct threat modeling and security reviews,... ...security architecture reviews, risk assessments, and technical governance...SeniorRisk- ..., Evaluation & Feedback Validate Learning: Conduct tests, practical simulations, and assessments to ensure training concepts are fully understood. Performance... ....ca Mentioning that the position is: Training Specialist Randstad is Canada's largest employment agency, and...Permanent employmentWorldwide
$55k - $110k per year
Power Platform Specialist- AWS Position Description We are seeking an experienced Senior Technical Specialist / Technical Lead with strong expertise in Power Apps, Power... ...recruitment team, AI tools may be used to help assess applications though they never replace human...Senior$57.51k - $86.26k per year
...Junior Configuration Management Specialist (Permanent) Halifax, NS Expected... ...a complex world marked by the threat of war, natural disasters, and... ...report resolutions using Clew – Risk and Assurance Software and completing Impact Assessments (IA’s). The ideal candidate...RiskPermanent employmentInternshipWork at office- ...Senior Human Factors Specialist Lloyd’s Register Location: Global – hybrid/remote options available... ...Human Factors engineering or ergonomic assessments, Human Reliability Assessments (HRA),... ...user research, interviews, usability testing and data analysis. Skilled in...SeniorLong term contractFull timeInternshipImmediate startRemote work
- ...Scotia Closing Date: August 13th, 2026 The Health & Wellness Specialist is responsible for providing disability case management,... ...work planning, wellness programming, health promotion and health assessments. Reporting to the Health & Wellness Manager, you will liaise...Full timeTemporary workRemote workFlexible hours
- ...to technical expert others rely on for answers? If so, the Senior Broker & Technical Specialist opportunity within Aon’s Financial Services Group could be... ...Day-to-day Will Look Like Analyze clients’ specific risk exposures to establish and implement tailored insurance program...SeniorRiskContract workWork at office1 day per week
$22.5 per hour
...excellence. As we scale rapidly, we are looking for a Vehicle Delivery Specialist to be the face of our company! Since our entire car-buying... ...Need a sharp eye for detail as you inspect vehicles, carefully assessing both cosmetic and mechanical aspects to identify potential...Hourly payPermanent employmentFull timeInternshipLong distance
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Threat Risk Assessment (TRA) Specialist / Penetration Testing (PT) Specialist - Senior. Be the first to apply!
- country risk analyst Halifax, NS
- market risk analyst Halifax, NS
- risk management analyst Halifax, NS
- risk management consultant Halifax, NS
- risk analyst Halifax, NS
- tester Halifax, NS
- test automation specialist Halifax, NS
- credit risk Halifax, NS
- risk and insurance manager Halifax, NS
- sénior service a la clientèle Halifax, NS
