RQ00742 - Security Specialist - Senior
Temporary
Maarut
Key activities included:
- Scoping the assessment in collaboration with business and technical stakeholders.
- Conducting structured risk analysis using recognized frameworks such as ISO 31000, NIST RMF, or FAIR.
- Performing threat modeling (e.g., STRIDE, MITRE ATT&CK) to map potential attack vectors and security gaps.
- Reviewing system architecture, data flows, and existing controls.
- Assessing compliance with relevant regulatory and organizational security requirements.
- Documenting findings in a detailed TRA report, including risk ratings and actionable mitigation recommendations.
- Presenting results to executive leadership and supporting integration of risk treatments into the broader security strategy.
Must haves:
- In-depth knowledge of risk management frameworks (e.g., ISO 31000, NIST RMF – Risk Management Framework) and threat modelling methodologies (e.g., STRIDE, DREAD).
- Expertise in identifying, evaluating, and prioritizing threats and vulnerabilities across physical, cyber, and operational domains.
- Strong analytical skills to assess potential impacts and likelihoods of various threat scenarios.
- Proficiency risk assessment matrices
- Excellent communication and reporting abilities to effectively present findings and risk mitigation strategies to both technical teams and executive stakeholders.
- Familiarity with legal, regulatory, and compliance requirements, ensuring assessments align with organizational and industry standards (e.g., PHIPAA - Personal Health Information Protection Act).
- Proactive mindset and situational awareness to anticipate and adapt to emerging threats in a dynamic risk environment.
Responsibilities:
- Drive end-to-end Threat Risk Assessment (TRA) initiatives across systems, processes, and assets.
- Develop and apply threat models to assess organizational security posture.
- Collaborate with stakeholders to align assessments with business objectives and risk tolerance.
- Analyze vulnerabilities and assess threats to determine likelihood and potential impact.
- Produce detailed TRA reports, documenting findings, recommendations, and risk ratings.
- Maintain risk registers and track remediation efforts.
- Propose actionable mitigation strategies based on assessment outcomes.
- Ensure alignment with:
- Regulatory requirements
- Industry standards
- Organizational security policies
- Regulatory requirements
- Communicate findings effectively to both technical teams and executive leadership.
- Support audit and compliance activities as needed.
- Contribute to the continuous improvement of risk management frameworks and methodologies.
- Stay informed on emerging threats, vulnerabilities, and security best practices.
Desired Skills:
- Demonstrated expertise in enterprise risk analysis, with a solid background in applying risk management frameworks such as ISO 31000, FAIR (Factor Analysis of Information Risk), and NIST RMF to identify, evaluate, and prioritize organizational security risks.
- Hands-on experience conducting structured threat analysis, utilizing methodologies like STRIDE, PASTA (Process for Attack Simulation and Threat Analysis), and MITRE ATT&CK. Familiarity with creating threat models, mapping attack surfaces, and visualizing system flows to uncover security weaknesses.
- Strong command of cybersecurity governance practices, including the development and enforcement of information security policies and standards. Practical understanding of how to align internal controls with recognized frameworks like ISO 27001, NIST CSF, and the CIS Critical Security Controls.
- Proven ability to translate technical risk findings into clear business language, producing high-quality documentation such as executive summaries, detailed risk reports, and stakeholder presentations. Skilled in managing communication between technical teams and leadership to drive informed decision-making.
Requirements
Required Skills:
- Risk Management & Assessment – 5–7 years - Proven experience in conducting threat risk assessments using frameworks like ISO 31000, NIST RMF, or FAIR.
- Threat Modeling – 3–5 years - Practical knowledge of threat modeling techniques (e.g., STRIDE, PASTA, MITRE ATT&CK), including development of data flow diagrams and attack vectors.
- Information Security Governance – 5+ years-Strong understanding of security policies, standards, and controls aligned with ISO 27001, NIST CSF, and CIS Controls.
- Communication & Reporting – 5+ years-skilled in writing technical and executive-level reports, risk registers, and presenting to stakeholders and leadership.
Evaluation Criteria:
- Threat Modeling: - 5-7 years of hands-on experience with threat modeling techniques such as STRIDE, PASTA, and MITRE ATT&CK, including the development of data flow diagrams and identification of attack vectors to inform secure design decisions and guide risk mitigation strategies across systems and applications. 20 Points
- TRA Report: - 5–7 years of experience conducting comprehensive threat and risk assessments using frameworks such as ISO 31000, NIST RMF, and FAIR, with a strong focus on identifying vulnerabilities, analyzing potential impacts, and delivering actionable risk mitigation strategies to stakeholders. 20 Points
- Gap Analysis: - 5–7 years of extensive experience with security controls and architecture, with a strong ability to identify gaps between the current security posture and industry standards, best practices, and regulatory requirements. 20 Points
- Team Player: - Demonstrates strong collaboration skills by working effectively with colleagues across functions, openly sharing information, supporting others to achieve shared goals, and contributing to a positive, respectful team environment. 30 Points
- Presentation Deck: - Over 5 years of experience authoring technical and executive-level reports, developing risk registers, and delivering presentations to stakeholders and senior leadership. 10 Points
Deliverables:
- TRA (Threat, Risk Assessment) Report : - A comprehensive document outlining identified threats, vulnerabilities, risks, and proposed mitigation strategies, tailored to the organization’s context.
- Risk Register: - A structured log of all identified risks, including severity, likelihood, risk rating, responsible owners, and mitigation actions.
- Threat Modeling Diagrams : - Visual representations of systems, data flows, and potential threat vectors using models like STRIDE or attack trees.
- Risk Assessment Matrix: - A visual tool mapping the likelihood and impact of risks to prioritize them effectively.
- Asset Inventory & Classification: - A list of assets in scope (e.g., systems, applications, data) categorized by value and sensitivity.
- Vulnerability Assessment Results: - A summary of technical vulnerabilities discovered during the assessment, often with outputs from tools like Nessus or OpenVAS.
- Gap Analysis: - Identification of discrepancies between current security posture and industry standards, best practices, or regulatory requirements.
- Mitigation & Remediation Plan: - Detailed action plans with timelines and responsibilities for reducing identified risks to acceptable levels.
- Executive Summary: - A high-level summary tailored for senior leadership, focusing on key findings, business impact, and strategic recommendations.
- Compliance Mapping: - Documentation showing how risks and controls align with regulatory or standards frameworks (e.g., NIST, ISO 27001, SOC 2).
- Presentation Deck: - Slide-based briefing to communicate findings, risks, and recommendations to stakeholders in a clear and digestible format.
Must Haves:
- Risk Management & Assessment – 5–7 years - Proven experience in conducting threat risk assessments using frameworks like ISO 31000, NIST RMF, or FAIR.
- Threat Modeling – 3–5 years - Practical knowledge of threat modeling techniques (e.g., STRIDE, PASTA, MITRE ATT&CK), including development of data flow diagrams and attack vectors.
- Information Security Governance – 5+ years-Strong understanding of security policies, standards, and controls aligned with ISO 27001, NIST CSF, and CIS Controls.
- Communication & Reporting – 5+ years-skilled in writing technical and executive-level reports, risk registers, and presenting to stakeholders and leadership.
Vacancy posted 8 hours ago
Similar jobs that could be interesting for youBased on the RQ00742 - Security Specialist - Senior in Toronto, ON vacancy
- We are seeking an experienced Senior Security Specialist to drive end-to-end Threat Risk Assessment (TRA) initiatives to evaluate and elevate organizational security posture across information systems, applications, infrastructure, and business processes. In this role, you will...SeniorContract workFlexible hours
- ...belong on #TeamBell. Summary We are seeking a Senior Security Operations Specialist II with hands-on experience in network security... ...successful candidate will provide technical leadership, support secure implementation of new technologies, and act as an...SeniorFull timeWork at office3 days per week
- ...possible, you belong on #TeamBell. Summary We are seeking a Senior Security Operations Specialist II with hands-on experience in network security... ...successful candidate will provide technical leadership, support secure implementation of new technologies, and act as an...SeniorFull timeWork at office3 days per week
- ...Opportunity: We’re looking to fill an opening with an experienced Security GRC Specialist to join our growing Security GRC team. Reporting to the... ...assurance programs and reporting appropriate metrics to the senior leadership. As one aviso: ~ We Care – You do the...SeniorFull timeInternship
- ...This is a remote position. Senior Cyber Security Specialist-Offensive Security Location: Remote (Canada) Experience: 10+ Years... ...required Work with engineering teams on remediation and secure SDLC Provide clear technical risk analysis and...SeniorFull timeContract workRemote work
$75.05 - $85.77 per hour
Our client, is seeking a high-caliber Security Specialist IV to join their Global Security Architecture... ...and Infrastructure division. In this senior technical position, you will be... ...translate functional business rules into secure, bulletproof firewall configurations....SeniorLong term contractContract workWork at officeImmediate startRemote workMonday to friday2 days per week- ...TEHORA est présentement à la recherche d’ un(e) architecte sécurité senior ayant une solide expérience en architecture de sécurité, en gestion des risques et en exigences non fonctionnelles. La personne retenue contribuera à l’intégration des considérations de sécurité dans...SeniorHourly payFull timeContract workApprenticeshipRemote workFlexible hours
- ...Senior Security Engineer Location : Toronto, On-Site Reports to: Head of Security The Role This is an early, high-ownership security... ...response (EDR) across the device fleet Design and maintain secure MDM baselines — configuration profiles and policies for all...SeniorFull time
- ...TEHORA est présentement à la recherche d’un(e) Analyste en sécurité opérationnelle sénior Sans être exhaustifs, voici les services et livrables que devra fournir la personne retenue : Surveiller les incidents de sécurité; Analyser les vulnérabilités; Mettre en...SeniorHourly payFull timeContract workApprenticeshipRemote workFlexible hours
$60k - $110k per year
Security Monitoring and Response Specialist Position Description Location: This role can be located at any CGI office in Canada The Security Monitoring... .... Spécialiste en surveillance et intervention de sécurité Job Description Lieu : Ce poste peut être basé...ApprenticeshipWork at office- ...We are hiring a Senior Manager, Information Security, Risk and Compliance on behalf of a well-established organization in Toronto. As the Senior Manager... ...supplemented by external experts. Bring in external specialists for audit peaks, point-in-time assessments, or...SeniorPermanent employmentManual labor
$122.74k - $141.95k per year
...team We’re looking for a new teammate to join us on the journey of keeping HelloFresh a trusted name - someone with a passion for security and appetite for new challenges. Security Engineers work in a variety of ways to constantly iterate and improve HelloFresh’s security...SeniorWork at officeRemote workWork from homeFlexible hours2 days per week3 days per week$63.85 - $70.51 per hour
...highly technical, expert-level Network LAN/Security Specialist to design and execute Data Center Server... ...Water and Wastewater sectors. As a senior technical authority, you will manage network equipment replacement projects, secure critical infrastructure using advanced firewall...SeniorRemplacementContract workRemote work$78.4k - $109.8k per year
...We are looking for a Senior Total Rewards Specialist to lead the administration, implementation, and continuous improvement of global Benefits and... ...Basic knowledge in immigration, tax, relocation and social security policies and procedures Accountability: holds self and...SeniorLong term contractPermanent employmentTemporary workLocal areaRemote workRelocation- ...As a Senior Technician - Security Systems with Bosch Building Technologies, you will collaboratively review, understand, analyze, and implement installation blueprints and plans from Project Managers and Sales Teams to complete installations. This role requires the ability...SeniorContract workWork at officeFlexible hours
$75k - $85k per year
...team that's changing the game, XR is the place for you. Let’s shape the future together! The Opportunity The Senior Technical Support Specialist is a highly skilled, technically focused position that operates at the intersection of support, engineering, and automation...SeniorLong term contractFull timeInternshipLocal areaWorldwide- ...The Opportunity As a Senior Collections Specialist, you will manage client collections in a timely and effective manner while maintaining positive client relationships and working collaboratively with the partners, billing and financial management team. Responsibilities...SeniorPermanent employment
$88k - $121k per year
...Secure Every Identity, from AI to Human Identity is the key to unlocking the potential of AI. Okta secures AI by building... ...all in on this mission. If you are too, let's talk. The Senior Regional Marketing Specialist We are looking for a strategic and results-driven...SeniorLocal areaWorldwide$78 per hour
...Position: Senior SAP GRC Security Consultant (SAP S/4HANA, SAP Security, Identity Access Governance) Location: Hybrid (Greater Toronto Area... ...stakeholders, project managers, and technical teams to deliver secure SAP solutions Collaborate with Internal and External Audit...SeniorContract workFlexible hours2 days per week3 days per week$65.17 - $69.82 per hour
...RQ00689 - Int. Security Specialist 6-month contract (129 business days) - possible extension ONSITE 5 days - 777 Bay Street, Toronto, Ontario Must Haves: 5+ years of experience in the following: Develops and implements cyber security strategy...Contract work- ...requires many teams working collaboratively, such as Corporate Security & Responsibility, Corporate Communications, Human Resources, Procurement... ...given day are prepared by the Company with due consideration to seniority), to participate in a standby program and work overtime as...SeniorRemplacementFull timeFor contractorsWork at officeFlexible hoursShift workNight shiftAfternoon shift3 days per week
$106.71k - $177.84k per year
...Your opportunity: Under the general direction of the Associate Director, Receivables and General Accounting, the Senior Accounting Specialist performs a variety of complex analyses and interpretation of confidential data relating to benefits budgeting and forecasting...SeniorFull timeWork at office$137k - $189k per year
...We are hiring a Senior Software Engineer to join our Server Security team. The Server Security team is a development-focused group within MongoDB's core engineering... ...team builds features that enable database users to secure their data globally. You will work on critical...SeniorFull timeRemote workWorldwideFlexible hours- ...seeks to bring its global expertise in AI to transform companies around the world. Remote (US or Canada) Seeking a hands-on Senior Security Data Solution Architect with 7+ years of experience designing and implementing large-scale security data and analytics solutions...SeniorFull timeRemote work
$130k - $180k per year
...The Security Product Management team is vital in safeguarding customer trust and making data security a market differentiator that enables MongoDB to succeed in enterprise and regulated industries. Our team's scope is broad and critical, covering a range of features, including...SeniorFull timeInternshipWork at officeRemote workWorldwideFlexible hours$120k - $160k per year
...are proudly part of Benefact Group , are looking for a Senior Risk Control Specialist to join our Toronto office. As a Senior Risk Control... ...School, related fire protection programs, construction, security, etc.) A minimum of 7 years of related Risk Controls, Risk...SeniorRemplacementPermanent employmentWork at officeHome officeMonday to friday- ...about the role & team Hands-on infrastructure security role with real ownership and visible impact We’re looking for a senior infrastructure professional who enjoys solving... ...focus on implementation, remediation, and secure operations across Windows and Linux environments...SeniorFull timeManual laborFlexible hours
$85k - $105k per year
...About the Role As a Senior Adobe Martech Specialist, you'll be the ultimate subject matter expert in designing, configuring, and maximizing our clients' enterprise Adobe ecosystems. Working alongside strategists, designers, developers, and enterprise stakeholders, you will...SeniorWork from homeFlexible hours$70k - $80k per year
...About the Role As a Senior Digital Marketing Specialist, you’ll play a key role in leading and delivering creative and data-driven marketing initiatives that drive global awareness, engagement, and growth. Reporting to the Digital Brand team, you’ll lead a wide range of...SeniorWork from homeFlexible hours$70.8k - $95.8k per year
...organization, and each other. THE ROLE Reporting to the Manager, Complex Transactions, this is a fantastic opportunity for an experienced Senior Pension Services professional to join a team of high performing professionals to make a great impact. You will be involved in a...SeniorLong term contractFull timeInternshipWork at officeRemote workFlexible hours2 days per week
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to RQ00742 - Security Specialist - Senior. Be the first to apply!
Related searches
- conseiller santé sécurité Toronto, ON
- security analyst Toronto, ON
- physical security specialist Toronto, ON
- spécialiste en sécurité Toronto, ON
- spécialiste en sécurité informatique Toronto, ON
- security systems specialist Toronto, ON
- security operations specialist Toronto, ON
- physical security analyst Toronto, ON
- conseiller en sécurité financière Toronto, ON
- application security consultant Toronto, ON
