RQ00671 - Security Specialist - Senior
Maarut Inc
The Security Specialist for Threat Risk Assessment, Threat Modelling, Vulnerability Assessment, Risk Identification will develop new workflows and contribute to the growth and maturity of the Security Risk Management and Information Security Office growth and maturity
Must haves:
- In-depth knowledge of risk management frameworks (e.g., ISO 31000, NIST RMF) and threat modelling methodologies (e.g., STRIDE, DREAD).
- Expertise in identifying, evaluating, and prioritizing threats and vulnerabilities across physical, cyber, and operational domains.
- Strong analytical skills to assess potential impacts and likelihoods of various threat scenarios.
- Proficiency risk assessment matrices
- Excellent communication and reporting abilities to effectively present findings and risk mitigation strategies to both technical teams and executive stakeholders.
- Familiarity with legal, regulatory, and compliance requirements, ensuring assessments align with organizational and industry standards (e.g., PHIPAA).
- Proactive mindset and situational awareness to anticipate and adapt to emerging threats in a dynamic risk environment.
Responsibilities:
The Senior Security Specialist will be responsible for conducting Threat Risk Assessments (TRA) plays a critical role in identifying, evaluating, and mitigating security risks across the organizationâs systems, processes, and assets. That includes participating in end-to-end risk assessment initiatives, developing and applying threat models, and working closely with stakeholders to understand business objectives and risk tolerance. The Senior Security Specialist will analyze vulnerabilities, assess potential threats, and determine the likelihood and impact of various risk scenarios, and will also be responsible for compiling detailed TRA reports, maintaining risk registers, and proposing actionable mitigation strategies and alignment with regulatory, industry, and organizational security standards, and effectively communicate findings to both technical teams and executive leadership. Additionally, the Security Specialist will contribute to the continuous improvement of risk management frameworks, support audit and compliance activities, and stay informed about emerging threats and security best practices.
Desired Skills:
- Risk Management & Assessment â 10â15 years
- Proven experience in conducting threat risk assessments using frameworks like ISO 31000, NIST RMF, or FAIR.
- Threat Modeling â 10â15 years
- Practical knowledge of threat modeling techniques (e.g., STRIDE, PASTA, MITRE ATT&CK), including development of data flow diagrams and attack vectors.
- Information Security Governance â 7+ years
- Strong understanding of security policies, standards, and controls aligned with ISO 27001, NIST CSF, and CIS Controls.
- Communication & Reporting â 10+ years
- Skilled in writing technical and executive-level reports, risk registers, and presenting to stakeholders and leadership.
Requirements
Rated Criteria:
- Threat Modeling Expertise 20 Points
- TRA Report: Demonstrated skills in TRA completions 20 Points
- Gap Analysis: Demonstrated skills in gap analysis 40 Points
- Communication Skills â both written and verbal. 20 Points
Deliverables:
- TRA Report : A comprehensive document outlining identified threats, vulnerabilities, risks, and proposed mitigation strategies, tailored to the organizationâs context.
- Risk Register: A structured log of all identified risks, including severity, likelihood, risk rating, responsible owners, and mitigation actions.
- Threat Modeling Diagrams: Visual representations of systems, data flows, and potential threat vectors using models like STRIDE or attack trees.
- Risk Assessment Matrix: A visual tool mapping the likelihood and impact of risks to prioritize them effectively.
- Asset Inventory & Classification: A list of assets in scope (e.g., systems, applications, data) categorized by value and sensitivity.
- Vulnerability Assessment Results : A summary of technical vulnerabilities discovered during the assessment, often with outputs from tools like Nessus or OpenVAS.
- Gap Analysis : Identification of discrepancies between current security posture and industry standards, best practices, or regulatory requirements.
- Mitigation & Remediation Plan : Detailed action plans with timelines and responsibilities for reducing identified risks to acceptable levels.
- Executive Summary: A high-level summary tailored for senior leadership, focusing on key findings, business impact, and strategic recommendations.
- Compliance Mapping: Documentation showing how risks and controls align with regulatory or standards frameworks (e.g., NIST, ISO 27001, SOC 2).
- Presentation Deck : Slide-based briefing to communicate findings, risks, and recommendations to stakeholders in a clear and digestible format.
Must Haves:
10+ years experience:
- In-depth knowledge of risk management frameworks (e.g., ISO 31000, NIST RMF) and threat modelling methodologies (e.g., STRIDE, DREAD).
- Expertise in identifying, evaluating, and prioritizing threats and vulnerabilities across physical, cyber, and operational domains.
- Strong analytical skills to assess potential impacts and likelihoods of various threat scenarios.
- Proficiency risk assessment matrices
- Excellent communication and reporting abilities to effectively present findings and risk mitigation strategies to both technical teams and executive stakeholders.
- Familiarity with legal, regulatory, and compliance requirements, ensuring assessments align with organizational and industry standards (e.g., PHIPAA).
- Proactive mindset and situational awareness to anticipate and adapt to emerging threats in a dynamic risk environment.
$90 per hour
...Job Responsibility: This role will require contractors to come onsite for occasional meetings.This is a new security modernization project from OPS. They will be reviewing vendor security.They will need to have experience reviewing SOC 2 Type 2 documentation and writing recommendations...SeniorHourly payFull timeFor contractorsFixed term contractRelocationMonday to friday- ...ATT&CK) to map potential attack vectors and security gaps. Reviewing system architecture,... ...identification of attack vectors to inform secure design decisions and guide risk mitigation... ...delivering presentations to stakeholders and senior leadership. 10 Points Deliverables:...SeniorFull time
- ...The Sr. Security Specialist will support and deliver on multiple initiatives related to Security Governance, Risk and Compliance and Cyber... ...risk registers, and delivering presentations to stakeholders and senior leadership. 20 points Requirements Deliverables include...SeniorFull time
$115 per hour
...are looking for contract S enior Cyber Security Specialist Duration : 12 month Experience required... ...incident response, threat intelligence, secure architecture, and other security... ...stakeholders ranging from technical teams to senior executives within the organization....SeniorHourly payFull timeContract workFor contractorsFixed term contractRelocationShift work- ...possible, you belong on #TeamBell. Summary We are seeking a Senior Security Operations Specialist II with hands-on experience in network security... ...successful candidate will provide technical leadership, support secure implementation of new technologies, and act as an...SeniorFull timeWork at office3 days per week
- ...belong on #TeamBell. Summary We are seeking a Senior Security Operations Specialist II with hands-on experience in network security... ...successful candidate will provide technical leadership, support secure implementation of new technologies, and act as an...SeniorFull timeWork at office3 days per week
- ...Opportunity: We’re looking to fill an opening with an experienced Security GRC Specialist to join our growing Security GRC team. Reporting to the... ...assurance programs and reporting appropriate metrics to the senior leadership. As one aviso: ~ We Care – You do the...SeniorFull timeInternship
- ...Manage and maintain Information Security Management System (ISMS) design and implementation of new information security... ...":1,"value":"M4C"}],"headerName":"RQ10341 \- Security Specialist \- Threat Risk Assessment \- Senior","widgetId":"383123000000072311","isJobBoard":"false",...SeniorContract workFlexible hours
$70 - $90 per hour
...Contract Compensation: $70–$90/hour Location: Remote Role Responsibilities Analyze and review content for security vulnerabilities with a focus on pattern recognition and classification in an AI context. Apply expertise in systems...Full timeContract workSummer workRemote workFlexible hours$19.5 per hour
...EVENT SECURITY SPECIALIST Are you passionate about Safety & Security and seeking opportunity to join a team of Security Specialist? A.S.P. Incorporated has provided security and customer service solutions for over 20 years to Canadian clients. We employ more than...Hourly payFull timeFlexible hoursShift workNight shiftWeekend workAfternoon shift$20 - $21 per hour
...RESPITE SECURITY SPECIALIST Are you passionate about Safety & Security and seeking opportunity to join a team of Security Specialist? A.... ...Respite Security Protection Specialist takes responsibility for secure and safe at the Respite Centers in Toronto. What you will do:...Hourly payFull time- ...team today! Position Summary: Reporting to the Project Manager, you will have the opportunity to execute and lead various security system projects. Your role will encompass estimation, engineering design, programming, commissioning, and client training. We value...Full timeFor contractorsWork at office
- ...This is a remote position. Senior Cyber Security Specialist-Offensive Security Location: Remote (Canada) Experience: 10+ Years... ...required Work with engineering teams on remediation and secure SDLC Provide clear technical risk analysis and...SeniorFull timeContract workRemote work
$70 - $100 per hour
About the job Mercor connects elite creative and technical talent with leading AI research labs. Headquartered in San Francisco, our investors include Benchmark , General Catalyst , Peter Thiel , Adam D'Angelo , Larry Summers , and Jack Dorsey . Position...Hourly payWeekly payFull timeContract workFor contractorsSummer workRemote work$100 - $150 per hour
...Evaluate POC exploit development to determine boundaries between security research and malicious intent. Provide ground-truth labels... ...code-heavy conversations. Masters or early-career through Senior/Principal experience. Compensation & Legal Hourly...SeniorHourly payWeekly payFull timeContract workFor contractorsSummer workRemote work$101.15k - $130.9k per year
...Hydro One! Job Function: The Senior Cybersecurity Specialist, GRC Risk Management is a senior... ...business, technology, compliance, and security architecture stakeholders to identify... ...investing in both their success and ours. To secure the best talent, we seek to create a...Senior- ...look like? As a Cyber Risk Consultant / Senior Consultant, you will have the opportunity... ...include: • Assessing and implementing Cloud security solutions for clients • Reviewing... ...processes to the cloud and operating it in a secure and private way. We offer cyber capabilities...SeniorPermanent employmentFlexible hours
- ...TEHORA est présentement à la recherche d’ un(e) architecte sécurité senior ayant une solide expérience en architecture de sécurité, en gestion des risques et en exigences non fonctionnelles. La personne retenue contribuera à l’intégration des considérations de sécurité dans...SeniorHourly payFull timeContract workApprenticeshipRemote workFlexible hours
- ...products. Join us on our mission and shape the future! As a Senior Security Engineer you will: Serve as trusted advisor to team’s... ...and able to review what tools are available ~ You understand secure engineering best practices, can articulate problem statements and...SeniorFull timeWork at officeRemote workFlexible hours
$75.05 - $85.77 per hour
Our client, is seeking a high-caliber Security Specialist IV to join their Global Security Architecture... ...and Infrastructure division. In this senior technical position, you will be... ...translate functional business rules into secure, bulletproof firewall configurations....SeniorLong term contractContract workWork at officeImmediate startRemote workMonday to friday2 days per week- ...Senior Security Engineer Location : Toronto, On-Site Reports to: Head of Security The Role This is an early, high-ownership security... ...response (EDR) across the device fleet Design and maintain secure MDM baselines — configuration profiles and policies for all...SeniorFull time
$130k - $160k per year
...culture. Responsibilities : Conduct threat modeling and security design reviews for new and changing application features, APIs,... ...vendor security solutions that improve detection, response, and secure design (e.g., logging/SIEM, SOAR, runtime protections, SAST/DAST...SeniorLong term contractFull timeTemporary workWork at officeLocal areaRemote workFlexible hours- ...As a Senior Technician - Security Systems with Bosch Building Technologies, you will collaboratively review, understand, analyze, and implement installation blueprints and plans from Project Managers and Sales Teams to complete installations. This role requires the ability...SeniorFull timeContract workWork at officeFlexible hours
- ...Role Responsibilities Review and evaluate AI-generated outputs related to threat analysis, vulnerability assessment, and security architecture recommendations. Create realistic scenarios based on cybersecurity workflows such as incident response runbooks, threat...SeniorHourly payFull timeContract workSummer workRemote work
- ...TEHORA est présentement à la recherche d’un(e) Analyste en sécurité opérationnelle sénior Sans être exhaustifs, voici les services et livrables que devra fournir la personne retenue : Surveiller les incidents de sécurité; Analyser les vulnérabilités; Mettre en...SeniorHourly payFull timeContract workApprenticeshipRemote workFlexible hours
$60k - $110k per year
Security Monitoring and Response Specialist Position Description Location: This role can be located at any CGI office in Canada The Security Monitoring... .... Spécialiste en surveillance et intervention de sécurité Job Description Lieu : Ce poste peut être basé...ApprenticeshipWork at office- ...Position Title: Senior Collections Specialist Contract: Full-time, Independent Contractor Posting Jurisdictions: To support US Eastern Time... ...working proactively and professionally to resolve issues and secure timely payments. You’ll partner closely with internal teams...SeniorFull timeContract workFor contractors
- ...well as support integration with Dynamic 365. \ \ Workday Specialist responsibilities include: \\ \ · \\\ Act as Workday expert... ...integration issues to resolution. \ \ · \\\ Experience with Security management, Tenant management and Vendor management. \ \ \...SeniorFull time
$180.2k - $233.2k per year
...inspires you, join us. Imagine what we’ll build together. About the Cyber Security Team The Security Engineering team at Thumbtack is focused on enabling innovation at scale by making the secure path the easiest path. We believe strong security is not a blocker to...SeniorFull timeSeasonal workLocal areaShift work$120k - $150k per year
...people who are lifelong learners. About The Role As the Senior Manager, Information Security, you will help lead the strategic and operational... ...practices that keep our people, data, and client engagements secure. You'll also help align our internal security posture...SeniorWork at officeFlexible hours1 day per week
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to RQ00671 - Security Specialist - Senior. Be the first to apply!
- conseiller santé sécurité Toronto, ON
- security analyst Toronto, ON
- physical security specialist Toronto, ON
- spécialiste en sécurité Toronto, ON
- spécialiste en sécurité informatique Toronto, ON
- security systems specialist Toronto, ON
- security operations specialist Toronto, ON
- physical security analyst Toronto, ON
- conseiller en sécurité financière Toronto, ON
- application security consultant Toronto, ON
