RQ00742 - Security Specialist - Senior
Full-time
Maarut Inc
Key activities included:
- Scoping the assessment in collaboration with business and technical stakeholders.
- Conducting structured risk analysis using recognized frameworks such as ISO 31000, NIST RMF, or FAIR.
- Performing threat modeling (e.g., STRIDE, MITRE ATT&CK) to map potential attack vectors and security gaps.
- Reviewing system architecture, data flows, and existing controls.
- Assessing compliance with relevant regulatory and organizational security requirements.
- Documenting findings in a detailed TRA report, including risk ratings and actionable mitigation recommendations.
- Presenting results to executive leadership and supporting integration of risk treatments into the broader security strategy.
Must haves:
- In-depth knowledge of risk management frameworks (e.g., ISO 31000, NIST RMF â Risk Management Framework) and threat modelling methodologies (e.g., STRIDE, DREAD).
- Expertise in identifying, evaluating, and prioritizing threats and vulnerabilities across physical, cyber, and operational domains.
- Strong analytical skills to assess potential impacts and likelihoods of various threat scenarios.
- Proficiency risk assessment matrices
- Excellent communication and reporting abilities to effectively present findings and risk mitigation strategies to both technical teams and executive stakeholders.
- Familiarity with legal, regulatory, and compliance requirements, ensuring assessments align with organizational and industry standards (e.g., PHIPAA - Personal Health Information Protection Act).
- Proactive mindset and situational awareness to anticipate and adapt to emerging threats in a dynamic risk environment.
Responsibilities:
- Drive end-to-end Threat Risk Assessment (TRA) initiatives across systems, processes, and assets.
- Develop and apply threat models to assess organizational security posture.
- Collaborate with stakeholders to align assessments with business objectives and risk tolerance.
- Analyze vulnerabilities and assess threats to determine likelihood and potential impact.
- Produce detailed TRA reports, documenting findings, recommendations, and risk ratings.
- Maintain risk registers and track remediation efforts.
- Propose actionable mitigation strategies based on assessment outcomes.
- Ensure alignment with:
- Regulatory requirements
- Industry standards
- Organizational security policies
- Regulatory requirements
- Communicate findings effectively to both technical teams and executive leadership.
- Support audit and compliance activities as needed.
- Contribute to the continuous improvement of risk management frameworks and methodologies.
- Stay informed on emerging threats, vulnerabilities, and security best practices.
Desired Skills:
- Demonstrated expertise in enterprise risk analysis, with a solid background in applying risk management frameworks such as ISO 31000, FAIR (Factor Analysis of Information Risk), and NIST RMF to identify, evaluate, and prioritize organizational security risks.
- Hands-on experience conducting structured threat analysis, utilizing methodologies like STRIDE, PASTA (Process for Attack Simulation and Threat Analysis), and MITRE ATT&CK. Familiarity with creating threat models, mapping attack surfaces, and visualizing system flows to uncover security weaknesses.
- Strong command of cybersecurity governance practices, including the development and enforcement of information security policies and standards. Practical understanding of how to align internal controls with recognized frameworks like ISO 27001, NIST CSF, and the CIS Critical Security Controls.
- Proven ability to translate technical risk findings into clear business language, producing high-quality documentation such as executive summaries, detailed risk reports, and stakeholder presentations. Skilled in managing communication between technical teams and leadership to drive informed decision-making.
Requirements
Required Skills:
- Risk Management & Assessment â 5â7 years - Proven experience in conducting threat risk assessments using frameworks like ISO 31000, NIST RMF, or FAIR.
- Threat Modeling â 3â5 years - Practical knowledge of threat modeling techniques (e.g., STRIDE, PASTA, MITRE ATT&CK), including development of data flow diagrams and attack vectors.
- Information Security Governance â 5+ years-Strong understanding of security policies, standards, and controls aligned with ISO 27001, NIST CSF, and CIS Controls.
- Communication & Reporting â 5+ years-skilled in writing technical and executive-level reports, risk registers, and presenting to stakeholders and leadership.
Evaluation Criteria:
- Threat Modeling: - 5-7 years of hands-on experience with threat modeling techniques such as STRIDE, PASTA, and MITRE ATT&CK, including the development of data flow diagrams and identification of attack vectors to inform secure design decisions and guide risk mitigation strategies across systems and applications. 20 Points
- TRA Report: - 5â7 years of experience conducting comprehensive threat and risk assessments using frameworks such as ISO 31000, NIST RMF, and FAIR, with a strong focus on identifying vulnerabilities, analyzing potential impacts, and delivering actionable risk mitigation strategies to stakeholders. 20 Points
- Gap Analysis: - 5â7 years of extensive experience with security controls and architecture, with a strong ability to identify gaps between the current security posture and industry standards, best practices, and regulatory requirements. 20 Points
- Team Player: - Demonstrates strong collaboration skills by working effectively with colleagues across functions, openly sharing information, supporting others to achieve shared goals, and contributing to a positive, respectful team environment. 30 Points
- Presentation Deck: - Over 5 years of experience authoring technical and executive-level reports, developing risk registers, and delivering presentations to stakeholders and senior leadership. 10 Points
Deliverables:
- TRA (Threat, Risk Assessment) Report : - A comprehensive document outlining identified threats, vulnerabilities, risks, and proposed mitigation strategies, tailored to the organizationâs context.
- Risk Register: - A structured log of all identified risks, including severity, likelihood, risk rating, responsible owners, and mitigation actions.
- Threat Modeling Diagrams : - Visual representations of systems, data flows, and potential threat vectors using models like STRIDE or attack trees.
- Risk Assessment Matrix: - A visual tool mapping the likelihood and impact of risks to prioritize them effectively.
- Asset Inventory & Classification: - A list of assets in scope (e.g., systems, applications, data) categorized by value and sensitivity.
- Vulnerability Assessment Results: - A summary of technical vulnerabilities discovered during the assessment, often with outputs from tools like Nessus or OpenVAS.
- Gap Analysis: - Identification of discrepancies between current security posture and industry standards, best practices, or regulatory requirements.
- Mitigation & Remediation Plan: - Detailed action plans with timelines and responsibilities for reducing identified risks to acceptable levels.
- Executive Summary: - A high-level summary tailored for senior leadership, focusing on key findings, business impact, and strategic recommendations.
- Compliance Mapping: - Documentation showing how risks and controls align with regulatory or standards frameworks (e.g., NIST, ISO 27001, SOC 2).
- Presentation Deck: - Slide-based briefing to communicate findings, risks, and recommendations to stakeholders in a clear and digestible format.
Must Haves:
- Risk Management & Assessment â 5â7 years - Proven experience in conducting threat risk assessments using frameworks like ISO 31000, NIST RMF, or FAIR.
- Threat Modeling â 3â5 years - Practical knowledge of threat modeling techniques (e.g., STRIDE, PASTA, MITRE ATT&CK), including development of data flow diagrams and attack vectors.
- Information Security Governance â 5+ years-Strong understanding of security policies, standards, and controls aligned with ISO 27001, NIST CSF, and CIS Controls.
- Communication & Reporting â 5+ years-skilled in writing technical and executive-level reports, risk registers, and presenting to stakeholders and leadership.
Vacancy posted 1 day ago
Similar jobs that could be interesting for youBased on the RQ00742 - Security Specialist - Senior in Toronto, ON vacancy
- ...The Sr. Security Specialist will support and deliver on multiple initiatives related to Security Governance, Risk and Compliance and Cyber... ...risk registers, and delivering presentations to stakeholders and senior leadership. 20 points Requirements Deliverables include...SeniorFull time
- ...The Security Specialist for Threat Risk Assessment, Threat Modelling, Vulnerability Assessment, Risk Identification will develop new workflows... ...in a dynamic risk environment. Responsibilities: The Senior Security Specialist will be responsible for conducting Threat...SeniorFull timeWork at office
$65 - $75 per hour
...Senior IT Security Contract Specialist Join a recognized leader in the insurance sector and contribute to high-impact initiatives involving technology vendors, risk governance, and regulatory compliance. Working closely with cross-functional stakeholders, you will help...SeniorHourly payPermanent employmentContract workWork at office3 days per week$60k - $90k per year
...keep learning, consider starting or growing your career with us at The Home Depot. Home Depot is looking for a Senior Digital Personalization Specialist to join the Digital Content & Personalization team. This role will focus on executing, and optimizing personalized digital...SeniorWork at officeWork from home- ...at . The Opportunity: We’re looking for an experienced Security GRC Specialist to join our growing Security GRC team. Reporting to the... ...assurance programs and reporting appropriate metrics to the senior leadership. Who you are: Service – You put your clients...SeniorFull timeInternship
- ...Manage and maintain Information Security Management System (ISMS) design and implementation of new information security... ...":1,"value":"M4C"}],"headerName":"RQ10341 \- Security Specialist \- Threat Risk Assessment \- Senior","widgetId":"383123000000072311","isJobBoard":"false",...SeniorContract workFlexible hours
$19.5 per hour
...EVENT SECURITY SPECIALIST Are you passionate about Safety & Security and seeking opportunity to join a team of Security Specialist? A.S.P. Incorporated has provided security and customer service solutions for over 20 years to Canadian clients. We employ more than...Hourly payFull timeFlexible hoursShift workNight shiftWeekend workAfternoon shift$70 - $90 per hour
...Contract Compensation: $70–$90/hour Location: Remote Role Responsibilities Analyze and review content for security vulnerabilities with a focus on pattern recognition and classification in an AI context. Apply expertise in systems...Full timeContract workSummer workRemote workFlexible hours$70 - $100 per hour
About the job Mercor connects elite creative and technical talent with leading AI research labs. Headquartered in San Francisco, our investors include Benchmark , General Catalyst , Peter Thiel , Adam D'Angelo , Larry Summers , and Jack Dorsey . Position...Hourly payWeekly payFull timeContract workFor contractorsSummer workRemote work- ...team today! Position Summary: Reporting to the Project Manager, you will have the opportunity to execute and lead various security system projects. Your role will encompass estimation, engineering design, programming, commissioning, and client training. We value...Full timeFor contractorsWork at office
$100 - $150 per hour
...Evaluate POC exploit development to determine boundaries between security research and malicious intent. Provide ground-truth labels... ...code-heavy conversations. Masters or early-career through Senior/Principal experience. Compensation & Legal Hourly...SeniorHourly payWeekly payFull timeContract workFor contractorsSummer workRemote work$63.85 - $70.51 per hour
We are seeking a highly accomplished and technical Senior Security Architect (Security Specialist) for an enterprise-level contract opportunity based in Toronto... ...direction to ensure high availability, design secure network segmentation across multi-cloud and hybrid environments...SeniorContract workRemote workFlexible hours2 days per week3 days per week- ...excellence, innovation, and agility. The Lead Information Security Specialist is responsible for program/project/product/service development... ...'s success and consistently report on human risk reduction to senior management. How you will succeed: You have an innovative...SeniorFull timeFlexible hours
- ...Role Responsibilities Review and evaluate AI-generated outputs related to threat analysis, vulnerability assessment, and security architecture recommendations. Create realistic scenarios based on cybersecurity workflows such as incident response runbooks, threat...SeniorHourly payFull timeContract workSummer workRemote work
- ...products. Join us on our mission and shape the future! As a Senior Security Engineer you will: Serve as trusted advisor to team’s... ...and able to review what tools are available ~ You understand secure engineering best practices, can articulate problem statements and...SeniorFull timeWork at officeRemote workFlexible hours
- ...well as support integration with Dynamic 365. \ \ Workday Specialist responsibilities include: \\ \ · \\\ Act as Workday expert... ...integration issues to resolution. \ \ · \\\ Experience with Security management, Tenant management and Vendor management. \ \ \...SeniorFull time
- ...better working world for all. We are actively seeking a Cloud Security Manager to join our Cybersecurity team. You’ll work alongside... ...and identify risks within engagements and raise any issues with senior members of the team. Client Responsibilities Help the firm...SeniorLong term contractShift workWeekend work
$180.2k - $233.2k per year
...inspires you, join us. Imagine what we’ll build together. About the Cyber Security Team The Security Engineering team at Thumbtack is focused on enabling innovation at scale by making the secure path the easiest path. We believe strong security is not a blocker to...SeniorFull timeSeasonal workLocal areaShift work- ...Position Title: Senior Collections Specialist Contract: Full-time, Independent Contractor Posting Jurisdictions: To support US Eastern Time... ...working proactively and professionally to resolve issues and secure timely payments. You’ll partner closely with internal teams...SeniorFull timeContract workFor contractors
$159.1k - $198k per year
...Summary League is seeking a Software Security Engineer to join our Security Engineering... ...to build tools and workflows that improve secure software delivery, automate security operations... ...productivity and quality of output Senior ICs / Managers: Integrate AI into team workflows...SeniorFull timeWork at officeRemote workFlexible hours$85k - $105k per year
...to work at home, in the office, or a mix of both. The Senior Performance Marketing Specialist leads the strategy, execution, optimization, and ongoing... ...environment blended with the stability and financial security of an enterprise. Resolver has also been named one of Canada...SeniorFull timeWork at officeRemote workWork from home- ...functional teamsâincluding support, security, privacy, change management, release management... ...proven troubleshooting expertise in secure systemâtoâsystem communication. \\... ...Responsibilities: \ ~The Senior Middleware Specialist is accountable \ for the end\-to\-end...SeniorContract workInternship
- ...We do have a job opening for Cloud Application Specialist - Senior for our direct client Province of Ontario. The position details are given... ...Demonstrated experience in enterprise cloud architecture, security (IAM, encryption, compliance), data engineering (ETL/ELT, Azure...SeniorFull time
- ...Senior Security Engineer Location : Toronto, On-Site Reports to: Head of Security The Role This is an early, high-ownership security... ...response (EDR) across the device fleet Design and maintain secure MDM baselines — configuration profiles and policies for all...SeniorFull time
$83.5k per year
...looking for a purpose-driven and authentic career! The Senior IT Operations Specialist is responsible for the design, implementation, and... ...Conduct manual technical audits across all locations for security, POS redundancy compliance, hardware firmware configurations...SeniorHourly payPermanent employmentFull timeRemote workShift work- ...We do have a job opening for Application Support Specialist - Senior for our direct client Province of Ontario. The position details are given... ...-directory administration (e.g., Microsoft Entra ID): security groups, B2B guest invitations, approver / Entitlement Management...SeniorFull time
- Job Title: SENIOR SECURITY COORDINATOR Job ID:66663 Job Category: Buildings, Property Operations & Real Estate Division & Section: Corporate Real Estate Management, Corporate Security Work Location: City Hall, 100 Queen St. West Job Type & Duration: Full-time, 2 Permanent...SeniorPermanent employmentFull timeTemporary workPart timeFixed term contractInternshipLocal areaMonday to fridayShift workNight shiftAfternoon shift
- ...challenges. Position Overview Dokainish & Company is seeking a Senior Cost Specialist - Benchmarking to provide program-level cost intelligence,... ...be eligible to obtain Federal Government Reliability Status security clearance Experience Minimum of 10–15 years of...SeniorFull timeInternship
$80 - $100 per hour
...Benchmark , General Catalyst , Peter Thiel , Adam D'Angelo , Larry Summers , and Jack Dorsey . Position: Insurance AI Specialist Type: Contract Compensation: $80–$100/hour Location: Remote Role Responsibilities Review...SeniorFull timeContract workSummer workRemote work- ...We are seeking a Stand Alone Senior Payroll Specialist who enjoys turning complexity into clarity. This role is ideal for someone who has stepped into legacy payroll environments and successfully modernized processes, improved reporting, and introduced smarter, more...SeniorLong term contractFull timeTemporary work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to RQ00742 - Security Specialist - Senior. Be the first to apply!
Related searches
- security analyst remote Toronto, ON
- conseiller santé sécurité Toronto, ON
- physical security analyst Toronto, ON
- security consultant Toronto, ON
- security systems specialist Toronto, ON
- spécialiste en sécurité Toronto, ON
- junior security analyst Toronto, ON
- security operations specialist Toronto, ON
- conseiller en sécurité financière Toronto, ON
- application security consultant Toronto, ON
