Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

RQ00742 - Security Specialist - Senior

Full-time

Maarut Inc


Key activities included:


  • Scoping the assessment in collaboration with business and technical stakeholders.

  • Conducting structured risk analysis using recognized frameworks such as ISO 31000, NIST RMF, or FAIR.

  • Performing threat modeling (e.g., STRIDE, MITRE ATT&CK) to map potential attack vectors and security gaps.

  • Reviewing system architecture, data flows, and existing controls.

  • Assessing compliance with relevant regulatory and organizational security requirements.

  • Documenting findings in a detailed TRA report, including risk ratings and actionable mitigation recommendations.

  • Presenting results to executive leadership and supporting integration of risk treatments into the broader security strategy.

Must haves:


  • In-depth knowledge of risk management frameworks (e.g., ISO 31000, NIST RMF – Risk Management Framework) and threat modelling methodologies (e.g., STRIDE, DREAD).

  • Expertise in identifying, evaluating, and prioritizing threats and vulnerabilities across physical, cyber, and operational domains.

  • Strong analytical skills to assess potential impacts and likelihoods of various threat scenarios.

  • Proficiency risk assessment matrices

  • Excellent communication and reporting abilities to effectively present findings and risk mitigation strategies to both technical teams and executive stakeholders.

  • Familiarity with legal, regulatory, and compliance requirements, ensuring assessments align with organizational and industry standards (e.g., PHIPAA - Personal Health Information Protection Act).

  • Proactive mindset and situational awareness to anticipate and adapt to emerging threats in a dynamic risk environment.

Responsibilities:


  • Drive end-to-end Threat Risk Assessment (TRA) initiatives across systems, processes, and assets.

  • Develop and apply threat models to assess organizational security posture.

  • Collaborate with stakeholders to align assessments with business objectives and risk tolerance.

  • Analyze vulnerabilities and assess threats to determine likelihood and potential impact.

  • Produce detailed TRA reports, documenting findings, recommendations, and risk ratings.

  • Maintain risk registers and track remediation efforts.

  • Propose actionable mitigation strategies based on assessment outcomes.

  • Ensure alignment with:

    • Regulatory requirements

    • Industry standards

    • Organizational security policies


  • Communicate findings effectively to both technical teams and executive leadership.

  • Support audit and compliance activities as needed.

  • Contribute to the continuous improvement of risk management frameworks and methodologies.

  • Stay informed on emerging threats, vulnerabilities, and security best practices.

Desired Skills:


  • Demonstrated expertise in enterprise risk analysis, with a solid background in applying risk management frameworks such as ISO 31000, FAIR (Factor Analysis of Information Risk), and NIST RMF to identify, evaluate, and prioritize organizational security risks.

  • Hands-on experience conducting structured threat analysis, utilizing methodologies like STRIDE, PASTA (Process for Attack Simulation and Threat Analysis), and MITRE ATT&CK. Familiarity with creating threat models, mapping attack surfaces, and visualizing system flows to uncover security weaknesses.

  • Strong command of cybersecurity governance practices, including the development and enforcement of information security policies and standards. Practical understanding of how to align internal controls with recognized frameworks like ISO 27001, NIST CSF, and the CIS Critical Security Controls.

  • Proven ability to translate technical risk findings into clear business language, producing high-quality documentation such as executive summaries, detailed risk reports, and stakeholder presentations. Skilled in managing communication between technical teams and leadership to drive informed decision-making.

Requirements

Required Skills:


  • Risk Management & Assessment – 5–7 years - Proven experience in conducting threat risk assessments using frameworks like ISO 31000, NIST RMF, or FAIR.

  • Threat Modeling – 3–5 years - Practical knowledge of threat modeling techniques (e.g., STRIDE, PASTA, MITRE ATT&CK), including development of data flow diagrams and attack vectors.

  • Information Security Governance – 5+ years-Strong understanding of security policies, standards, and controls aligned with ISO 27001, NIST CSF, and CIS Controls.

  • Communication & Reporting – 5+ years-skilled in writing technical and executive-level reports, risk registers, and presenting to stakeholders and leadership.

Evaluation Criteria:


  • Threat Modeling:  - 5-7 years of hands-on experience with threat modeling techniques such as STRIDE, PASTA, and MITRE ATT&CK, including the development of data flow diagrams and identification of attack vectors to inform secure design decisions and guide risk mitigation strategies across systems and applications.  20 Points

  • TRA Report: - 5–7 years of experience conducting comprehensive threat and risk assessments using frameworks such as ISO 31000, NIST RMF, and FAIR, with a strong focus on identifying vulnerabilities, analyzing potential impacts, and delivering actionable risk mitigation strategies to stakeholders.  20 Points

  • Gap Analysis:  - 5–7 years of extensive experience with security controls and architecture, with a strong ability to identify gaps between the current security posture and industry standards, best practices, and regulatory requirements.  20 Points

  • Team Player: -  Demonstrates strong collaboration skills by working effectively with colleagues across functions, openly sharing information, supporting others to achieve shared goals, and contributing to a positive, respectful team environment.  30 Points

  • Presentation Deck: -  Over 5 years of experience authoring technical and executive-level reports, developing risk registers, and delivering presentations to stakeholders and senior leadership.  10 Points

Deliverables:


  • TRA (Threat, Risk Assessment) Report : - A comprehensive document outlining identified threats, vulnerabilities, risks, and proposed mitigation strategies, tailored to the organization’s context.

  • Risk Register:  - A structured log of all identified risks, including severity, likelihood, risk rating, responsible owners, and mitigation actions.

  • Threat Modeling Diagrams : - Visual representations of systems, data flows, and potential threat vectors using models like STRIDE or attack trees.

  • Risk Assessment Matrix:  - A visual tool mapping the likelihood and impact of risks to prioritize them effectively.

  • Asset Inventory & Classification:  - A list of assets in scope (e.g., systems, applications, data) categorized by value and sensitivity.

  • Vulnerability Assessment Results: -  A summary of technical vulnerabilities discovered during the assessment, often with outputs from tools like Nessus or OpenVAS.

  • Gap Analysis:  - Identification of discrepancies between current security posture and industry standards, best practices, or regulatory requirements.

  • Mitigation & Remediation Plan:  - Detailed action plans with timelines and responsibilities for reducing identified risks to acceptable levels.

  • Executive Summary:  - A high-level summary tailored for senior leadership, focusing on key findings, business impact, and strategic recommendations.

  • Compliance Mapping:  - Documentation showing how risks and controls align with regulatory or standards frameworks (e.g., NIST, ISO 27001, SOC 2).

  • Presentation Deck: -  Slide-based briefing to communicate findings, risks, and recommendations to stakeholders in a clear and digestible format.

Must Haves:


  • Risk Management & Assessment – 5–7 years - Proven experience in conducting threat risk assessments using frameworks like ISO 31000, NIST RMF, or FAIR.

  • Threat Modeling – 3–5 years - Practical knowledge of threat modeling techniques (e.g., STRIDE, PASTA, MITRE ATT&CK), including development of data flow diagrams and attack vectors.

  • Information Security Governance – 5+ years-Strong understanding of security policies, standards, and controls aligned with ISO 27001, NIST CSF, and CIS Controls.

  • Communication & Reporting – 5+ years-skilled in writing technical and executive-level reports, risk registers, and presenting to stakeholders and leadership. 

Vacancy posted 1 day ago
Similar jobs that could be interesting for youBased on the RQ00742 - Security Specialist - Senior in Toronto, ON vacancy
  • $114k - $164k per year

     ...Great Place to Work ®, seven years in a row! As a Senior Infrastructure Security Specialist , you will play a key role in protecting Kepler's corporate...  ...controls, and ensure Kepler's infrastructure remains secure and resilient as the organization continues to scale.... 
    Senior
    Full time
    Contract work
    Internship
    Work at office
    Remote work
    Relocation package

    Kepler Communications Inc.

    Toronto, ON
    1 day ago
  •  ...The Security Specialist for Threat Risk Assessment, Threat Modelling, Vulnerability Assessment, Risk Identification will develop new workflows...  ...in a dynamic risk environment. Responsibilities: The Senior Security Specialist will be responsible for conducting Threat... 
    Senior
    Full time
    Work at office

    Maarut Inc

    Toronto, ON
    1 day ago
  •  ...The Sr. Security Specialist will support and deliver on multiple initiatives related to Security Governance, Risk and Compliance and Cyber...  ...risk registers, and delivering presentations to stakeholders and senior leadership.  20 points Requirements Deliverables include... 
    Senior
    Full time

    Maarut Inc

    Toronto, ON
    1 day ago
  •  ...wide events to stay connected and engaged.  * We’re a certified  Great Place to Work ®, seven years in a row! As Senior Infrastructure Security Specialist , you will protect Kepler’s corporate, cloud, and operational infrastructure. Reporting to the VP, Information... 
    Senior
    Full time
    Work at office
    Relocation package

    kepler

    Toronto, ON
    18 days ago
  •  ...at . The Opportunity: We’re looking for an experienced Security GRC Specialist to join our growing Security GRC team. Reporting to the...  ...assurance programs and reporting appropriate metrics to the senior leadership. Who you are: Service – You put your clients... 
    Senior
    Full time
    Internship

    Aviso Wealth

    Toronto, ON
    1 day ago
  • $80.59 - $94.88 per hour

     ...client, is seeking an experienced, highly detail-oriented Security Specialist V (Senior IT Risk & Regulatory Remediation Specialist) to join their...  ...regulatory finding remediations. Conversion Potential: Secure a strategic 6-month engagement within a world-class... 
    Senior
    Permanent employment
    Contract work
    Manual labor
    Work at office
    2 days per week

    Randstad

    Toronto, ON
    6 days ago
  • $65 - $75 per hour

     ...Benchmark , General Catalyst , Peter Thiel , Adam D'Angelo , Larry Summers , and Jack Dorsey . Position: Source Security Specialist Type: Contract Compensation: $65–$75/hour Location: Remote Role Responsibilities Write... 
    Full time
    Contract work
    Summer work
    Remote work

    Mercor

    Toronto, ON
    1 day ago
  •  ...Transport family, here in Toronto! The Cyber Security Specialist ensures consistency of project solutions that are cyber secure by design. That is, according to defined cyber...  ...to communicate effectively and succinctly with senior management about complex technical matters... 
    Senior
    Full time
    Work at office
    Worldwide

    Thales

    Toronto, ON
    12 days ago
  • $70 - $90 per hour

     ...Contract Compensation: $70–$90/hour Location: Remote Role Responsibilities Analyze and review content for security vulnerabilities with a focus on pattern recognition and classification in an AI context. Apply expertise in systems... 
    Full time
    Contract work
    Summer work
    Remote work
    Flexible hours

    Mercor

    Toronto, ON
    1 day ago
  •  ...team today!     Position Summary:   Reporting to the Project Manager, you will have the opportunity to execute and lead various security system projects. Your role will encompass estimation, engineering design, programming, commissioning, and client training. We value... 
    Full time
    For contractors
    Work at office

    Carrières Ainsworth

    Toronto, ON
    1 day ago
  •  ...excited about creating something big!  The Opportunity As a Senior Security Engineer, you will be a hands-on technical leader strengthening...  ...controls, automate security processes, and help teams ship secure and reliable software. What you'll do Cloud and infrastructure... 
    Senior
    Full time
    Immediate start

    Forma.ai

    Toronto, ON
    1 day ago
  •  ...Role Responsibilities Review and evaluate AI-generated outputs related to threat analysis, vulnerability assessment, and security architecture recommendations. Create realistic scenarios based on cybersecurity workflows such as incident response runbooks, threat... 
    Senior
    Hourly pay
    Full time
    Contract work
    Summer work
    Remote work

    Mercor

    Toronto, ON
    1 day ago
  •  ...products. Join us on our mission and shape the future! As a Senior Security Engineer you will: Serve as trusted advisor to team’s...  ...and able to review what tools are available ~ You understand secure engineering best practices, can articulate problem statements and... 
    Senior
    Full time
    Work at office
    Remote work
    Flexible hours

    Cohere

    Toronto, ON
    1 day ago
  • $100 - $150 per hour

     ...Evaluate POC exploit development to determine boundaries between security research and malicious intent. Provide ground-truth labels...  ...code-heavy conversations. Masters or early-career through Senior/Principal experience. Compensation & Legal Hourly... 
    Senior
    Hourly pay
    Weekly pay
    Full time
    Contract work
    For contractors
    Summer work
    Remote work

    Mercor

    Toronto, ON
    1 day ago
  • $101.15k - $130.9k per year

     ...Hydro One! Job Function: The Senior Cybersecurity Specialist, GRC Risk Management is a senior advisor...  ..., technology, compliance, and security architecture stakeholders to identify...  ...investing in both their success and ours. To secure the best talent, we seek to create a... 
    Senior

    Hydro One Networks Inc

    Toronto, ON
    14 days ago
  • $20 - $21 per hour

     ...RESPITE SECURITY SPECIALIST Are you passionate about Safety & Security and seeking opportunity to join a team of Security Specialist? A.S....  ...Respite Security Protection Specialist takes responsibility for secure and safe at the Respite Centers in Toronto. What you will do:... 
    Hourly pay

    A.S.P. Incorporated

    Toronto, ON
    9 days ago
  • $63.85 - $70.51 per hour

    We are seeking a highly accomplished Senior Cybersecurity GRC Analyst (Security Specialist) for an enterprise-level contract opportunity based in Toronto. In this...  ...infrastructure. Long-Term Enterprise Engagement: Secure a foundational multi-year contract runway with... 
    Senior
    Long term contract
    Contract work
    2 days per week
    3 days per week

    Randstad

    Toronto, ON
    a month ago
  • $159.1k - $198k per year

     ...Summary League is seeking a Software Security Engineer to join our Security Engineering...  ...to build tools and workflows that improve secure software delivery, automate security operations...  ...productivity and quality of output Senior ICs / Managers: Integrate AI into team workflows... 
    Senior
    Full time
    Work at office
    Remote work
    Flexible hours

    League

    Toronto, ON
    1 day ago
  • $153k - $240.5k per year

     ...self-managed data stores such as MongoDB. We're looking for a Senior Cloud Security Engineer II to join our Security Engineering function as a...  ...mentorship and review. You'll go especially deep across three areas — secure architecture and threat modeling, detection engineering and... 
    Senior
    Full time
    Internship
    Work at office
    Local area
    Flexible hours

    Braze

    Toronto, ON
    1 day ago
  •  ...SENIOR REGULATORY COMPLIANCE SPECIALIST, Successful Investor Wealth Management Inc. We are an established wealth management and investment publishing...  .... As a registered firm under the Ontario Securities Commission (OSC), we prioritize integrity, fiduciary responsibility... 
    Senior
    Long term contract
    Full time
    Flexible hours

    The Successful Investor

    Toronto, ON
    1 day ago
  • $148k - $214k per year

     ...worldwide from increasingly sophisticated cyber and AI-driven threats, securing their AI transformation. Our prevention-first approach...  ...the place to do it. Job Description As an  MSP Sales Specialist , you will be responsible for accelerating the growth of Check... 
    Long term contract
    Full time
    Temporary work
    Worldwide

    Check Point Software Technologies

    Toronto, ON
    18 hours ago
  • In Canada, HSBC Global Services (Canada) Limited (HGCA) is a wholly owned subsidiary of HSBC Global Services Limited. Operating in Toronto, HGCA is part of a global service company, delivering services to support the operating entities of HSBC Group. We have different capabilities...
    Senior
    Flexible hours

    HSBC Global Services Limited

    Toronto, ON
    14 hours ago
  • $60 - $90 per hour

     ...Networks is headquartered in Irvine, CA USA with Asia HQ in Singapore and also operating in Denmark, Spain and Vietnam. The Security Specialist, Vulnerability Management will establish and operate a risk-based vulnerability management capability across the company’s... 
    Remote job
    Full time
    Contract work

    Axon-networks

    Toronto, ON
    1 day ago
  • $118k - $152k per year

     ...The Role As a Senior Application Security Engineer, you will provide hands-on technical delivery for the migration of Web Application Firewall (WAF) capabilities to Cloudflare and/or Akamai. You will work closely with architecture, security, network, and application teams... 
    Senior
    Internship
    Immediate start

    Capco

    Toronto, ON
    5 days ago
  •  ...well as support integration with Dynamic 365. \ \ Workday Specialist responsibilities include: \\ \ · \\\ Act as Workday expert...  ...integration issues to resolution. \ \ · \\\ Experience with Security management, Tenant management and Vendor management. \ \ \... 
    Senior
    Full time

    Yoush Consulting

    Toronto, ON
    1 day ago
  • $118k - $152k per year

     ...Help strengthen network and data security across complex financial services environments protecting...  ...evolving threats. The Role As a Senior Network Security Consultant you will work...  ...sensitive information while maintaining secure reliable and high-performing connectivity.... 
    Senior
    Contract work
    Internship
    Immediate start
    Remote work

    Capco

    Toronto, ON
    6 days ago
  • $160k - $220k per year

     ...makes our marketplace work. Our Application Security function is focused on keeping...  ...practice and love to write software that is secure, tested, easy to maintain, and can scale to...  ...listen to the data; and iterate. As a Senior Security Engineer, Application Security, you... 
    Senior
    Work at office
    Local area
    Remote work
    Monday to friday
    Shift work
    3 days per week

    Faire

    Toronto, ON
    5 days ago
  • $159.1k - $198k per year

     ...Summary League is seeking a Software Security Engineer to join our Security Engineering...  ...to build tools and workflows that improve secure software delivery, automate security operations...  ...productivity and quality of output Senior ICs / Managers: Integrate AI into team workflows... 
    Senior
    Full time
    Work at office
    Remote work
    Flexible hours

    League Inc.

    Toronto, ON
    5 days ago
  • $109k - $173k per year

     ...State/Province: Ontario City:  Toronto  Project Objectives & Role Summary The AI DevOps Specialist is primarily responsible for the technical deployment, secure enablement, administration, and continuous optimization of Celestica’s global HPS Artificial Intelligence... 
    Temporary work
    Local area
    Remote work

    Celestica International LP

    Toronto, ON
    1 day ago
  • $110k - $125k per year

     ..., we hope you’ll join us. About the role: Reporting to the Vice President of Information Technology as the first hire on our Security Operations Centre (SOC) team, you will be responsible for threat detection, investigation and incident response across endpoint, cloud... 
    Senior
    Full time
    Internship
    Work at office
    Flexible hours
    Weekend work
    Afternoon shift

    Financeit

    Toronto, ON
    1 day ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to RQ00742 - Security Specialist - Senior. Be the first to apply!