Talent.com
Maarut
RQ00671 Security Specialist SeniorMaarut • Toronto, Ontario, Canada
RQ00671 Security Specialist Senior

RQ00671 Security Specialist Senior

Maarut • Toronto, Ontario, Canada
30+ days ago
Job type
  • Full-time
Job description

The Security Specialist for Threat Risk Assessment Threat Modelling Vulnerability Assessment Risk Identification will develop new workflows and contribute to the growth and maturity of the Security Risk Management and Information Security Office growth and maturity

Must haves:

  • In-depth knowledge of risk management frameworks (e.g. ISO 31000 NIST RMF) and threat modelling methodologies (e.g. STRIDE DREAD).
  • Expertise in identifying evaluating and prioritizing threats and vulnerabilities across physical cyber and operational domains.
  • Strong analytical skills to assess potential impacts and likelihoods of various threat scenarios.
  • Proficiency risk assessment matrices
  • Excellent communication and reporting abilities to effectively present findings and risk mitigation strategies to both technical teams and executive stakeholders.
  • Familiarity with legal regulatory and compliance requirements ensuring assessments align with organizational and industry standards (e.g. PHIPAA).
  • Proactive mindset and situational awareness to anticipate and adapt to emerging threats in a dynamic risk environment.

Responsibilities:

The Senior Security Specialist will be responsible for conducting Threat Risk Assessments (TRA) plays a critical role in identifying evaluating and mitigating security risks across the organizations systems processes and assets. That includes participating in end-to-end risk assessment initiatives developing and applying threat models and working closely with stakeholders to understand business objectives and risk tolerance. The Senior Security Specialist will analyze vulnerabilities assess potential threats and determine the likelihood and impact of various risk scenarios and will also be responsible for compiling detailed TRA reports maintaining risk registers and proposing actionable mitigation strategies and alignment with regulatory industry and organizational security standards and effectively communicate findings to both technical teams and executive leadership. Additionally the Security Specialist will contribute to the continuous improvement of risk management frameworks support audit and compliance activities and stay informed about emerging threats and security best practices.

Desired Skills:

  • Risk Management & Assessment 1015 years
  • Proven experience in conducting threat risk assessments using frameworks like ISO 31000 NIST RMF or FAIR.
  • Threat Modeling 1015 years
  • Practical knowledge of threat modeling techniques (e.g. STRIDE PASTA MITRE ATT&CK) including development of data flow diagrams and attack vectors.
  • Information Security Governance 7 years
  • Strong understanding of security policies standards and controls aligned with ISO 27001 NIST CSF and CIS Controls.
  • Communication & Reporting 10 years
  • Skilled in writing technical and executive-level reports risk registers and presenting to stakeholders and leadership.


Requirements

Rated Criteria:

  • Threat Modeling Expertise 20 Points
  • TRA Report: Demonstrated skills in TRA completions 20 Points
  • Gap Analysis: Demonstrated skills in gap analysis 40 Points
  • Communication Skills both written and verbal. 20 Points

Deliverables:

  • TRA Report: A comprehensive document outlining identified threats vulnerabilities risks and proposed mitigation strategies tailored to the organizations context.
  • Risk Register: A structured log of all identified risks including severity likelihood risk rating responsible owners and mitigation actions.
  • Threat Modeling Diagrams: Visual representations of systems data flows and potential threat vectors using models like STRIDE or attack trees.
  • Risk Assessment Matrix: A visual tool mapping the likelihood and impact of risks to prioritize them effectively.
  • Asset Inventory & Classification: A list of assets in scope (e.g. systems applications data) categorized by value and sensitivity.
  • Vulnerability Assessment Results: A summary of technical vulnerabilities discovered during the assessment often with outputs from tools like Nessus or OpenVAS.
  • Gap Analysis: Identification of discrepancies between current security posture and industry standards best practices or regulatory requirements.
  • Mitigation & Remediation Plan: Detailed action plans with timelines and responsibilities for reducing identified risks to acceptable levels.
  • Executive Summary: A high-level summary tailored for senior leadership focusing on key findings business impact and strategic recommendations.
  • Compliance Mapping: Documentation showing how risks and controls align with regulatory or standards frameworks (e.g. NIST ISO 27001 SOC 2).
  • Presentation Deck: Slide-based briefing to communicate findings risks and recommendations to stakeholders in a clear and digestible format.

Must Haves:

10 years experience:

  • In-depth knowledge of risk management frameworks (e.g. ISO 31000 NIST RMF) and threat modelling methodologies (e.g. STRIDE DREAD).
  • Expertise in identifying evaluating and prioritizing threats and vulnerabilities across physical cyber and operational domains.
  • Strong analytical skills to assess potential impacts and likelihoods of various threat scenarios.
  • Proficiency risk assessment matrices
  • Excellent communication and reporting abilities to effectively present findings and risk mitigation strategies to both technical teams and executive stakeholders.
  • Familiarity with legal regulatory and compliance requirements ensuring assessments align with organizational and industry standards (e.g. PHIPAA).
  • Proactive mindset and situational awareness to anticipate and adapt to emerging threats in a dynamic risk environment.



Employment Type : Full Time
Experience: years
Vacancy: 1
Monthly Salary Salary: 101 - 101
Create a job alert for this search

RQ00671 Security Specialist Senior • Toronto, Ontario, Canada

Similar jobs

Security Specialist - $95,500 - $119,400 A Year

Beem Credit UnionEast York, Canada
Full-time

Security Specialist to enhance threat detection, incident response, and cloud security using Microsoft Azure technologies, SIEM, and automation.Responsible for SOC capabilities and MSSP oversight. Show more

 • Promoted

Specialist Offensive Security - $113,683 - $155,216 A Year

ipss inc.Toronto, Canada
Full-time

Conducts penetration testing, identifies security weaknesses, and assists with remediation.Develops ethical hacking capabilities, supports the CISO's mandate, and provides security reports. Show more

 • Promoted

Enterprise Security Specialist - C$120,000 - C$135,000 A Year

Portfolio+Stouffville, Canada
Full-time

Leads the enterprise security program for a fintech company, focusing on governance, risk, compliance, and audits.Advises CTO on security practices without formal management. Show more

 • Promoted

Rq00671 - 2 X Sr. Security Specialist

Source CodeToronto, Canada
Full-time

Security Specialist2 openings - 2 submissions10-month contracts (195 business days)ONSITE 5 days - 525 University AvenueMust Haves:In-depth knowledge of risk management frameworks (e.ISO 31000, NIS... Show more

 • Promoted

Senior Security Analyst Threat Intelligence Role

Robinhoodtoronto, on, Canada
Full-time

Be at the forefront of cybersecurity as a Senior Security Analyst for Threat Intelligence at Robinhood in Toronto.Engage in advanced threat detection and prevention efforts.This role within the Thr... Show more

 • Promoted

Senior Security Specialist – Vulnerability & Mss Lead - $42 - $59 An Hour

IT solutions providerEast York, Canada
Full-time

Seeking a Senior Security Specialist for Managed Security Services in Toronto, providing 2nd level support, mentoring, and managing technical issues.Requires degree or IT experience and security ce... Show more

 • Promoted

Rq08709 - Security Specialist - Senior

Rubicon PathToronto, Canada
Full-time

About the job RQ08709 - Security Specialist - SeniorRole: Senior Security Specialists1.Support the development, UAT and Production of OPS Secure environmentsMonitoring the health, performance, and ... Show more

 • Promoted

Security Specialist - Senior_10+yrs

Maarut IncToronto
Full-time

The Cyber Security Centre of Excellence (COE) is seeking one (1) Senior Cyber Security Specialist to support in strengthening Ontario’s cyber security infrastructure as the province collectively mo... Show more

 • Promoted

Intact Senior Security Specialist

IntactToronto, ON, CA
Full-time

Join Intact as a Senior Security Advisor, focusing on Vault management and security architecture.Utilize your expertise in AWS and GCP to drive security strategies.You will manage the deployment an... Show more

 • Promoted

Senior Specialist Application Security - $122,305 - $163,639 A Year

ipss inc.East York, Canada
Full-time

This role provides strategic and operational guidance for application security, enhancing cloud-native security and integrating DevSecOps. Show more

 • Promoted

Senior Specialist - IT Security (Dev Sec Ops)

Marshtoronto, on, Canada
Full-time

DevSecOps & Secure-SDLC Engineer.Lead initiatives related to DevSecOps and Secure-SDLC.Enhance the company’s Secure Software development Liability (Secure-Business) (Secure-Business) which in turn ... Show more

 • Promoted

Senior Security Engineer

CohereToronto, ON, CA
Full-time

Our mission is to scale intelligence to serve humanity.We’re training and deploying frontier models for developers and enterprises who are building AI systems to power magical experiences like cont... Show more

 • Promoted

Senior Security Engineer

RootlyToronto
Full-time

About Rootly: At Rootly, we are on a mission to be the go-to way companies respond when things go wrong, helping every organization be more reliable.We do this by building an industry-leading incid... Show more

 • Promoted

Security specialist

Flip retailToronto
Full-time

Security Specialist vacancy in Toronto Canada.Security Specialist mainframe - REMOTE.Duty: Safety Specialist data processor.Ability: Protection Specification: Rational Identity & Accessibility Mgmt... Show more

 • Promoted

Security Specialist -- Siem Technologies - $33.3 - $46.5 An Hour

CdwToronto, Canada
Full-time

Provide second-level cybersecurity incident response and client support specializing in Microsoft Sentinel and Defender.Responsibilities include monitoring, investigation, remediation, and service ... Show more

 • Promoted

Palo Alto Security SME - Implementation

Tech Talent Internationaltoronto, on, Canada
Full-time

About the job Palo Alto Security SME - Implementation.Fortune 100/500/1000 and other companies in Canada/US.We are currently hiring for a Palo Alto Security SME - Implementation for our IT infrastr... Show more

 • Promoted

Senior Security Engineer

DoceboToronto
Full-time

At Docebo, AI isn’t just a buzzword — it’s how we help teams move faster, perform better, and focus on the work that actually matters.Our learning platform is built with smart, time-saving tools th... Show more

 • Promoted

Senior Security Operations Specialist - C$140,000 - C$154,000 A Year

RelayToronto, Canada
Full-time

Senior Security Operations Specialist to join a digital banking platform.Responsibilities include monitoring, investigating, and containing security threats in real-time, building detection logic, ... Show more

 • Promoted

Senior Security Specialist – Vulnerability & Mss Lead - $42 - $59 An Hour

CDW CanadaEast York, Canada
Full-time

Senior Security Specialist needed to provide technical support, mentor staff and manage complex technical issues. Show more

 • Promoted

Senior Cyber Security Specialist - $100,200 - $137,700 A Year

AtkinsRéalisToronto County, Canada
Full-time

Seeking a Cyber Security Specialist to advise on security and risk for critical infrastructure, focusing on OT/ICS environments.Responsibilities include risk assessment, compliance, and client mana... Show more