Talent.com
SereneAid
Threat Risk Assessment (TRA) Specialist / Penetration Testing (PT) Specialist – SeniorSereneAid • Halifax Central, NS, ca
No longer accepting applications
Threat Risk Assessment (TRA) Specialist / Penetration Testing (PT) Specialist – Senior

Threat Risk Assessment (TRA) Specialist / Penetration Testing (PT) Specialist – Senior

SereneAid • Halifax Central, NS, ca
30+ days ago
Job type
  • Full-time
  • Quick Apply
Job description
Job Description
Threat Risk Assessment (TRA) Specialist / Penetration Testing (PT) Specialist – Senior
Client: Government of Nova Scotia – Cyber Security & Digital Solutions (CSDS)
Project: Land Modernization Initiative (LMI)
Location: Halifax, Nova Scotia (Remote with optional onsite work)
Contract Duration: July 20, 2026 – May 31, 2027
Engagement Type: Competitive-Sourced
Work Arrangement: Remote (with occasional collaboration with CSDS stakeholders)
Project Overview
The Government of Nova Scotia is seeking experienced cybersecurity professionals to support the Land Modernization Initiative (LMI), a major transformation program modernizing the Province’s Land Registry services.
The selected consultants will work closely with the CSDS/LMI Technical Manager, Cyber Security and Risk Management (CSRM) team, and business stakeholders to conduct:
  • Threat Risk Assessments (TRA)
  • Penetration Testing (PT)
  • Security risk analysis
  • Vulnerability assessments
  • Security recommendations and remediation guidance
The initial engagement focuses on the MVS 1.0 release, with potential future work supporting releases 1.1, 1.2, and 1.3.

Requirements

Key Responsibilities
Threat Risk Assessment (TRA)
Scope
  • Identify and document security threats, vulnerabilities, and risks across the Nova Scotia Land Registry ecosystem.
  • Assess people, processes, technologies, communications, and information assets.
  • Evaluate likelihood and business impact of identified risks.
  • Recommend mitigation strategies and security controls.
  • Perform assessments using the NIST SP 800-53 Revision 5 High Baseline framework.
  • Review security certifications and reports including:
    • ISO/IEC 27001
    • ISO/IEC 42001
    • SOC 2 Type II
    • PCI DSS
Activities
  • Conduct workshops and stakeholder interviews.
  • Review system architecture, integrations, and data flows.
  • Analyze operational effectiveness of security controls.
  • Assess compliance across applicable NIST control families.
  • Document threat actors, attack vectors, vulnerabilities, and risk treatments.
  • Produce executive and technical reports.
  • Present findings to senior leadership and project stakeholders.
Penetration Testing (PT)
Scope
Conduct penetration testing against:
  • Web Applications
  • APIs
  • Cloud Environments
  • Networks
  • Mobile Applications
  • Endpoints
Testing Methodologies
  • White Box Testing
  • Grey Box Testing
  • Black Box Testing
Activities
  • Execute penetration testing using industry best practices.
  • Identify, validate, and document vulnerabilities.
  • Analyze prior security testing results.
  • Conduct remediation verification and retesting.
  • Produce executive and technical reports.
  • Immediately escalate Critical vulnerabilities using CVSS standards.
  • Participate in ongoing security assessments and risk management activities.
Required Deliverables
Threat Risk Assessment Deliverables
  • Draft TRA Report
  • Final TRA Report
  • Completed TRA Checklist
  • Risk Response Form
  • Executive Presentation
Penetration Testing Deliverables
  • Final Penetration Testing Report
  • Executive Presentation
  • Remediation Validation / Retest Results
Mandatory Qualifications (Required)
Candidates who do not meet the following requirements should not be submitted.
Threat Risk Assessment Requirements
Mandatory Experience
  • Minimum 3 years of experience conducting Threat Risk Assessments (TRAs) on digital systems.
  • At least one proposed resource must have completed two (2) or more TRAs on digital systems within the last three (3) years.
  • Experience conducting TRAs within Canadian public sector environments.
  • Experience working with:
    • NIST SP 800-53
    • ISO/IEC 27001
    • ISO/IEC 42001
    • SOC 2 Type II
    • PCI DSS
  • Experience assessing:
    • Cloud environments (AWS, Azure)
    • Network infrastructure
    • Enterprise applications
    • Technology platforms
  • Ability to work with business, security, and technical teams.
Mandatory Documentation
  • Criminal Record Check completed within the last six (6) months.
Penetration Testing Requirements
Mandatory Experience
  • Minimum 3 years of experience conducting penetration testing.
  • At least one proposed resource must have completed two (2) or more penetration tests within the last twelve (12) months.
  • Experience conducting penetration testing in Canadian public sector organizations.
  • Strong experience testing:
    • Web applications
    • APIs
    • Cloud environments
    • Networks
    • Enterprise systems
Mandatory Certifications
Tier 1 Certification (Required)
At least one proposed resource must hold one of the following:
  • OSCP (Offensive Security Certified Professional)
  • CREST CRT (Registered Penetration Tester)
Tier 2 Certification (Required)
At least one proposed resource should hold one of the following:
  • CEH Master
  • GPEN
  • CompTIA PenTest+
Mandatory Documentation
  • Criminal Record Check completed within the last six (6) months.
Preferred Qualifications
The following are considered strong assets:
Security Certifications
  • CISSP
  • CISM
  • CRISC
  • OSCP
  • CREST CRT
  • CEH Master
  • GPEN
  • CompTIA PenTest+
Government Experience
  • Previous experience performing Threat Risk Assessments for Canadian government organizations.
  • Previous experience conducting Penetration Testing for Canadian government organizations.
  • Direct experience supporting the Government of Nova Scotia.
  • Familiarity with Government of Nova Scotia cybersecurity standards, risk frameworks, and governance processes.
Technical Skills
Candidates should demonstrate expertise in:
  • Threat Risk Assessment Methodologies
  • Penetration Testing Methodologies
  • NIST SP 800-53 Rev. 5
  • ISO/IEC 27001
  • ISO/IEC 42001
  • SOC 2 Type II
  • PCI DSS
  • Cyber Risk Management
  • Vulnerability Assessment
  • Security Architecture Review
  • Risk Analysis and Treatment Planning
  • Security Control Assessment
  • Cloud Security (AWS / Azure)
  • Application Security
  • Network Security
  • Security Reporting and Executive Presentations
  • CVSS Scoring Framework
Evaluation Highlights
Candidates and vendors will be evaluated based on:
  • TRA experience and expertise
  • Penetration testing experience
  • NIST and security framework knowledge
  • Tier 1 and Tier 2 security certifications
  • Public sector cybersecurity experience
  • Government of Nova Scotia experience
  • Client references
  • Pricing competitiveness
This opportunity is ideal for senior cybersecurity consultants with proven expertise in both Threat Risk Assessments and Penetration Testing within government and highly regulated environments. The successful team will play a critical role in securing one of Nova Scotia's most significant digital modernization initiatives.


Requirements
Mandatory Qualifications (Required) Candidates who do not meet the following requirements should not be submitted. Threat Risk Assessment Requirements Mandatory Experience Minimum 3 years of experience conducting Threat Risk Assessments (TRAs) on digital systems. At least one proposed resource must have completed two (2) or more TRAs on digital systems within the last three (3) years. Experience conducting TRAs within Canadian public sector environments. Experience working with: NIST SP 800-53 ISO/IEC 27001 ISO/IEC 42001 SOC 2 Type II PCI DSS Experience assessing: Cloud environments (AWS, Azure) Network infrastructure Enterprise applications Technology platforms Ability to work with business, security, and technical teams. Mandatory Documentation Criminal Record Check completed within the last six (6) months. Penetration Testing Requirements Mandatory Experience Minimum 3 years of experience conducting penetration testing. At least one proposed resource must have completed two (2) or more penetration tests within the last twelve (12) months. Experience conducting penetration testing in Canadian public sector organizations. Strong experience testing: Web applications APIs Cloud environments Networks Enterprise systems Mandatory Certifications Tier 1 Certification (Required) At least one proposed resource must hold one of the following: OSCP (Offensive Security Certified Professional) CREST CRT (Registered Penetration Tester) Tier 2 Certification (Required) At least one proposed resource should hold one of the following: CEH Master GPEN CompTIA PenTest+ Mandatory Documentation Criminal Record Check completed within the last six (6) months. Preferred Qualifications The following are considered strong assets: Security Certifications CISSP CISM CRISC OSCP CREST CRT CEH Master GPEN CompTIA PenTest+ Government Experience Previous experience performing Threat Risk Assessments for Canadian government organizations. Previous experience conducting Penetration Testing for Canadian government organizations. Direct experience supporting the Government of Nova Scotia. Familiarity with Government of Nova Scotia cybersecurity standards, risk frameworks, and governance processes. Technical Skills Candidates should demonstrate expertise in: Threat Risk Assessment Methodologies Penetration Testing Methodologies NIST SP 800-53 Rev. 5 ISO/IEC 27001 ISO/IEC 42001 SOC 2 Type II PCI DSS Cyber Risk Management Vulnerability Assessment Security Architecture Review Risk Analysis and Treatment Planning Security Control Assessment Cloud Security (AWS / Azure) Application Security Network Security Security Reporting and Executive Presentations CVSS Scoring Framework Evaluation Highlights Candidates and vendors will be evaluated based on: TRA experience and expertise Penetration testing experience NIST and security framework knowledge Tier 1 and Tier 2 security certifications Public sector cybersecurity experience Government of Nova Scotia experience Client references Pricing competitiveness
Create a job alert for this search

Threat Risk Assessment (TRA) Specialist / Penetration Testing (PT) Specialist – Senior • Halifax Central, NS, ca

Similar jobs

Fire Protection Specialist

CBCL LimitedHalifax, Halifax County, CA
Full-time

RJ Bartlett Engineering, a division of CBCL Limited, has decades of experience in fire protection engineering, code consulting, alternative compliance analyses and customer service.With a thorough ... Show more

 • Promoted

Senior Treasury Specialist

ACCA CareersHalifax, Halifax County, CA
Full-time

We never ask for payment as part of our selection process, and we always contact candidates via our corporate accounts and platforms.If you are approached for payment, this is likely to be fraudule... Show more

 • Promoted

Senior Regulatory Operations Specialist

CencoraHalifax, Halifax County, CA
Full-time

Our team members are at the heart of everything we do.At Cencora, we are united in our responsibility to create healthier futures, and every person here is essential to us being able to deliver on ... Show more

 • Promoted

Senior Consultant, Health Equity Safety & Wellness Portfolio

IWK HealthHalifax, Halifax County, CA
Permanent

Senior Consultant, Health Equity Safety & Wellness Portfolio.IWK Health is a respected academic health sciences centre located in Halifax, Nova Scotia, providing care to millions annually.We focus ... Show more

 • Promoted

ITIL compliance specialist

FX Innovation, a Bell Canada CompanyHalifax, Halifax County, CA
Full-time

Be among the first 25 applicants.Get AI-powered advice on this job and more exclusive features.Ensure compliance with ITIL processes, including Incident Management, Problem Management, Change Manag... Show more

 • Promoted

Security Systems Design Consultant - Buildings

WSPHalifax, Halifax County, CA
Full-time

Security Systems Design Consultant - Buildings.What if you could redefine what’s possible?.We are the home of ambitious, passionate, and innovative world shapers.With an unmatched breadth and depth... Show more

 • Promoted

Senior QE Analyst

RBCHalifax, Halifax County, CA
Full-time

We are seeking a QA Test Engineer to join our technology team.This role requires a proactive individual who can execute quality assurance initiatives, develop and execute test strategies, and ensur... Show more

 • Promoted

Remote Product Tester - No Experience

OCPAHalifax, Nova Scotia, CA
CA$25.00 hourly
Remote
Part-time +1

Product Testers are wanted to work from home nationwide in the US to fulfill upcoming contracts with national and international companies.We guarantee 15-25 hours per week with an hourly pay of bet... Show more

 • Promoted

Senior Manager, Risk and Controls GFT

RBCHalifax, Halifax County, CA
Full-time

Are you passionate about Risk? We are looking for an experienced professional to fill the role of Senior Manager, Risk and Controls, for the Risk and Governance team in Global Functions Technology ... Show more

 • Promoted

Specialist, HSSEQ Event Investigation

WSP in CanadaHalifax, Halifax County, CA
Full-time

Specialist, HSSEQ Investigations.Lead thorough investigations into workplace incidents, environmental events, and non‑compliances.Analyse data, evidence, and timelines to uncover root causes and co... Show more

 • Promoted

Junior Compliance Analyst – AML & Risk Insights

Butterfield GroupHalifax, Halifax County, CA
Full-time

A leading offshore bank and trust company is seeking a Junior Compliance Analyst in Halifax.The successful candidate will support compliance validation testing, assist with regulatory requests, and... Show more

 • Promoted

Senior Systems Integration and Test Engineer -WOME

Lockheed MartinHalifax, Halifax County, CA
Full-time

Senior Systems Integration and Test Engineer -WOME.Senior Systems Integration and Test Engineer -WOME.This position is part of the Rotary and Mission Systems business area, where employees across C... Show more

 • Promoted

Senior Test Specialist

Babcock Mission Critical Services España SA.Halifax, Halifax County, CA
Permanent

Location: Halifax, Nova Scotia, CA, B3B 1E6.Onsite or Hybrid: Senior Test Specialist, Mechanical or Electrical (Permanent) – Halifax, NS.Expected Salary: $80,458 to $98,337.To determine final salar... Show more

 • Promoted

Tax Information Specialist (FATCA, CRS, CH3) Fixed-Term Contract (Approx. 10 Months)

The Citco Group LimitedHalifax, Halifax County, CA
Temporary

Maintain knowledge of FATCA and CRS (AEOI) regulatory and compliance environment as it impacts service and/or clients; conduct additional research as necessary to resolve internal or external queri... Show more

 • Promoted

Cyber Security Analyst - Halifax

DaviesHalifax, Halifax County, CA
Full-time

Cyber Security Analyst - Halifax.Application Deadline: 28 November 2025.Department: Risk and Compliance.Reporting to: Lead Cyber Security Engineer.Managing alerts within the group’s security toolin... Show more

 • Promoted

Senior Quality Assurance Analyst

Lockheed MartinHalifax, Halifax County, CA
Full-time

Develop and implement program quality plans, programs, and procedures using statistical quality control statistics, lean manufacturing concepts, and six-sigma tools and analyses.Ensures that perfor... Show more

 • Promoted

Remote Product Tester

OCPAHalifax, Nova Scotia, CA
CA$25.00 hourly
Remote
Part-time +1

Product Testers are wanted to work from home nationwide in the US to fulfill upcoming contracts with national and international companies.We guarantee 15-25 hours per week with an hourly pay of bet... Show more

 • Promoted

Patient Safety Consultant, Quality & Patient Safety

IWK HealthHalifax, Halifax County, CA
Permanent

Department/Program: Quality and Patient Safety , Quality, Patient Safety and Patient Experience.Type of Employment: Permanent Hourly FT ( 100% FTE) x 1 position(s).Union Status: NSNU Nursing, Nursi... Show more

 • Promoted

Pet Trainer

PetSmartHalifax, Halifax County, CA
Full-time

PetSmart does Anything for Pets and Everything for You – JOIN OUR TEAM!.At PetSmart, we’re more than just a company.We believe when our associates are happy and healthy, they can provide the best p... Show more

 • Promoted

Automation Tester

Lorven Technologies Inc.Halifax, Halifax County, CA
Full-time

Location: Halifax (4 days a week on site).Develop and maintain automation test scripts using Python and Robot Framework.Execute automated and manual test cases as required.Identify logs and track d... Show more