Cyber Security Consultant
Offre en anglaisPosition Title – RQ00365 - Security Risk Assessment (SRA) Consultant/Cybersecurity Consultant Location: Hybrid – Fredericton, New Brunswick Type: Contract Position Overview Successful candidate will lead the end-to-end evaluation of the solution's security posture, including architecture, mobile applications, cloud services, APIs, authentication platforms, and enterprise integrations. This role requires expertise in application security testing, mobile security, cloud security, identity and access management, and industry-standard security frameworks. Key Responsibilities Conduct a comprehe…
- Hybride
- NEW BRUNSWICK
- Publié 20 juill. 2026
- Postuler avant le 19 août 2026
- 1 poste
Résumé du poste
Position Title – RQ00365 - Security Risk Assessment (SRA) Consultant/Cybersecurity Consultant Location: Hybrid – Fredericton, New Brunswick Type: Contract Position Overview Successful candidate will lead the end-to-end evaluation of the solution's security posture, including architecture, mobile applications, cloud services, APIs, authentication platforms, and enterprise integrations. This role requires expertise in application security testing, mobile security, cloud security, identity and access management, and industry-standard security frameworks. Key Responsibilities Conduct a comprehensive Security Risk Assessment (SRA) of the Digital Trust solution, including mobile applications, cloud services, APIs, vendor platforms, and enterprise integrations. Perform end-to-end architectural risk assessments and identify security vulnerabilities across the Digital Trust ecosystem. Execute application security testing, including: Static Application Security Testing (SAST) Dynamic Application Security Testing (DAST) Authentication and authorization validation API security assessments Vulnerability Assessment and Penetration Testing (VAPT) Assess security controls for identity management platforms, authentication services, cloud infrastructure, and enterprise applications. Evaluate security architecture using industry frameworks such as OWASP ASVS Level 3 and OWASP MASVS. Review integrations involving Ping Identity, Microsoft Entra ID, BizTalk, AMANDA, and other enterprise systems. Assess mobile applications on iOS and Android platforms for compliance with mobile application security standards. Analyze risks related to credential issuance, authentication, authorization, credential lifecycle, audit logging, and data protection. Produce detailed Security Risk Assessment reports, risk registers, remediation recommendations, and executive summaries. Present findings and recommendations to technical teams, project stakeholders, and senior management. Collaborate with project teams to validate remediation efforts and ensure security best practices are implemented. Required Qualifications Minimum 5 years of experience conducting Security Risk Assessments (SRA). Strong experience performing application security testing and vulnerability assessments. Hands-on experience with OWASP ASVS and/or OWASP MASVS security frameworks. Experience with: Static Code Analysis (SAST) Dynamic Application Security Testing (DAST) Penetration Testing (VAPT) API Security Testing Authentication and Authorization Security Experience assessing cloud-based applications and enterprise architectures. Strong understanding of Identity and Access Management (IAM) platforms. Excellent analytical, documentation, communication, and stakeholder management skills. Strong written and verbal communication skills in English. Preferred Qualifications 3+ years of experience performing security assessments using OWASP ASVS and/or OWASP MASVS. Experience with identity and authentication platforms such as Ping Identity, PingOne, Microsoft Entra ID (Azure AD), Okta, or similar technologies. Experience conducting security assessments within government, public sector, or regulated environments. Experience producing Security Risk Assessment (SRA) reports for complex enterprise or privacy-sensitive systems. Familiarity with cloud security services, enterprise APIs, mobile application security, and digital identity solutions.
Ce que vous ferez
Lead end-to-end security evaluations of the Digital Trust solution, including mobile applications, cloud services, and enterprise integrations. Conduct comprehensive risk assessments, perform vulnerability testing, and provide remediation recommendations to stakeholders.
Exigences
Requires a minimum of 5 years of experience in Security Risk Assessments and application security testing. Must have hands-on expertise with OWASP frameworks and experience with IAM platforms and cloud-based architectures.
Autres compétences pertinentes
Relevées dans la description du poste. Confirmez les exigences importantes ci-dessus.
- Security Risk Assessment
- Application Security Testing
- Mobile Security
- Cloud Security
- Identity and Access Management
- SAST
- DAST
- Vulnerability Assessment
- Penetration Testing
- API Security
- OWASP ASVS
- OWASP MASVS
- Ping Identity
- Microsoft Entra ID
- Cloud Infrastructure Security
- Digital Identity
Renseignements supplémentaires
- Expérience minimale
- 5+ ans
- Postuler avant le
- 19 août 2026