Retour à la recherche
RT
Russell TobinSource d’offres vérifiée

Security Specialist - Senior

Offre en anglais

The role involves driving end-to-end Threat Risk Assessments (TRA) to evaluate the security posture of systems, applications, and business processes. Responsibilities include performing threat modeling, documenting risk ratings, and proposing mitigation strategies to executive leadership.

  • Hybride
  • Toronto, ON
  • Publié 5 août 2026
  • Postuler avant le 4 sept. 2026
  • 1 poste

Résumé du poste

Russell Tobin & Associates is hiring on behalf of one of its esteemed clients. Job ID: 26-23957 Job Title: Security Specialist - Senior Location: Toronto, ON (Hybrid) Duration: 151 Business Days with possible extension Client: Public Sector Pay Rate: CAD $105 per hour Role Overview This engagement involves driving the end-to-end execution of a Threat Risk Assessment (TRA) to evaluate the security posture of the information system, application, infrastructure, and business process. The objective is to identify potential threats, assess vulnerabilities, and determine the likelihood and impact of various risk scenarios affecting confidentiality, integrity, and availability. Key activities included: Scoping the assessment in collaboration with business and technical stakeholders. Conducting structured risk analysis using recognized frameworks such as ISO 31000, NIST RMF, or FAIR. Performing threat modeling (e.g., STRIDE, MITRE ATT&CK) to map potential attack vectors and security gaps. Reviewing system architecture, data flows, and existing controls. Assessing compliance with relevant regulatory and organizational security requirements. Documenting findings in a detailed TRA report, including risk ratings and actionable mitigation recommendations. Presenting results to executive leadership and supporting integration of risk treatments into the broader security strategy. Must Have: Risk Management & Assessment: 5-7 years - Proven experience in conducting threat risk assessments using frameworks like ISO 31000, NIST RMF, or FAIR. Threat Modeling: 3-5 years - Practical knowledge of threat modeling techniques (e.g., STRIDE, PASTA, MITRE ATT&CK), including development of data flow diagrams and attack vectors. Information Security Governance: 5+ years-Strong understanding of security policies, standards, and controls aligned with ISO 27001, NIST CSF, and CIS Controls. Communication & Reporting: 5+ years-skilled in writing technical and executive-level reports, risk registers, and presenting to stakeholders and leadership. Role and responsibilities. Drive end-to-end Threat Risk Assessment (TRA) initiatives across systems, processes, and assets. Develop and apply threat models to assess organizational security posture. Collaborate with stakeholders to align assessments with business objectives and risk tolerance. Analyze vulnerabilities and assess threats to determine likelihood and potential impact. Produce detailed TRA reports, documenting findings, recommendations, and risk ratings. Maintain risk registers and track remediation efforts. Propose actionable mitigation strategies based on assessment outcomes. Ensure alignment with: Regulatory requirements Industry standards Organizational security policies Communicate findings effectively to both technical teams and executive leadership. Support audit and compliance activities as needed. Contribute to the continuous improvement of risk management frameworks and methodologies. Stay informed on emerging threats, vulnerabilities, and security best practices. Russell Tobin is a leading minority-owned professional and technical recruitment and staffing advisory organization. We are comprised of specialized practices focusing on a variety of skill sets and industries. Having a depth and breadth of industry expertise, our subject matter experts are able to provide tailored and swift sourcing solutions to fulfill client hiring needs. In other words, we connect top talent with companies. We are the staffing arm of the Pride Global network, a minority-owned integrated human capital solutions firm, with additional offerings in vendor management, payroll programs, and business process optimization. #RTA

Ce que vous ferez

The role involves driving end-to-end Threat Risk Assessments (TRA) to evaluate the security posture of systems, applications, and business processes. Responsibilities include performing threat modeling, documenting risk ratings, and proposing mitigation strategies to executive leadership.

Exigences

Candidates must have 5-7 years of experience in risk management using frameworks like ISO 31000 or NIST RMF and 3-5 years of practical threat modeling experience. Strong knowledge of security governance standards and the ability to produce executive-level technical reports are required.

Autres compétences pertinentes

Relevées dans la description du poste. Confirmez les exigences importantes ci-dessus.

  • Threat Risk Assessment
  • Risk Management
  • Threat Modeling
  • Information Security Governance
  • ISO 31000
  • NIST RMF
  • FAIR
  • STRIDE
  • MITRE ATT&CK
  • ISO 27001
  • NIST CSF
  • CIS Controls
  • Technical Reporting
  • Vulnerability Analysis
  • Compliance Auditing
  • Stakeholder Management

Domaines d’emploi

  • Security & Safety
  • Technology
  • Government & Public Sector
  • Consulting
  • Software

Renseignements supplémentaires

Expérience minimale
5+ ans
Postuler avant le
4 sept. 2026
Langue de l’offre
anglais
Heures de travail
40 heures par semaine
Niveau d’expérience
Mid-Senior level
Mode de candidature
La candidature directe est offerte