Retour à la recherche
S
StafinGoSource d’offres vérifiée

Senior IT Security Specialist

Offre en anglais

Lead end-to-end Threat Risk Assessments (TRAs) and threat modeling for applications, infrastructure, and business processes. Translate complex technical security findings into executive-level reports and remediation plans for senior leadership.

  • Hybride
  • Toronto, ON
  • Publié 5 août 2026
  • Postuler avant le 4 sept. 2026
  • 1 poste

Résumé du poste

Stafingo is Hiring – Senior IT Security Specialist | Threat & Risk Assessment-Hybrid-GTA Stafingo is currently recruiting a Senior IT Security Specialist for a confidential public-sector client in Ontario. We are seeking an experienced cybersecurity professional with strong hands-on experience in Threat Risk Assessments (TRA), threat modelling, security governance, risk management, compliance, and executive reporting. This is an excellent opportunity for a senior security professional who can work across technical and business teams, assess complex technology environments, identify security risks, and provide practical recommendations to support informed security and business decisions. Position Details : Position: Senior IT Security Specialist Focus: Threat Risk Assessment / Cybersecurity Risk Location: GTA – Hybrid(3 days onsite, 2 days home) Onsite: Up to 3 days per week, based on project requirements Contract: September 1st, 2026 – March 2027 (with potential for extension) Submission Deadline: Friday, August 17, 2026 at 5 pm EST Public Sector Experience: Preferred Compensation: $90-$110 per hour (depending on skills and experience) Key Responsibilities Lead end-to-end Threat Risk Assessments (TRAs) covering applications, information systems, infrastructure, business processes, and data. Work with business and technical stakeholders to define assessment scope, understand system architecture, data flows, business requirements, and security controls. Identify and assess threats, vulnerabilities, attack vectors, and security weaknesses. Conduct threat modeling using approaches such as STRIDE, PASTA, MITRE ATT&CK, or similar methodologies. Develop data-flow diagrams, threat models, risk matrices, and risk registers to support security assessments. Evaluate the likelihood and potential business impact of identified risks and establish appropriate risk ratings. Conduct security gap assessments against organizational policies, industry standards, regulatory requirements, and recognized frameworks. Develop practical risk mitigation and remediation plans and support tracking of risks through resolution. Assess security controls and alignment with frameworks such as ISO 27001, NIST CSF, NIST RMF, CIS Controls, and ISO 31000. Prepare detailed TRA reports, executive summaries, risk registers, gap analyses, and remediation recommendations. Translate complex technical security findings into clear business impacts and recommendations for senior leadership. Prepare and deliver executive-level presentation decks to communicate findings, risks, priorities, and recommended actions. Collaborate with cybersecurity, architecture, infrastructure, application, business, and other technology teams. Support compliance, audit, risk treatment, and continuous improvement activities. Maintain clear documentation and provide knowledge transfer to internal teams throughout the engagement. Required Qualifications : The successful candidate should have: 5–7+ years of experience conducting Threat Risk Assessments or cybersecurity risk assessments. Strong hands-on experience with risk management frameworks such as ISO 31000, NIST RMF, and/or FAIR. 5+ years of information security governance and risk management experience. Practical experience with threat modeling methodologies such as STRIDE, PASTA, MITRE ATT&CK, or comparable approaches. Strong understanding of ISO 27001, NIST CSF, CIS Controls, and security governance practices. Experience identifying, evaluating, and prioritizing cybersecurity threats and vulnerabilities. Experience developing risk assessment matrices, risk registers, TRA reports, gap analyses, and mitigation plans. Experience creating system/data-flow diagrams and threat models. Strong analytical, problem-solving, documentation, and decision-making skills. Excellent written and verbal communication skills, with the ability to communicate effectively with both technical teams and executives. Familiarity with privacy, regulatory, legal, and compliance requirements. Ability to work independently while collaborating effectively with cross-functional teams. Nice-to-Have Experience : Previous public-sector or government experience. Experience working in highly regulated environments. Experience assessing cloud, SaaS, enterprise applications, and infrastructure. Experience with vulnerability assessment tools such as Nessus, OpenVAS, or similar platforms. Experience supporting privacy, information protection, audit, or regulatory compliance initiatives. Experience presenting cybersecurity findings to senior executives and leadership teams. Key Deliverables : The successful resource will be expected to produce deliverables including: Comprehensive Threat Risk Assessment (TRA) Reports Risk Registers and risk assessment matrices Threat Modelling and Data-Flow Diagrams Security Gap Analysis Vulnerability assessment findings Asset inventory and classification documentation Risk Mitigation & Remediation Plans Compliance/control mapping Executive summaries Executive Presentation Decks Supporting documentation and knowledge-transfer materials Stafingo is supporting a confidential public-sector search and will be submitting one qualified resource for this opportunity. If you have strong experience in Threat Risk Assessment, threat modelling, cybersecurity governance, risk management, and executive-level security reporting, we encourage you to apply to the job posting directly or send your resume to harpreet@stafingo.com for immediate consideration.

Ce que vous ferez

Lead end-to-end Threat Risk Assessments (TRAs) and threat modeling for applications, infrastructure, and business processes. Translate complex technical security findings into executive-level reports and remediation plans for senior leadership.

Exigences

Requires 5-7+ years of experience in cybersecurity risk assessments and governance using frameworks like NIST and ISO. Must be proficient in threat modeling methodologies and capable of communicating risks to both technical teams and executives.

Autres compétences pertinentes

Relevées dans la description du poste. Confirmez les exigences importantes ci-dessus.

  • Threat Risk Assessment
  • Threat Modelling
  • Security Governance
  • Risk Management
  • Compliance
  • Executive Reporting
  • STRIDE
  • PASTA
  • MITRE ATT&CK
  • ISO 27001
  • NIST CSF
  • NIST RMF
  • CIS Controls
  • ISO 31000
  • FAIR
  • Gap Analysis

Domaines d’emploi

  • Security & Safety
  • Technology
  • Government & Public Sector
  • Consulting
  • Software

Renseignements supplémentaires

Expérience minimale
5+ ans
Postuler avant le
4 sept. 2026
Langue de l’offre
anglais
Heures de travail
40 heures par semaine
Présence au bureau
3 jours par semaine
Niveau d’expérience
Mid-Senior level
Mode de candidature
La candidature directe est offerte