Retour à la recherche
T
ThoughtStormSource d’offres vérifiée

Senior Security Consultant

Offre en anglais

The primary responsibility is to conduct a comprehensive security risk assessment of the SNB Digital Trust solution, including application security testing. This involves assessing risks related to mobile, cloud, and application components, ensuring adherence to standards like OWASP.

  • Sur place
  • Fredericton, NB
  • Publié 16 juill. 2026
  • Postuler avant le 15 août 2026
  • 1 poste

Résumé du poste

Job Description- The primary focus of the security resource(s) under the terms of this Statement of Work will be to perform an SRA, including application security testing, of the SNB Digital Trust solution. This is a complex solution that requires a unique skillset related to mobile, cloud and application testing. The security resource(s) working on this assessment need to have the ability to assess all risks and the impact of those risks has on the whole solution. Comprehensive Security Risk Assessment (RA): Conduct an end-to-end architectural risk assessment of the Digital Trust solution, including the mobile apps, vendor components, portals, and internal government assets and services. We require leveraging core standards such as OWASP MASVS and OWASP AVAS, but respondents are encouraged to propose an enhanced mix of frameworks or alternate methodologies, in addition to OWASP, to ensure complete coverage. Application Security Testing: All components system will need to be security tested. Using the ‘SOP Application Security Testing and the OWASP MASVS, document as a guideline. This will include static code analysis, dynamic code analysis, authentication, and authorization controls validation. The SOP Application Security testing for SNB requires application testing to follow the OWASP L3 framework and validating concerning findings. The MASVS security testing also requires to be tested at the highest available level. This includes: Application testing Using ASVS OWASP Framework, Level 3 Assessment scope The Ping Identity platform including PingOne Verify, PingOne DaVinci, PingOne Credentials, and related Ping services and integrations directly used by the Digital Trust solution, including: Services supporting identity proofing, credential issuance, credential revocation, credential management, authentication, and workflow orchestration. A web-based utility built using Ping DaVinci available only to internal SNB support staff to assist in troubleshooting with the end user. For the Ping Identity platform, proponents should reference existing third-party assurance documentation, including Ping’s published security and compliance documentation and available SOC 2 Type 2 report, and should not re-perform platform-level assessments already completed by Ping. AMANDA Permitting, Compliance & Licensing (Granicus) and Citizen Portal for AMANDA (Meraki IT Group) Federated authentication services supporting GNB Wallet-based login to the Citizen Portal for AMANDA for the Department of Natural Resources. The AMANDA scope is limited to Citizen Portal for AMANDA supporting the Department of Natural Resources’ implementation of Granicus AMANDA Permitting, Compliance & Licensing, and the related AMANDA configuration, database, triggers, and business logic that directly support Digital Trust credential updates. Four mobile applications: (MAST level R and VAPT) GNB Wallet (iOS) GNB Wallet (Android) GNB Verify (iOS) GNB Verify (Android) Microsoft Entra authentication services used by the GNB Verify mobile applications (not the GNB Wallet mobile applications) are in scope only as they relate to authentication, authorization, and access control for those applications. Cloud storage services supporting the Digital Trust solution, including: Storage of user feedback submissions from the GNB Wallet applications, and Storage of verifier audit logs from the GNB Verify applications. Integrations and associated APIs connecting the Ping Identity platform to Government of New Brunswick enterprise systems used by the Digital Trust solution, including AMANDA, with BizTalk serving as the integration layer. MVS integration points are used by the Digital Trust solution to support identity proofing and related exception handling; however, they are out-of-scope as a risk assessment has been previously performed. AMANDA integration points used by the Digital Trust solution to support wallet onboarding, credential updates, and revocation for DNR Outdoors Card holders. End-to-end Verifiable Credential (VC) lifecycle processes, including credential issuance, update, presentation, revocation, and verification. Out of Scope Platform-level assessments already completed by Ping Other AMANDA products, modules, implementations, services, environments, or portals owned or operated by SNB or GNB are out of scope. Review of AMANDA is limited to the configuration, user roles and permissions, triggers, APIs, data flows, audit logging, and other integration components or back-office actions that directly support Digital Trust credential issuance, updates or revocation for Citizen Portal for AMANDA.

Ce que vous ferez

The primary responsibility is to conduct a comprehensive security risk assessment of the SNB Digital Trust solution, including application security testing. This involves assessing risks related to mobile, cloud, and application components, ensuring adherence to standards like OWASP.

Exigences

Candidates should possess a unique skillset related to mobile, cloud, and application testing, with the ability to assess risks and their impacts. Familiarity with OWASP standards and experience in application security testing are essential.

Autres compétences pertinentes

Relevées dans la description du poste. Confirmez les exigences importantes ci-dessus.

  • Security Risk Assessment
  • Application Security Testing
  • Mobile Testing
  • Cloud Testing
  • OWASP
  • Static Code Analysis
  • Dynamic Code Analysis
  • Authentication
  • Authorization
  • Risk Assessment
  • Credential Management
  • API Integration
  • Identity Proofing
  • Audit Logging
  • Compliance Documentation
  • Troubleshooting

Domaines d’emploi

  • Technology
  • Security & Safety
  • Consulting
  • Government & Public Sector
  • Data & Analytics

Renseignements supplémentaires

Expérience minimale
5+ ans
Postuler avant le
15 août 2026
Langue de l’offre
anglais
Heures de travail
40 heures par semaine
Niveau d’expérience
Mid-Senior level
Mode de candidature
La candidature directe est offerte