Security Specialist - Senior, 7M contract
HybridToronto, Ontario, Canada
Toronto, Ontario, CanadaHybridContractSenior Level
ContractSenior Level
Job Summary
Conduct threat risk assessments using ISO 31000, NIST RMF, or FAIR frameworks and develop data flow diagrams to map attack vectors via STRIDE, PASTA, and MITRE ATT&CK. Establish security policies and controls aligned with ISO 27001, NIST CSF, and CIS Controls while drafting technical and executive-level reports for stakeholder presentations. Requires 5–7 years in risk management, 3–5 years in threat modeling, and 5+ years in governance. Hybrid schedule in Toronto, Ontario through March 2027.
Required Qualifications
- Risk Management & Assessment – 5–7 years - Proven experience in conducting threat risk assessments using frameworks like ISO 31000, NIST RMF, or FAIR.
- Threat Modeling – 3–5 years - Practical knowledge of threat modeling techniques (e.g., STRIDE, PASTA, MITRE ATT&CK), including development of data flow diagrams and attack vectors.
- Information Security Governance – 5+ years-Strong understanding of security policies, standards, and controls aligned with ISO 27001, NIST CSF, and CIS Controls.
- Communication & Reporting – 5+ years-skilled in writing technical and executive-level reports, risk registers, and presenting to stakeholders and leadership.
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.