Skip to main content
Post your resume and find your next job on Indeed!

Cis jobs

Sort by: -
    • 10+ years of experience in all of the following:
    • In-depth knowledge of risk management frameworks (e.g., ISO 31000, NIST RMF) and threat modelling methodologies…
    • View all Source Code jobs - Toronto jobs - Security Specialist jobs in Toronto, ON
    • Salary Search: RQ00671 - 2 x Sr. Security Specialist salaries in Toronto, ON
    • 6-month contract (131 business days) - possible extension.
    • Minimum 5+ years of hands-on experience with ServiceNow Discovery and MID Server configuration.
    • Deliver internal audit, risk, and compliance services including ICOFR, SOX, and IT control testing.
    • Develop recommendations to enhance internal controls and…
    • You will be a member of the team, which maintains the posture of the various systems throughout their operational life cycle.
    • BDO is looking for a ServiceNow Functional Consultant to join our growing team, with the ability to work from anywhere in Canada, the ServiceNow Functional…
    • Evolving in a clean, temperate environment with the latest technology.
    • Starting a new job with paid and adapted training.
    • Reporting to the Chief Administrative Officer and Controller, the Accounting Manager is responsible for supporting the School's financial operations, including…
    • En tant que chargé de cours en Cybersécutiré (ex: Éthique, sécurité et vie privée, SPLUNK - Garantie de sécurité, tests et validation, CRYP - Cryptographie,…
    • Reporting to the Before and After School Manager, the Extended Care Assistant supports the delivery of a safe , nurturing, engaging and well organized Before…
    • (This position will commence late August 2026)*.
    • Reporting to the Head of Upper School, Teachers are responsible for a range of activities which fall into three…
    • The Assistant Director of Care (ADOC) reports to the Director of Care (DOC) and provides operational and clinical leadership to the nursing team to ensure…
    • Ce qu'on vous offre*.
    • Une culture d'entreprise familiale reconnue pour sa belle rétention.
    • Coordonner le cycle complet de recrutement, d'intégration et de…
    • Mortgage Operations, RESL provides specialized underwriting and processing services to Brokers, Home Financing Advisors, and eHOME customers.
    • 5 days of paid leave for Indigenous Employees for Ceremonial, Cultural, and Spiritual events per year.
    • 8 weeks of paid leave for gender affirming care for…
  • View similar jobs with this employer
    • Starting Salary: *$110,000 to $134,000/year.
    • Reporting to the Chief Information Officer, this role is responsible for ensuring that cloud platforms, enterprise…
Get e-mail updates for the latest Cis jobs

By creating a job alert, you agree to our Terms . You can change your consent settings at any time by unsubscribing or as detailed in our terms.

Career Resources:

Job Post Details

RQ00671 - 2 x Sr. Security Specialist - job post

Source Code
3.1 out of 5 stars
Toronto, ON
$77.24–$92.69 an hour - Full-time

Job details

Pay

  • $77.24–$92.69 an hour

Job type

  • Full-time

Location

Toronto, ON

Full job description

RQ00671 - 2 x Sr. Security Specialist

2 openings - 2 submissions

10-month contracts (195 business days)


ONSITE 5 days - 525 University Avenue

Must Haves:

10+ years of experience in all of the following:

  • In-depth knowledge of risk management frameworks (e.g., ISO 31000, NIST RMF) and threat modelling methodologies (e.g., STRIDE, DREAD).
  • Expertise in identifying, evaluating, and prioritizing threats and vulnerabilities across physical, cyber, and operational domains.
  • Strong analytical skills to assess potential impacts and likelihoods of various threat scenarios.
  • Proficiency risk assessment matrices
  • Excellent communication and reporting abilities to effectively present findings and risk mitigation strategies to both technical teams and executive stakeholders.
  • Familiarity with legal, regulatory, and compliance requirements, ensuring assessments align with organizational and industry standards (e.g., PHIPAA).
  • Proactive mindset and situational awareness to anticipate and adapt to emerging threats in a dynamic risk environment.

Nice-to-have:

  • Public Sector experience


Description:

The Security Specialist for Threat Risk Assessment, Threat Modelling, Vulnerability Assessment, Risk Identification will develop new workflows and contribute to the growth and maturity of the Security Risk Management and Information Security Office growth and maturity

Responsibilities:

The Senior Security Specialist will be responsible for conducting Threat Risk Assessments (TRA) plays a critical role in identifying, evaluating, and mitigating security risks across the organization's systems, processes, and assets. That includes participating in end-to-end risk assessment initiatives, developing and applying threat models, and working closely with stakeholders to understand business objectives and risk tolerance. The Senior Security Specialist will analyze vulnerabilities, assess potential threats, and determine the likelihood and impact of various risk scenarios, and will also be responsible for compiling detailed TRA reports, maintaining risk registers, and proposing actionable mitigation strategies and alignment with regulatory, industry, and organizational security standards, and effectively communicate findings to both technical teams and executive leadership. Additionally, the Security Specialist will contribute to the continuous improvement of risk management frameworks, support audit and compliance activities, and stay informed about emerging threats and security best practices.

Desired Skills:

  • Risk Management & Assessment – 10–15 years
  • Proven experience in conducting threat risk assessments using frameworks like ISO 31000, NIST RMF, or FAIR.
  • Threat Modeling – 10–15 years
  • Practical knowledge of threat modeling techniques (e.g., STRIDE, PASTA, MITRE ATT&CK), including development of data flow diagrams and attack vectors.
  • Information Security Governance – 7+ years
  • Strong understanding of security policies, standards, and controls aligned with ISO 27001, NIST CSF, and CIS Controls.
  • Communication & Reporting – 10+ years
  • Skilled in writing technical and executive-level reports, risk registers, and presenting to stakeholders and leadership.

Deliverables:

  • TRA Report: A comprehensive document outlining identified threats, vulnerabilities, risks, and proposed mitigation strategies, tailored to the organization's context.
  • Risk Register: A structured log of all identified risks, including severity, likelihood, risk rating, responsible owners, and mitigation actions.
  • Threat Modeling Diagrams: Visual representations of systems, data flows, and potential threat vectors using models like STRIDE or attack trees.
  • Risk Assessment Matrix: A visual tool mapping the likelihood and impact of risks to prioritize them effectively.
  • Asset Inventory & Classification: A list of assets in scope (e.g., systems, applications, data) categorized by value and sensitivity.
  • Vulnerability Assessment Results: A summary of technical vulnerabilities discovered during the assessment, often with outputs from tools like Nessus or OpenVAS.
  • Gap Analysis: Identification of discrepancies between current security posture and industry standards, best practices, or regulatory requirements.
  • Mitigation & Remediation Plan: Detailed action plans with timelines and responsibilities for reducing identified risks to acceptable levels.
  • Executive Summary: A high-level summary tailored for senior leadership, focusing on key findings, business impact, and strategic recommendations.
  • Compliance Mapping: Documentation showing how risks and controls align with regulatory or standards frameworks (e.g., NIST, ISO 27001, SOC 2).
  • Presentation Deck: Slide-based briefing to communicate findings, risks, and recommendations to stakeholders in a clear and digestible format.

AI Disclaimer: Source Code may use artificial intelligence (AI) tools to assist in certain aspects of its recruiting and business operations.

Note: The higher end of the range is intended for absolutely exceptional candidates who meet all must-have requirements and most or all nice-to-have qualifications. The client will evaluate candidates based on both rate expectations and overall skill set when shortlisting.

INCORPORATED RATE RANGE (7.25 billable hours per day)

  • $96.55/hr - $115.86/hr Inc.

T4 RATE RANGE (7.25 billable hours per day)

  • $77.24/hr - $92.69/hr T4
Let Employers Find YouUpload Your Resume