Security Threat and Risk Assessment Lead (Contract)
$85.00/hr
Sign in to apply
New here? Create a free account in under a minute.
ascio is hiring a Security Threat and Risk Assessment Lead to support our security and risk work across a range of systems, cloud services, procurements and existing technology environments.
This role will lead security threat and risk assessments from initial scoping through to final reporting, translating technical findings into clear risks, priorities and recommended actions for technical teams and decision makers.
Responsibilities
- Define the scope, boundaries and depth of security threat and risk assessments.
- Identify threats, model attack paths and assess existing security controls.
- Assess likelihood, impact and residual risk using a consistent risk methodology.
- Review system architectures, data flows, integrations and cloud configurations.
- Develop practical risk treatment plans identifying priorities, actions, ownership and level of effort.
- Prepare clear security assessment reports for technical and non-technical audiences.
- Present findings and recommendations to executives, audit committees and governance bodies.
Required Skills and Experience
- Eight or more years of experience in information security, including at least five years leading security threat and risk assessments.
- Demonstrated experience applying a threat and risk assessment methodology from scoping through assessment, reporting and risk treatment.
- Experience conducting threat modelling using STRIDE, attack trees, MITRE ATT&CK or comparable approaches.
- Experience assessing security controls against frameworks and standards including ISO/IEC 27001:2022, ISO/IEC 27002:2022, NIST CSF 2.0 or NIST SP 800-53.
- Strong architecture and data-flow analysis skills across on-premises, Microsoft Azure, AWS and SaaS environments.
- Cloud security assessment experience covering identity and access management, network segmentation, encryption, logging and monitoring.
- Experience conducting third-party and vendor security assessments.
- Strong written and verbal communication skills, with the ability to explain security risks clearly to both executive and technical audiences.
Qualifications
- Degree or diploma in computer science, information systems or a related field, or equivalent professional experience.
- One or more current professional certifications, such as CISSP, CRISC, CISM, CCSP, ISO/IEC 27001 Lead Auditor or ISO/IEC 27001 Lead Implementer.
- Applicants must be able to provide certification status and expiry dates, where applicable.
- Training or demonstrated experience with a recognized risk methodology such as ISO/IEC 27005, OCTAVE, FAIR or HTRA.
Preferred Experience
- Privacy impact assessments.
- Operational technology or industrial control system security assessments.
- Experience working within large, multi-department organizations.
- Application security and secure development lifecycle reviews.
Location and Work Arrangement
- Remote within Canada.
- Some assignments may require occasional onsite work or travel within Canada.
- Applicants must be based in Canada and legally entitled to work in Canada.
- A criminal record check may be required before access to sensitive systems, information or environments.