Maarut Inc

RQ00742 - Security Specialist - Senior

Maarut Inc  •  Toronto, CA (Onsite)  •  4 days ago
Apply
AI can make mistakes so check important info. Chat history is never stored.

Job Description


Key activities included:


  • Scoping the assessment in collaboration with business and technical stakeholders.

  • Conducting structured risk analysis using recognized frameworks such as ISO 31000, NIST RMF, or FAIR.

  • Performing threat modeling (e.g., STRIDE, MITRE ATT&CK) to map potential attack vectors and security gaps.

  • Reviewing system architecture, data flows, and existing controls.

  • Assessing compliance with relevant regulatory and organizational security requirements.

  • Documenting findings in a detailed TRA report, including risk ratings and actionable mitigation recommendations.

  • Presenting results to executive leadership and supporting integration of risk treatments into the broader security strategy.


Must haves:


  • In-depth knowledge of risk management frameworks (e.g., ISO 31000, NIST RMF – Risk Management Framework) and threat modelling methodologies (e.g., STRIDE, DREAD).

  • Expertise in identifying, evaluating, and prioritizing threats and vulnerabilities across physical, cyber, and operational domains.

  • Strong analytical skills to assess potential impacts and likelihoods of various threat scenarios.

  • Proficiency risk assessment matrices

  • Excellent communication and reporting abilities to effectively present findings and risk mitigation strategies to both technical teams and executive stakeholders.

  • Familiarity with legal, regulatory, and compliance requirements, ensuring assessments align with organizational and industry standards (e.g., PHIPAA - Personal Health Information Protection Act).

  • Proactive mindset and situational awareness to anticipate and adapt to emerging threats in a dynamic risk environment.


Responsibilities:


  • Drive end-to-end Threat Risk Assessment (TRA) initiatives across systems, processes, and assets.

  • Develop and apply threat models to assess organizational security posture.

  • Collaborate with stakeholders to align assessments with business objectives and risk tolerance.

  • Analyze vulnerabilities and assess threats to determine likelihood and potential impact.

  • Produce detailed TRA reports, documenting findings, recommendations, and risk ratings.

  • Maintain risk registers and track remediation efforts.

  • Propose actionable mitigation strategies based on assessment outcomes.

  • Ensure alignment with:

    • Regulatory requirements

    • Industry standards

    • Organizational security policies

  • Communicate findings effectively to both technical teams and executive leadership.

  • Support audit and compliance activities as needed.

  • Contribute to the continuous improvement of risk management frameworks and methodologies.

  • Stay informed on emerging threats, vulnerabilities, and security best practices.


Desired Skills:


  • Demonstrated expertise in enterprise risk analysis, with a solid background in applying risk management frameworks such as ISO 31000, FAIR (Factor Analysis of Information Risk), and NIST RMF to identify, evaluate, and prioritize organizational security risks.

  • Hands-on experience conducting structured threat analysis, utilizing methodologies like STRIDE, PASTA (Process for Attack Simulation and Threat Analysis), and MITRE ATT&CK. Familiarity with creating threat models, mapping attack surfaces, and visualizing system flows to uncover security weaknesses.

  • Strong command of cybersecurity governance practices, including the development and enforcement of information security policies and standards. Practical understanding of how to align internal controls with recognized frameworks like ISO 27001, NIST CSF, and the CIS Critical Security Controls.

  • Proven ability to translate technical risk findings into clear business language, producing high-quality documentation such as executive summaries, detailed risk reports, and stakeholder presentations. Skilled in managing communication between technical teams and leadership to drive informed decision-making.


Requirements


Required Skills:


  • Risk Management & Assessment – 5–7 years - Proven experience in conducting threat risk assessments using frameworks like ISO 31000, NIST RMF, or FAIR.

  • Threat Modeling – 3–5 years - Practical knowledge of threat modeling techniques (e.g., STRIDE, PASTA, MITRE ATT&CK), including development of data flow diagrams and attack vectors.

  • Information Security Governance – 5+ years-Strong understanding of security policies, standards, and controls aligned with ISO 27001, NIST CSF, and CIS Controls.

  • Communication & Reporting – 5+ years-skilled in writing technical and executive-level reports, risk registers, and presenting to stakeholders and leadership.


Evaluation Criteria:


  • Threat Modeling:
    -
    5-7 years of hands-on experience with threat modeling techniques such as STRIDE, PASTA, and MITRE ATT&CK, including the development of data flow diagrams and identification of attack vectors to inform secure design decisions and guide risk mitigation strategies across systems and applications.

    20 Points

  • TRA Report: -
    5–7 years of experience conducting comprehensive threat and risk assessments using frameworks such as ISO 31000, NIST RMF, and FAIR, with a strong focus on identifying vulnerabilities, analyzing potential impacts, and delivering actionable risk mitigation strategies to stakeholders.

    20 Points

  • Gap Analysis:
    - 5–7 years of extensive experience with security controls and architecture, with a strong ability to identify gaps between the current security posture and industry standards, best practices, and regulatory requirements.

    20 Points

  • Team Player: -
    Demonstrates strong collaboration skills by working effectively with colleagues across functions, openly sharing information, supporting others to achieve shared goals, and contributing to a positive, respectful team environment.

    30 Points

  • Presentation Deck: -
    Over 5 years of experience authoring technical and executive-level reports, developing risk registers, and delivering presentations to stakeholders and senior leadership.

    10 Points


Deliverables:


  • TRA (Threat, Risk Assessment) Report
    : - A comprehensive document outlining identified threats, vulnerabilities, risks, and proposed mitigation strategies, tailored to the organization’s context.

  • Risk Register:
    - A structured log of all identified risks, including severity, likelihood, risk rating, responsible owners, and mitigation actions.

  • Threat Modeling Diagrams
    : - Visual representations of systems, data flows, and potential threat vectors using models like STRIDE or attack trees.

  • Risk Assessment Matrix:
    - A visual tool mapping the likelihood and impact of risks to prioritize them effectively.

  • Asset Inventory & Classification:
    - A list of assets in scope (e.g., systems, applications, data) categorized by value and sensitivity.

  • Vulnerability Assessment Results: -
    A summary of technical vulnerabilities discovered during the assessment, often with outputs from tools like Nessus or OpenVAS.

  • Gap Analysis:
    - Identification of discrepancies between current security posture and industry standards, best practices, or regulatory requirements.

  • Mitigation & Remediation Plan:
    - Detailed action plans with timelines and responsibilities for reducing identified risks to acceptable levels.

  • Executive Summary:
    - A high-level summary tailored for senior leadership, focusing on key findings, business impact, and strategic recommendations.

  • Compliance Mapping:
    - Documentation showing how risks and controls align with regulatory or standards frameworks (e.g., NIST, ISO 27001, SOC 2).

  • Presentation Deck: -
    Slide-based briefing to communicate findings, risks, and recommendations to stakeholders in a clear and digestible format.


Must Haves:


  • Risk Management & Assessment – 5–7 years - Proven experience in conducting threat risk assessments using frameworks like ISO 31000, NIST RMF, or FAIR.

  • Threat Modeling – 3–5 years - Practical knowledge of threat modeling techniques (e.g., STRIDE, PASTA, MITRE ATT&CK), including development of data flow diagrams and attack vectors.

  • Information Security Governance – 5+ years-Strong understanding of security policies, standards, and controls aligned with ISO 27001, NIST CSF, and CIS Controls.

  • Communication & Reporting – 5+ years-skilled in writing technical and executive-level reports, risk registers, and presenting to stakeholders and leadership.
Maarut Inc

About Maarut Inc

Maarut Inc is a Canadian company helping organizations fulfill staffing solutions based on current, future and ongoing needs of market.

Check out the new job openings https://careers.maarutinc.com/jobs/Careers

Register with us : https://careers.maarutinc.com/candidateportal?register=true

Finding IT talent is a significant challenge in today’s business landscape. Maarut Inc has the unique methodology for identifying, acquiring and retaining top IT resources across various areas of expertise. We help companies hire better candidate, and make meaningful relationships between the job seeker and the employers.

Engaging the right people with the right skills and experience can make or break your company. As an employment agency representing many talented skilled professionals who can pinch in immediate on projects, fill team gaps and support growth, we quickly deliver the exact talent you require for your needs.

Our goal is to craft flexible, targeted solutions as per your staffing needs by matching the right people, to the right job, at the right time.

Our recruiters are savvy insiders, having worked in the industries for which they recruit. They’ve walked in your shoes, so they understand the exciting, satisfying and challenging aspects of each job. They understand what makes IT placement unique, team dynamics and how each company and candidate are special.

Our recruitment team is specialized in identifying the top technical consultants with skill sets such as:

Application Development

Big Data

Business Intelligence/Reporting

Business Systems Analysis

Data Warehousing

Database

Devops Engineers

ERP/SCM/CRM

Guidewire consultants

Incident management Professionals

Infrastructure

Mainframe

Project Management

Quality Assurance

Salesforce consultants

Web Development/Design

Apply for jobs now or Register yourself now

https://www.maarutinc.com/applyjobs

Industry
IT & Software
Company Size
11-50 employees
Headquarters
Toronto, CA
Year Founded
Unknown
Social Media