Skip to content

Sr. Specialist Threat Risk Assessment

  • On-site
    • Toronto, Ontario, Canada
  • CA$131,000 - CA$131,000 per year
  • City of Toronto

Job description

JOB SUMMARY:

To provide senior level strategic and tactical guidance to the Director Business Application Resilience, as well as the Chief Information Security Office (CISO) in the execution of its mandate to establish and maintain a City-wide cyber program to ensure the City is adequately protected.

To define, develop and support Threat Risk Assessments (TRA) and cyber security risks while engaging with teams across the organization to build alignment on key projects and develop execution roadmaps.

To provide subject matter expertise, strategic advice, senior level guidance and operational support in the identification of cyber risks, and in the development of Risk Treatment Plan and recommendation to support the organization and the CISO's strategic objectives.

To collaborate with other segments of the organization to manage City-wide cyber initiatives.

MAJOR RESPONSIBILITIES:

  • Conducts Threat Risk Assessment for assigned initiatives.
  • Participates in the development and sustainment of the Threat Risk Assessment program.
  • Identifies, evaluates and supports initiatives that integrate into the Threat Risk Assessment program..
  • Develops and contribute to TRA and Risk Management standards and approaches to enable seamless and secure integrated solutions.
  • Provides support to the continuous improvement of the capabilities related to the Risk Management programs.
  • Supports the development and enhancement of metrics on Threat Risk Assessments to the senior management.
  • Participates in the enterprise-wide risk management strategy relating to cyber for the organization.
  • Aligns to organizational governance mandates and advocate for governance within Divisions, Agencies & Corporations.
  • Participates in the successful delivery of risk management initiatives ensuring technical excellence and a practical/business focused approach.
  • Builds collaborative and productive working relationships across the organization to establish, maintain, and continuously improve cyber risk management capabilities and promote risk awareness and intelligent risk-taking.
  • Conducts research into assigned area ensuring that such research takes into account developments within the field, corporate policies and practices, legislation and initiatives by other levels of government.
  • Provides input into assigned project budgets, ensuring that expenditures are controlled and maintained within approved budget limitations.
  • Provides subject matter expertise and senior level strategic advice on cyber security issues affecting the organization, identifying potential exposures, and conducting reviews to ensure that undesirable effects are detected, mitigated and/or corrected, and providing pragmatic advice to clients to ensure that cyber risks are managed appropriately.
  • Serves as the internal/external point of contact and subject matter expert in their respective function.
  • Determines cyber security requirements of business strategies in order to provide appropriate advice, guidance, and technical solutions.
  • Develops, reviews, and ensures approvals of security strategies within industry-accepted frameworks.
  • Provides leadership in the evaluation, selection and recommendation of technical solutions and professional services. Identifies and evaluates emerging security technologies.

Job requirements

QUALIFICATIONS/CERTIFICATIONS:

  • Post-secondary degree in Business or Technology or a related discipline.
  • Over 8 years of senior level experience in Cyber Security and in conducting Threat Risk Assessments.
  • Strong relevant Threat Risk Assessment experience in a fast paced environment.
  • Keen understanding of the digital ecosystems and customer needs with a focus on applications and application integration.
  • Subject Matter Expert, and strong experience in providing threat mitigation advisory and consultative support to clients
  • Solid understanding in emerging technologies
  • Extensive experience of applying security industry standards and best practices such as ISO 27001 and NIST standards.
  • Extensive experience preparing comprehensive reports and presentations for all levels of an organization.
  • Strong understanding of security risks, threats, and vulnerabilities and the judgment to assess and articulate risk effectively
  • Knowledge of architectural design and implementation methodologies including software, network and infrastructure.
  • Knowledge of network and information security methods, standards, architectures, policies and procedures.
  • Preferred Certifications (any in the list): CISSP, CCSP, CISA, CISM

SKILLS:

  • Ability to work in transformative programs
  • Excellent leadership and organizational skills and the ability to work effectively with all level of stakeholders.
  • Motivated self-starter demonstrating integrity, initiative and innovation qualities.
  • Strong analytical ability where problems are typically unusual and difficult.
  • Ability to judge, prioritise and multitask.
  • Excellent problem-solving skills with ability to identify solutions to unusual and complex problems.
  • Strong business acumen and client facing persona.
  • Ability to work with the broader IT organization and business management to align priorities and plans with key business objectives.
  • Demonstrated capacity to lead under pressure, make decisions in ambiguous situations and drive cross functional collaboration in a short period of time.
  • Demonstrated influence and persuasion skills, able to present to senior levels.
  • Strong understanding of the business impact of security tools, technologies and policies.
  • Excellent communication and active listening skills with an aptitude for extracting and synthesizing complex information.
  • Exceptional written and oral communication skills.
  • Transferable skills, like communication and decision-making..

or