Senior Security Advisor at Intact, performing threat modelling and collaborating with cross-functional teams on security solutions. Requires extensive IT experience and security expertise.
Responsibilities
Perform structured threat modelling (e.g., STRIDE, MITRE ATT&CK, kill chain, attack trees, misuse/abuse cases) for applications, systems, and architecture patterns.
Work with data flow diagrams (DFDs), and architecture diagrams for new and existing systems.
Identify assets, trust boundaries, entry points, and potential attack paths.
Assess the likelihood and impact of identified threats, and assign inherent and residual risk ratings.
Translate threat modelling outcomes into clear security requirements and recommended controls.
Document control gaps and track remediation activities through to closure.
Collaborate with product, architect, developers, and engineers to support solution design by reviewing proposed architectures, patterns, and design decisions for security implications and providing recommendations.
Work with stakeholders to integrate threat modelling into product development workflows (e.g., SDLC, Agile, project delivery) across the organization.
Participate in secure code reviews to support security requirements and threat mitigations.
Plan and facilitate threat modelling workshops.
Communicate complex technical risks in clear, business-relevant language to both technical and non-technical stakeholders.
Contribute to the development and continuous improvement of threat modelling methodologies, templates, and tooling.
Support incident response and post-incident reviews by mapping exploited paths back to threat models and identifying improvements.
Maintain an up-to-date understanding of the threat landscape, including tactics, techniques, and procedures (TTPs), including those relevant to AI-related technologies.
Apply the Maestro framework (or similar) to structure and standardize threat modelling activities for use cases involving AI agents.
Requirements
Bachelor’s degree in computer science, or any combination of equivalent education and experience
Minimum ten (10) years of experience in information technology, including at least five (5) years in information security, with demonstrated experience in one or more of the following areas: application/cloud security, security architecture, threat modelling or risk assessment, threat intel, incident response, SOC, SIEM, vulnerability management, and red teaming or penetration testing
Strong knowledge of information security management principles and practices
Strong ethical principles and understanding of business and information security ethics
Good knowledge of common security vulnerabilities of web and cloud applications and operating techniques from sources such as SANS, OWASP Top 10 and Cloud Security Alliance (CSA)
Relevant certifications include (but are not limited to): CISSP, CISA, CISM, CGEIT, CRISC, GSEC, GISP, CCSP, SSCP, CSSLP, OSCP, SABSA, CEH, GCIH, GCTI, GCFE
Excellent oral and written communication skills – Need to interact on a regular basis with colleagues across the country
Positive attitude, team spirit and eagerness to learn
Critical mind
Experience working in a Security Operations Centre
Master the digital investigation concepts such as the chain of custody and the digital evidence
Demonstrated commitment to training, self-learning and maintaining proficiency in the technical cybersecurity domain
Experience with threat modelling tools is an asset (e.g., Microsoft Threat Modeling Tool, IriusRisk, Threat Dragon, in-house tools)
Experience working with diagramming tools is an asset (e.g., draw.io , Lucidchart, Visio) or code-based diagrams (e.g., PlantUML)
Proficiency in English is required; fluency in French is a plus.
No Canadian work experience required however must be eligible to work in Canada.
Benefits
Flexible work arrangements and a hybrid work model
Possibility to purchase up to 5 extra days off per year
Multiple benefits offered to support physical and mental wellbeing, including telemedicine, Wellness account and much more
Share plan & other savings: up to 12% of salary or even more (ask how you could earn guaranteed income for life)
Développeur.euse sécurité cloud protégeant l’infrastructure de nesto, plateforme de financement hypothécaire canadienne. Conception de contrôles cloud, automatisation DevSecOps et réponse aux incidents.
Lead SCADA and cybersecurity engineer designing compliant electric - substation systems for GE Vernova. Coordinating multidisciplinary teams, vendors, testing, estimates, and project risk for decarbonized energy infrastructure.
Join RBC's Application Security Group to develop innovative security solutions, mentor junior staff, and collaborate across teams to enhance decision - making and automate tasks.
Lead SCADA and cybersecurity engineer designing compliant substation systems for GE Vernova. Guiding project teams, vendor designs, estimates, and acceptance testing for cleaner energy infrastructure.
Senior security advisor simulating cyber threats and strengthening defenses for Desjardins, North America's largest cooperative financial group. Leading complex initiatives, methodologies and cybersecurity risk mitigation.
SA&A Lead securing Azure applications and Microsoft platforms for PLATO, Canada’s Indigenous - owned software testing company. Leading authorization, control testing, evidence collection, and risk remediation.
Senior security advisor simulating and mitigating cyberthreats for Desjardins, North America's largest cooperative financial group. Leading offensive security methodologies, tools and strategic initiatives.
Staff Product Security Engineer building customer identity and authentication services for Affirm’s buy - now - pay - later platform. Designing secure, scalable CIAM backend systems and integrations.
Senior Security Engineer securing AWS infrastructure, production systems, and AI - driven workflows. Building guardrails, vulnerability remediation, monitoring, and incident response for a rapidly scaling platform.