Conduct enterprise Threat Risk Assessments (TRA) for applications, systems, cloud services, infrastructure, and business processes. Develop threat models and attack path analyses using recognized methodologies. Identify, assess, and prioritize cyber threats, vulnerabilities, and business risks. Perform security gap assessments against NIST, ISO 27001, CIS Controls, and regulatory requirements. Develop risk registers, mitigation plans, remediation roadmaps, and executive summaries. Collaborate with security architects, technical teams, project stakeholders, and senior leadership. Support audit, compliance, governance, and risk management initiatives. Deliver actionable recommendations that strengthen the organization’s overall security posture.
Requirements
10+ years in Cyber Security Risk Management and Threat Risk Assessments. 10+ years conducting Threat Modeling and Security Assessments. 7+ years in Information Security Governance and Compliance. 10+ years preparing executive-level security reports and presentations. Demonstrated experience with NIST RMF, ISO 31000, ISO 27001, NIST CSF, and CIS Controls. Experience within healthcare, public sector, or highly regulated environments is considered an asset.
Defensive Security Analyst responsible for identifying, analyzing, and mitigating threats to Desjardins's systems and networks. Engaging in continuous monitoring and risk assessment to ensure robust security posture.
Security Analyst providing 24/7 support for Bulletproof's Security Operations Center. Handling security issues, troubleshooting, and coordinating incident responses in a hybrid work environment.
Senior Technical Security Analyst in Identity & Access Management at RBC. Supporting end user access requests, troubleshooting, and collaborating in a high - performing team environment.
Security Analyst at Stripe managing bug bounty programs, coordinating security vulnerability remediation, and collaborating with researchers to enhance security posture.
Information Security Analyst needed for a banking client to monitor security reports, collaborate on remediation, and support security technology deployment.
Data Protection Analyst responsible for maintaining security infrastructure with a focus on data protection at RBC. Collaborating with cross - functional teams and enhancing monitoring controls.