Conduct enterprise Threat Risk Assessments (TRA) for applications, systems, cloud services, infrastructure, and business processes. Develop threat models and attack path analyses using recognized methodologies. Identify, assess, and prioritize cyber threats, vulnerabilities, and business risks. Perform security gap assessments against NIST, ISO 27001, CIS Controls, and regulatory requirements. Develop risk registers, mitigation plans, remediation roadmaps, and executive summaries. Collaborate with security architects, technical teams, project stakeholders, and senior leadership. Support audit, compliance, governance, and risk management initiatives. Deliver actionable recommendations that strengthen the organization’s overall security posture.
Requirements
10+ years in Cyber Security Risk Management and Threat Risk Assessments. 10+ years conducting Threat Modeling and Security Assessments. 7+ years in Information Security Governance and Compliance. 10+ years preparing executive-level security reports and presentations. Demonstrated experience with NIST RMF, ISO 31000, ISO 27001, NIST CSF, and CIS Controls. Experience within healthcare, public sector, or highly regulated environments is considered an asset.
Threat Intelligence Analyst investigating telecom security threats and customer deployment data for Enea, a global telecom and cybersecurity software company. Supporting client security reviews and threat intelligence operations.
Information Security Analyst governing End - User Computing risks, controls, and remediation for TD, a major North American bank. Advising stakeholders and supporting governance reporting, audits, and regulatory requirements.
IT Security Analyst II coordinating cybersecurity monitoring, MSP oversight, audits, and incident follow - up. Supporting Veristat’s global life - sciences services and regulated technology environments.
Security Analyst protecting GitLab’s DevSecOps platform through vulnerability triage and CVE operations. Coordinating researchers, customers, and internal teams on secure software response.
SIEM/SOAR cybersecurity analyst monitoring threats, building alerts, and measuring controls. Supporting Wepoint’s digital transformation work for businesses and public sector organizations.
SIEM/SOAR information security analyst supporting Wepoint’s digital transformation services. Developing cybersecurity monitoring cases, alerts, dashboards, and security - control documentation.
Security Analyst II protecting Intact’s insurance operations through incident response and SIEM monitoring. Supporting security platforms, incident resolution, dashboards, and IT security initiatives.