This recruiter is online.

This is your chance to shine!

Apply Now

Sr. Threat Modeling Architect to lead the identification of Cyber security risks and ensure sufficient controls are in place to mitigate these risks for ou

Toronto, ON
  • Number of positions available : 1

  • To be discussed
  • Contract job

  • Starting date : 1 position to fill as soon as possible

Position: Sr. Threat Modeling Architect to lead the identification of Cyber security risks and ensure sufficient controls are in place to mitigate these risks for our banking client

Duration: 6 months to start

Location: Hybrid Toronto (2x per week on-site)

The Work:

The Senior Threat Modeling Architect will work closely with the technology teams and line of business teams to develop secure technology solution designs. The Senior Threat Modeling Architect will lead the identification of Cyber security risks to the bank’s technologies and ensure sufficient controls are in place to mitigate these risks which could otherwise result in Cyber Security attacks, while enabling the business to grow the bank and serve our customers efficiently and securely.


Must haves:

  • At least 5+ years of information security performing IT security risk assessments and developing risk mitigation recommendations
  • Experience performing Threat modeling and threat modeling analysis (i.e. attack trees, sequence flow diagrams, Data Flow Diagrams etc.)
  • Experience with OKTA/IAM/CIAM tools
  • Experience in supporting application security programs working with Application Security frameworks is required e.g. OWASP
  • Experience and deep understanding of Azure hybrid cloud technologies is required.


Nice to haves:

  • Understanding of CI/CD pipeline and approaches to automate security testing is an asset
  • Understanding of API security is an asset.
  • Having coding experience is an asset.
  • The following certifications are preferred: CCSP, SABSA, CCSK, CISM, CISSP, or CRISC.
  • Understanding and experience with TOGAF, OWASP, SAMM, MITRE ATT&CK, BSIMM, NIST, ISO 27K series is an asset.
  • Experience working in a banking or financial services environment is an asset.


Job Description:

  • Perform the threat modelling for applications still in design phase
  • Provide security advisory services to technology and business teams.
  • Perform security assessments for technical solution designs.
  • Identify threat scenarios and evaluate risk rating based on a thorough review of the solution design by working closely with SMEs.
  • Track and remediate design flaws identified by the Threat Model process.
  • Ensure onboarding of appropriate security services by the project; e.g. Automated security scanning, MFA, SIEM onboarding etc.
  • Manage design security flaws tracking and escalate outstanding risks as required.
  • Manage security risks for assigned portfolio to ensure that action/mitigation plans are defined and actioned in-time.
  • Support Threat modeling and solution design security process improvements.
Apply

Requirements

Level of education

undetermined

Work experience (years)

undetermined

Written languages

undetermined

Spoken languages

undetermined