Job Title or Location
RECENT SEARCHES

RQ00394 - Sr. Security Specialist - Penetration Testing

Source Code - 116 Jobs

Toronto, ON

Posted today

Job Details:

Full-time
Entry Level

RQ00394 - Sr. Security Specialist - Penetration Testing

Contract 4+ months,

1 day in office minimum - GHQ (777 Memorial, Orillia) or Queens Park Detachment (56 Wellesley Street W, Toronto), either one.

Responsibilities:

  • Red team exercises, threat hunting, network vulnerability assessments, conducts penetration tests, vulnerability assessments, code reviews related to the OPP and OPS province wide I&IT infrastructure, applications and information resources.
  • Defines, evaluates, and assesses security requirements and safeguards for systems environments and IT projects.
  • Ensures the incorporation of IT security and contingency measures in the development and secure deployment of systems.
  • Advises on the identification, analysis, and resolution of specific security factors, risks, vulnerabilities; protection of personal privacy issues; and appropriate industry and international security standards.
  • Carry out information and information technology (I&IT) security projects and tasks in the Ontario Provincial Police as assigned by the OPP Chief Security Office and/or cluster I&IT management.

General Skills:

  • Strong understanding and expertise in security architecture, application and network security testing.
  • Experience in vulnerability assessment/penetration testing of web applications by identifying, analyzing and exploiting common vulnerabilities contained in web applications by using manual techniques and automated tools appropriate for enterprise use.
  • Experience with vulnerability assessment methodologies, tools and techniques used to conduct network vulnerability assessments, threat hunting, red team exercises and penetration testing.
  • Knowledge of techniques to secure information assets and the planning, design, and implementation of security technologies, safeguards and controls.
  • Proven techniques to discover gaps or weaknesses in security architecture to identify and mitigate known security threats, bugs, vulnerabilities and/or inherent weaknesses.
  • Knowledge and understanding of relevant legislation and corporate directives related to the security and confidentiality of information (e.g. Freedom of Information and Protection of Privacy Act) in order to identify and assess areas of concern and risk.
  • Solid knowledge of current security and contingency technology and techniques (e.g. digital signature, encryption, access controls, firewalls, authentication, virus protection, etc. ); and a proven working knowledge of security audit procedures and protocols.
  • Experience in establishing secure environments at a network, operating system or application level.
  • Experience with implementing security on complex and distributed systems in a high sensitive, law enforcement environment.
  • Experience in writing reports, documenting risks and making recommendations for a diverse audience including executive/non-technical management level and technical resources.
  • Awareness of emerging IT trends and directions, especially as related to security, privacy and compliance in a public sector environment.
  • Excellent analytical, problem-solving, and decision-making skills; written and verbal communication skills; interpersonal and negotiation skills.
  • A team player with a track record for meeting deadlines, managing competing priorities and client relationship management experience.

Deliverables:

  • Lead threat hunting and red team exercises to simulate cyber-attacks and identify vulnerabilities.
  • Conduct penetration tests, code reviews, and vulnerability assessments for OPP systems and applications
  • Define and assess security architecture requirements across systems and projects.
  • Ensure IT security and contingency measures are integrated into system development.
  • Advise on security risks, privacy concerns, and compliance with industry standards.

*Not looking for candidates in incident response and technical support but rather RED TEAM tools, techniques and strategies.*

Must Haves:

  • 10+ years experience with red team tactics and techniques
  • 10+ years experience network threat hunting
  • 10+ years experience network and application security

Nice-to-Have's:

  • Public sector experience

Share This Job: