We are seeking an experienced Senior Security Specialist to drive end-to-end Threat Risk Assessment (TRA) initiatives to evaluate and elevate organizational security posture across information systems, applications, infrastructure, and business processes. In this role, you will collaborate with business and technical stakeholders to scope assess
...
ments, perform structured threat modeling, review architectural data flows, and analyze system vulnerabilities. Utilizing established risk frameworks, you will determine risk likelihood and impact across confidentiality, integrity, and availability, producing comprehensive reports and executive risk registers that guide strategic risk mitigation efforts.
Location: Toronto, ON (Hybrid – up to 3 days onsite at manager's discretion)
Duration: 7-month contract
Public Sector Experience: Preferred.
Advantages
Strategic Security Leadership: Drive high-visibility, end-to-end Threat Risk Assessments (TRAs) across enterprise systems.
Modern Threat Frameworks: Utilize leading risk and threat modeling methodologies including NIST RMF, ISO 31000, STRIDE, and MITRE ATT&CK.
Executive Visibility: Author high-impact risk registers and present strategic risk mitigation plans directly to executive leadership.
Balanced Hybrid Model: Enjoy work-life balance with a flexible hybrid work schedule in Toronto.
Responsibilities
Drive end-to-end Threat Risk Assessment (TRA) initiatives across systems, applications, infrastructure, and operational business processes.
Perform structured threat modeling to map attack vectors, identify security gaps, and evaluate attack surfaces.
Review system architecture, data flow diagrams, and existing security controls in collaboration with business and technical stakeholders.
Evaluate and prioritize threats and vulnerabilities to determine potential likelihood and business impact across security domains.
Produce detailed TRA reports, executive summaries, risk ratings, and actionable risk mitigation recommendations.
Develop and maintain comprehensive risk registers, tracking remediation efforts and risk treatment progress.
Ensure all assessment activities and controls align with regulatory standards, industry compliance requirements, and organizational security policies.
Present complex risk findings, assessment results, and strategic mitigation options to technical teams and executive leadership.
Support ongoing security audit activities and contribute to the continuous improvement of internal risk management frameworks and threat intelligence methodologies.
Qualifications
Risk Assessment & Management: 5 to 7 years of proven experience conducting threat risk assessments using recognized frameworks such as ISO 31000, NIST RMF, or FAIR (Strictly Required).
Threat Modeling Expertise: 3 to 5 years of practical experience with threat modeling methodologies (STRIDE, PASTA, MITRE ATT&CK), including data flow diagramming and attack vector mapping (Strictly Required).
Information Security Governance: 5+ years of deep understanding of security policies, standards, and control frameworks aligned with ISO 27001, NIST CSF, and CIS Controls (Strictly Required).
Communication & Executive Reporting: 5+ years of experience authoring technical risk reports, executive summaries, and risk registers, with strong skills presenting to technical teams and executive leadership (Strictly Required).
Regulatory Compliance Knowledge: Familiarity with legal, regulatory, and privacy compliance requirements (such as PHIPA) to ensure assessments meet industry standards.
Summary
If you're interested in the "Senior Security Specialist" role based in Toronto, we encourage you to apply online at www.randstad.ca.
Only qualified candidates will be contacted for the next steps. We look forward to hearing from you!
Randstad Canada is committed to fostering a workforce reflective of all peoples of Canada. As a result, we are committed to developing and implementing strategies to increase the equity, diversity and inclusion within the workplace by examining our internal policies, practices, and systems throughout the entire lifecycle of our workforce, including its recruitment, retention and advancement for all employees. In addition to our deep commitment to respecting human rights, we are dedicated to positive actions to affect change to ensure everyone has full participation in the workforce free from any barriers, systemic or otherwise, especially equity-seeking groups who are usually underrepresented in Canada's workforce, including those who identify as women or non-binary/gender non-conforming; Indigenous or Aboriginal Peoples; persons with disabilities (visible or invisible) and; members of visible minorities, racialized groups and the LGBTQ2+ community.
Randstad Canada is committed to creating and maintaining an inclusive and accessible workplace for all its candidates and employees by supporting their accessibility and accommodation needs throughout the employment lifecycle. We ask that all job applications please identify any accommodation requirements by sending an email to accessibility@randstad.ca to ensure their ability to fully participate in the interview process.
This posting is for existing and upcoming vacancies.
show more
We are seeking an experienced Senior Security Specialist to drive end-to-end Threat Risk Assessment (TRA) initiatives to evaluate and elevate organizational security posture across information systems, applications, infrastructure, and business processes. In this role, you will collaborate with business and technical stakeholders to scope assessments, perform structured threat modeling, review architectural data flows, and analyze system vulnerabilities. Utilizing established risk frameworks, you will determine risk likelihood and impact across confidentiality, integrity, and availability, producing comprehensive reports and executive risk registers that guide strategic risk mitigation efforts.
Location: Toronto, ON (Hybrid – up to 3 days onsite at manager's discretion)
Duration: 7-month contract
Public Sector Experience: Preferred.
Advantages
Strategic Security Leadership: Drive high-visibility, end-to-end Threat Risk Assessments (TRAs) across enterprise systems.
Modern Threat Frameworks: Utilize leading risk and threat modeling methodologies including NIST RMF, ISO 31000, STRIDE, and MITRE ATT&CK.
...
Executive Visibility: Author high-impact risk registers and present strategic risk mitigation plans directly to executive leadership.
Balanced Hybrid Model: Enjoy work-life balance with a flexible hybrid work schedule in Toronto.
Responsibilities
Drive end-to-end Threat Risk Assessment (TRA) initiatives across systems, applications, infrastructure, and operational business processes.
Perform structured threat modeling to map attack vectors, identify security gaps, and evaluate attack surfaces.
Review system architecture, data flow diagrams, and existing security controls in collaboration with business and technical stakeholders.
Evaluate and prioritize threats and vulnerabilities to determine potential likelihood and business impact across security domains.
Produce detailed TRA reports, executive summaries, risk ratings, and actionable risk mitigation recommendations.
Develop and maintain comprehensive risk registers, tracking remediation efforts and risk treatment progress.
Ensure all assessment activities and controls align with regulatory standards, industry compliance requirements, and organizational security policies.
Present complex risk findings, assessment results, and strategic mitigation options to technical teams and executive leadership.
Support ongoing security audit activities and contribute to the continuous improvement of internal risk management frameworks and threat intelligence methodologies.
Qualifications
Risk Assessment & Management: 5 to 7 years of proven experience conducting threat risk assessments using recognized frameworks such as ISO 31000, NIST RMF, or FAIR (Strictly Required).
Threat Modeling Expertise: 3 to 5 years of practical experience with threat modeling methodologies (STRIDE, PASTA, MITRE ATT&CK), including data flow diagramming and attack vector mapping (Strictly Required).
Information Security Governance: 5+ years of deep understanding of security policies, standards, and control frameworks aligned with ISO 27001, NIST CSF, and CIS Controls (Strictly Required).
Communication & Executive Reporting: 5+ years of experience authoring technical risk reports, executive summaries, and risk registers, with strong skills presenting to technical teams and executive leadership (Strictly Required).
Regulatory Compliance Knowledge: Familiarity with legal, regulatory, and privacy compliance requirements (such as PHIPA) to ensure assessments meet industry standards.
Summary
If you're interested in the "Senior Security Specialist" role based in Toronto, we encourage you to apply online at www.randstad.ca.
Only qualified candidates will be contacted for the next steps. We look forward to hearing from you!
Randstad Canada is committed to fostering a workforce reflective of all peoples of Canada. As a result, we are committed to developing and implementing strategies to increase the equity, diversity and inclusion within the workplace by examining our internal policies, practices, and systems throughout the entire lifecycle of our workforce, including its recruitment, retention and advancement for all employees. In addition to our deep commitment to respecting human rights, we are dedicated to positive actions to affect change to ensure everyone has full participation in the workforce free from any barriers, systemic or otherwise, especially equity-seeking groups who are usually underrepresented in Canada's workforce, including those who identify as women or non-binary/gender non-conforming; Indigenous or Aboriginal Peoples; persons with disabilities (visible or invisible) and; members of visible minorities, racialized groups and the LGBTQ2+ community.
Randstad Canada is committed to creating and maintaining an inclusive and accessible workplace for all its candidates and employees by supporting their accessibility and accommodation needs throughout the employment lifecycle. We ask that all job applications please identify any accommodation requirements by sending an email to accessibility@randstad.ca to ensure their ability to fully participate in the interview process.
This posting is for existing and upcoming vacancies.
show more