Cyber Security Consultant
About the role
Position Title – RQ00365 - Security Risk Assessment (SRA) Consultant/Cybersecurity Consultant Location: Hybrid – Fredericton, New Brunswick Type: Contract
Position Overview
Successful candidate will lead the end-to-end evaluation of the solution's security posture, including architecture, mobile applications, cloud services, APIs, authentication platforms, and enterprise integrations. This role requires expertise in application security testing, mobile security, cloud security, identity and access management, and industry-standard security frameworks.
Key Responsibilities
Conduct a comprehensive Security Risk Assessment (SRA) of the Digital Trust solution, including mobile applications, cloud services, APIs, vendor platforms, and enterprise integrations. Perform end-to-end architectural risk assessments and identify security vulnerabilities across the Digital Trust ecosystem.
Execute application security testing, including
Static Application Security Testing (SAST) Dynamic Application Security Testing (DAST) Authentication and authorization validation API security assessments Vulnerability Assessment and Penetration Testing (VAPT) Assess security controls for identity management platforms, authentication services, cloud infrastructure, and enterprise applications. Evaluate security architecture using industry frameworks such as OWASP ASVS Level 3 and OWASP MASVS. Review integrations involving Ping Identity, Microsoft Entra ID, BizTalk, AMANDA, and other enterprise systems. Assess mobile applications on iOS and Android platforms for compliance with mobile application security standards. Analyze risks related to credential issuance, authentication, authorization, credential lifecycle, audit logging, and data protection. Produce detailed Security Risk Assessment reports, risk registers, remediation recommendations, and executive summaries. Present findings and recommendations to technical teams, project stakeholders, and senior management. Collaborate with project teams to validate remediation efforts and ensure security best practices are implemented.
Required Qualifications
Minimum 5 years of experience conducting Security Risk Assessments (SRA). Strong experience performing application security testing and vulnerability assessments. Hands-on experience with OWASP ASVS and/or OWASP MASVS security frameworks.
Experience with
Static Code Analysis (SAST) Dynamic Application Security Testing (DAST) Penetration Testing (VAPT) API Security Testing Authentication and Authorization Security Experience assessing cloud-based applications and enterprise architectures. Strong understanding of Identity and Access Management (IAM) platforms. Excellent analytical, documentation, communication, and stakeholder management skills. Strong written and verbal communication skills in English.
Preferred Qualifications
3+ years of experience performing security assessments using OWASP ASVS and/or OWASP MASVS. Experience with identity and authentication platforms such as Ping Identity, PingOne, Microsoft Entra ID (Azure AD), Okta, or similar technologies. Experience conducting security assessments within government, public sector, or regulated environments. Experience producing Security Risk Assessment (SRA) reports for complex enterprise or privacy-sensitive systems. Familiarity with cloud security services, enterprise APIs, mobile application security, and digital identity solutions.
About BuzzClan
BuzzClan is an AI-first technology consulting firm helping government agencies and enterprises drive meaningful digital transformation.
Since 2013, we’ve partnered with organizations to modernize legacy systems, unlock the value of their data, and improve how they operate and scale.
What began as a Texas-based firm has grown into a global organization that delivers solutions across cloud, data, cybersecurity, software engineering, and managed services, with AI embedded in how we design and deliver outcomes rather than treated as an add-on.
Our Services: AI and Machine Learning Services Cloud Consulting and Managed IT Services Data Engineering, Data and Analytics, and Business Intelligence Cyber Security and IT Infrastructure Digital Transformation, QA Services, and ServiceNow Mobile App Development CIO Advisory Staffing Services, Workforce Management Global Capability Centers
We are a certified partner to Oracle, Microsoft Azure, AWS, Google Cloud, Saviynt, and Atlassian. We hold ISO 9001:2015, CMMI Level 3, and SOC 2 Type 2 certifications, because the clients who trust us with critical infrastructure deserve nothing less.
Over 150 public sector clients. More than 50 commercial enterprises across financial services, healthcare, manufacturing, and retail. The goal is always the same: find where AI creates real leverage, build the data foundation to sustain it, and deliver outcomes that last. Because at BuzzClan, we don't just solve the problem. We own the solution.
Recognition: Inc. 5000 (2021–2025, five consecutive years) | Inc. Regionals Southwest: (2021, 2023, 2025, 2026) | SMU Cox Dallas 100 (2017, 2023, 2024) | USPAACC (2022–2026, five-time honoree)
Similar Jobs
Cyber Security Consultant
About the role
Position Title – RQ00365 - Security Risk Assessment (SRA) Consultant/Cybersecurity Consultant Location: Hybrid – Fredericton, New Brunswick Type: Contract
Position Overview
Successful candidate will lead the end-to-end evaluation of the solution's security posture, including architecture, mobile applications, cloud services, APIs, authentication platforms, and enterprise integrations. This role requires expertise in application security testing, mobile security, cloud security, identity and access management, and industry-standard security frameworks.
Key Responsibilities
Conduct a comprehensive Security Risk Assessment (SRA) of the Digital Trust solution, including mobile applications, cloud services, APIs, vendor platforms, and enterprise integrations. Perform end-to-end architectural risk assessments and identify security vulnerabilities across the Digital Trust ecosystem.
Execute application security testing, including
Static Application Security Testing (SAST) Dynamic Application Security Testing (DAST) Authentication and authorization validation API security assessments Vulnerability Assessment and Penetration Testing (VAPT) Assess security controls for identity management platforms, authentication services, cloud infrastructure, and enterprise applications. Evaluate security architecture using industry frameworks such as OWASP ASVS Level 3 and OWASP MASVS. Review integrations involving Ping Identity, Microsoft Entra ID, BizTalk, AMANDA, and other enterprise systems. Assess mobile applications on iOS and Android platforms for compliance with mobile application security standards. Analyze risks related to credential issuance, authentication, authorization, credential lifecycle, audit logging, and data protection. Produce detailed Security Risk Assessment reports, risk registers, remediation recommendations, and executive summaries. Present findings and recommendations to technical teams, project stakeholders, and senior management. Collaborate with project teams to validate remediation efforts and ensure security best practices are implemented.
Required Qualifications
Minimum 5 years of experience conducting Security Risk Assessments (SRA). Strong experience performing application security testing and vulnerability assessments. Hands-on experience with OWASP ASVS and/or OWASP MASVS security frameworks.
Experience with
Static Code Analysis (SAST) Dynamic Application Security Testing (DAST) Penetration Testing (VAPT) API Security Testing Authentication and Authorization Security Experience assessing cloud-based applications and enterprise architectures. Strong understanding of Identity and Access Management (IAM) platforms. Excellent analytical, documentation, communication, and stakeholder management skills. Strong written and verbal communication skills in English.
Preferred Qualifications
3+ years of experience performing security assessments using OWASP ASVS and/or OWASP MASVS. Experience with identity and authentication platforms such as Ping Identity, PingOne, Microsoft Entra ID (Azure AD), Okta, or similar technologies. Experience conducting security assessments within government, public sector, or regulated environments. Experience producing Security Risk Assessment (SRA) reports for complex enterprise or privacy-sensitive systems. Familiarity with cloud security services, enterprise APIs, mobile application security, and digital identity solutions.
About BuzzClan
BuzzClan is an AI-first technology consulting firm helping government agencies and enterprises drive meaningful digital transformation.
Since 2013, we’ve partnered with organizations to modernize legacy systems, unlock the value of their data, and improve how they operate and scale.
What began as a Texas-based firm has grown into a global organization that delivers solutions across cloud, data, cybersecurity, software engineering, and managed services, with AI embedded in how we design and deliver outcomes rather than treated as an add-on.
Our Services: AI and Machine Learning Services Cloud Consulting and Managed IT Services Data Engineering, Data and Analytics, and Business Intelligence Cyber Security and IT Infrastructure Digital Transformation, QA Services, and ServiceNow Mobile App Development CIO Advisory Staffing Services, Workforce Management Global Capability Centers
We are a certified partner to Oracle, Microsoft Azure, AWS, Google Cloud, Saviynt, and Atlassian. We hold ISO 9001:2015, CMMI Level 3, and SOC 2 Type 2 certifications, because the clients who trust us with critical infrastructure deserve nothing less.
Over 150 public sector clients. More than 50 commercial enterprises across financial services, healthcare, manufacturing, and retail. The goal is always the same: find where AI creates real leverage, build the data foundation to sustain it, and deliver outcomes that last. Because at BuzzClan, we don't just solve the problem. We own the solution.
Recognition: Inc. 5000 (2021–2025, five consecutive years) | Inc. Regionals Southwest: (2021, 2023, 2025, 2026) | SMU Cox Dallas 100 (2017, 2023, 2024) | USPAACC (2022–2026, five-time honoree)