Rq00716 Jobs in Toronto, Ontario, Canada
Create alert for “RQ00716”
Toronto, Ontario, Canada
You've reached the end
Try refining your search for more options
RQ00716 - Security Specialist - Senior
About the role
We are reaching you out to bring an incredible job opportunity to your attention, one that will truly captivate your interest.
Kindly send the following documents to by hrsmss@smsoftconsulting.com
Thursday, July 23, 2026 at 10:00 AM. EST. if that interests you and matches your profile.
Updated Resume in word format (Mandatory)
Skills Matrix and References (Mandatory) Expected hourly rate (Mandatory) Visa Status (Mandatory) LinkedIn ID (Mandatory)
Job Title
RQ00716 - Security Specialist - Senior
Start Date
2026-08-17
Client
Supply Ontario
End Date
2027-08-13
Work Location
525 University Ave, Toronto, Ontario, Canada
#Business Days:
125.00
Job Type
Hybrid
Hours Per Day Or Week
7.25 hours per day (5 Days)
Must Haves
Minimum 8 years of hands-on experience with IPC (very strong) and OAGO audits. Minimum 5 years extensive experience in conducting comprehensive security Threat and Risk Assessment (TRA) using frameworks such as NIST CSF, HTRA, and ISO 27001. Risk Assessment, mitigation recommendations and management with a strong focus on identifying vulnerabilities, analyzing potential impacts, and delivering actionable risk mitigation to stakeholders. 25 points Minimum 5 years of extensive experience with Information security governance, developing policies and standards with a strong ability to identify gaps between the current security posture and industry standards, best practices, and regulatory requirements. 25 points 5+ years of experience authoring executive-level reports, developing cyber security program and risk registers, and delivering presentations to stakeholders and senior leadership. Experience in risk management models for assessing and mitigating various aspects of risk exposure. Experience with risk assessment methodologies such as HTRA and NIST CSF, and frameworks such as ISO 27001/2. Experience with security governance including developing policies, standards, processes and procedures. Hands on experience with IPC (Information Privacy Commissioner) triennial audits. Demonstrated experience in working with various compliance and audit frameworks including, PHIPA, SOC 2 Type II, OAGO An adept team player who is action oriented, with a record of accomplishment of motivating other team members to achieve higher goals.
Description
The Sr. Security Specialist will support and deliver on multiple initiatives related to Security Governance, Risk and Compliance and Cyber Defense Operations. This includes leading multiple initiatives related to security strategy, security audit and compliance requirements and findings, security governance including policies, standards and processes development and security risk management procedures.
Desired Skills
10+ years’ experience in various security domains including third-party risk management, IT audits and/or Security Governance, Risk and Compliance (GRC) Bachelor’s or Master’s degree in Computer Science, Information Technology, Cyber Security, Systems or other related field, or equivalent work experience. Professional certifications in information/cyber security (e.g. CISSP, CCSP, CISA, CISM, CRISC) is required.
Knowledge of prevalent industry standards (ISO 27001/27002, NIST, CIS, COBIT)
Required Skills
An understanding of risk assessment methodologies such as HTRA and CSF, and frameworks such as NIST and ISO 27001/2. Knowledge and experience developing and working with security architecture, and IT management frameworks such as SABSA, and CeBIT. Strong knowledge and demonstrated experience working with compliance and audit frameworks including PHIPA, SOC 2 TII, OAGO audits.
Hands on experience with IPC triennial audits
Technical writing expertise and demonstrated knowledge and experience in developing Information security policies and standards in alignment with PHIPA, IPC requirements and industry standards. Strong understanding and ability to interpret and communicate risk management concepts. Good experience & knowledge of TRA methodologies and other risk assessment methodologies and tools, and familiarity with related security tests and test methodologies Deep understanding of typical security threats, vulnerabilities and safeguards relevant to IT systems. Experience in writing and presenting subject matter information that is both comprehensive and easy to understand. Excellent communication and reporting abilities to effectively present findings and risk mitigation strategies to both technical teams and executive stakeholders. Experience and working knowledge of risk management lifecycle, processes, and concepts. Strong analytical skills to assess potential impacts and likelihoods of various threat scenarios.
Evaluation Criteria
Minimum 5 years extensive experience in conducting comprehensive security Threat and Risk Assessment (TRA) using frameworks such as NIST CSF, HTRA, and ISO 27001. Risk Assessment, mitigation recommendations and management with a strong focus on identifying vulnerabilities, analyzing potential impacts, and delivering actionable risk mitigation to stakeholders - 25 points Minimum 5 years of extensive experience with Information security governance, developing policies and standards with a strong ability to identify gaps between the current security posture and industry standards, best practices, and regulatory requirements - 25 points Minimum 8 years of hands-on experience with IPC and OAGO audits - 30 points 5+ years of experience authoring executive-level reports, developing cyber security program and risk registers, and delivering presentations to stakeholders and senior leadership - 20 points
Deliverables
Deliverables Include, But Are Not Limited To
Development of security policies, standards, procedures, processes.
Development of frameworks and models for select security capabilities
Support implementation of new enterprise governance, risk and compliance tool. Support development of a cyber security strategy and key aspects of program development including program performance reporting. Support on completion of security assessment using tools based on NIST CSF. Review of Threat Risk Assessment, VA scan report, Penetration Test report and other security documents.
Notes
Additional Terms
This Engagement Assignment is the equivalent of 125 Business Days to be worked at between the Start and End Dates. The Engagement Assignment may be extended for unused Business Days at the Agency's discretion. The resource will work approximately 78 Business Days in FY26/27 and 47 Business Days in FY 27/28.
The resource will comply with the Agency’s policies and procedures.
The Agency systems cannot be accessed from outside the province of Ontario, and Agency assets including laptops and related equipment cannot be removed from the province of Ontario, without prior written approval from the Agency.
Assignment Type: This position is currently listed as "Hybrid". The resource under this request will be required to work onsite as per Hiring Manager sole discretion.
The resource will be issued an Agency laptop and is expected to provide at their own expense at least one additional monitor, an external keyboard, and a mouse. In addition, when the resource is working from their home location, they must have a private office space and are not permitted to work in an open communal space. Internet connection must be hard-wired and suitable bandwidth to support the IT requirements of this role. If these conditions cannot be met within their home office space, the resource will transition to full time in office, and the hybrid option will no longer be available.
Location: Hybrid
Public Sector Experience: Must Have
Not the right fit? Search for RQ00716 jobs in Toronto, Ontario, Canada
About S M Software Solutions Inc
SMSS Inc. is the best solution company specialized in providing Information Technology and Management Consulting. We provide value for money to our clients by delivering the best quality technical services and solutions at reasonable rates. We also provide the best working environment for our staff and consultants. It is a growing IT services provider having wide array of solutions from Business Strategy Analysis to implementation and execution of Information Technology as well as management aspects of a business entity.