New Value Solutions, a Canadian IT consulting and professional services firm with offices in Canada, US and the EU, is seeking a Cybersecurity Senior Technical Lead. This is a contract opportunity and is a hybrid role requiring onsite work at our client. The successful candidate will be the senior technical authority for the identity team, application security, and 3rd party risks. Your primary responsibility will be to turn business requirements into designs, policies, controls, and processes, oversee delivery, and coach the teams to decide more on their own.
The ideal candidate is someone who has designed and built security solutions. We are not looking for experience centered on SOC operations, incident management, or network and perimeter security.
Responsibilities:
- Act as subject matter expert and first escalation point for the three teams, resolving design and risk decisions without routing them to the Director.
- Own complex escalations and coach engineers to handle routine ones, including business requests that are unclear or conflict with security standards.
- Make decisions through a structured risk process: frame the problem, identify missing details, recommend a direction, and document the decision.
- Work with business decision makers to turn requirements into implementations, policies, standards, controls, and processes, with testable acceptance criteria agreed before work starts.
- Oversee junior and intermediate staff through delivery: assign and track work, clarify requirements, remove blockers, and verify results meet the requirement before approval.
- Lead security design risk assessments (SDRA) for new vendors and third party applications.
- When the business pushes back, explain the risk and negotiate compensating controls or formal risk acceptance.
- Review security policies, standards, and design documents and bring them to approval quality.
- Maintain traceability from business requirement to delivered control for stakeholders and auditors, and report progress, risks, and tradeoffs in plain language.
Qualifications
- 10+ years in IT security, including 4+ years as a lead, principal, or senior technical design authority directing several engineering teams at once.
- Experienced in design and implementation decisions, not only administered tools or done analyst work. Your primary background is identity engineering, application security engineering, or both.
- Designed, built, and customized identity solutions end to end, not only operated identity tools. Your experience spans workforce, customer (CIAM), privileged (PAM), and nonhuman identities, plus Conditional Access.
- Practical experience with one or two major platforms such as Microsoft Entra ID, Okta or Auth0, Ping Identity, ForgeRock, SailPoint, or CyberArk. You can compare vendors across a multivendor landscape and know SAML 2.0, OAuth 2.0, OpenID Connect, SCIM, FIDO2, passkeys, and MFA well.
- Define and enforce Joiner/Mover/Leaver (JML) lifecycle, access certification, RBAC and ABAC models, role mining, and segregation of duties. Set identity policies and standards, and manage exceptions and risk acceptance.
- Threat modeling, secure design reviews, and security requirements in the SDLC. You interpret SAST, DAST, SCA, and secrets scanning results, guide remediation priorities, and know OWASP Top 10, ASVS, and API Security Top 10. You can assess web, API, cloud native, and SaaS designs for weaknesses in authentication, authorization, session management, data protection, and logging.
- Led security design risk assessments and run or improved a third party risk management (TPRM) process. You analyze a vendor's design for attack surface, trust relationships, excessive permissions, OAuth consent, data flows and residency, and supply chain risk. You rate findings, define mitigations, and state residual risk clearly.
- Defined vendor requirements for identity, data protection, logging, vulnerability management, resilience, compliance evidence (SOC 2 Type II, ISO 27001), and contract terms. You handle gaps, such as a vendor without SCIM support, with compensating controls and a clear risk conversation.
- Build end to end security blueprints and target state designs grounded in Zero Trust. You weigh security, business impact, cost, and usability, then make and defend a decision.
- Working knowledge of at least two of NIST CSF, NIST SP 800-53, ISO 27001, SOC 2, or CIS Controls. You write policies, standards, reference designs, and design decision records.
- Proven mentoring of junior and intermediate engineers across teams, with constructive, actionable reviews of their work. You build trusted relationships with business decision makers and present risk clearly to executives and nontechnical audiences.
Desired Qualifications:
- Certifications such as CISSP, CISSP-ISSAP, CCSP, CSSLP, Microsoft SC-300, or Okta Certified Professional
- Experience in Canadian public sector or regulated organizations
- Familiarity with BC FOIPPA and Canadian Centre for Cyber Security guidance such as ITSG-33
- Cloud security experience in Azure, AWS, or GCP, including IAM, workload identity, and posture management
- Awareness of post quantum cryptography and crypto agility planning
- A background in software development or DevSecOps