Location: Remote with 2 meetings/month in Montreal
Duration: 3 years (plus a 1-year option to extend)
Security Clearance: Reliability Status
Responsibilities
- Plan and initiate IT Security Vulnerability Analysis (SVA) activities, identifying key stakeholders, required documentation, and expected deliverables.
- Perform security vulnerability analysis across IT systems, assess systems, and document findings.
- Evaluate risks associated with identified vulnerabilities and recommend mitigation measures.
- Review Vulnerability Assessment and Penetration Testing (VAPT) results and validate implementation evidence.
- Assess and tailor security controls and review security control implementations.
- Assess cybersecurity risks from existing Threat and Risk Assessments (TRAs) and support residual risk determination.
- Develop, review, and complete security vulnerability analysis deliverables and supporting documentation.
- Review system architectures, conduct document reviews, and support assessment workshops.
- Present findings and recommendations to stakeholders and participate in technical discussions.
- Support the preparation of authorization packages and risk-based authorization decisions.
- Support periodic reviews, reassessments, and continuous monitoring activities.
- Provide knowledge transfer to internal personnel through presentations, briefings, workshops, and the sharing of methodologies and lessons learned.
Qualifications
- A minimum of three (3) distinct projects of experience in developing, reviewing, updating, or supporting the preparation of a minimum of four (4) of the following deliverables:
- SA&A Plans;
- Security Requirements Traceability Matrices (SRTMs);
- Management Action Plans (MAPs);
- Security Assessment Reports (SARs);
- Statements of Risk Acceptance (SoRAs); and
- Authorization to operate Packages.
- Experience developing, reviewing, and completing security vulnerability analyses, including presenting findings and recommendations to stakeholders.
- Experience applying Government of Canada cybersecurity requirements, Canadian Centre for Cyber Security (CCCS) guidance, ITSG-33, NIST, ISO 28001, or other recognized cybersecurity frameworks or standards in support of vulnerability assessments, risk assessments, or authorization activities.
- Experience assessing IT systems, documenting findings, and evaluating risks.
- Experience reviewing Vulnerability Assessment and Penetration Testing (VAPT) results.
- Strong communication and stakeholder facilitation skills to support risk-based decisions while maintaining project objectives.
Security Clearance: Reliability Status
AI Disclosure: We do not use artificial intelligence (AI) tools to screen, assess, or select applicants at any stage of our recruitment process. All applications are reviewed by our recruitment team.
OXARO is committed to fostering an inclusive, equitable and respectful workplace where every individual feels valued and empowered to contribute their best. We believe that diversity drives innovation and strengthens our ability to serve our clients and communities. We are dedicated to ensuring a fair and unbiased recruitment process and welcome applications from members of the four designated groups under the Employment Equity Act: women, Indigenous peoples, persons with disabilities and members of visible minorities.
Accommodations are available upon request for candidates taking part in all aspects of the recruitment process.
We sincerely thank all applicants for their interest in this opportunity. While we appreciate every application, only those selected for an interview will be contacted.