- 5+ years’ experience in various security domains including third-party risk management, IT audits and/or Security Governance, Risk and Compliance (GRC
- Knowledge of prevalent industry standards (ISO 27001/27002, NIST, CIS, COBIT)
- 3+ years' experience in Threat risk assessment methodologies (TRA) such as HTRA and CSF, and frameworks such as NIST and ISO 27001/2
- Experience in writing and presenting subject matter information that is both comprehensive and easy to understand.
- Experience and working knowledge of risk management lifecycle, processes, and concepts
- Demonstrated experience with presenting materials to large audience
- Experience in writing and presenting subject matter information that is both comprehensive and easy to understand.
- Experience and working knowledge of risk management lifecycle, processes, and concepts.
- Working knowledge of GRC tools used to support security governance. Working knowledge and expertise in the Personal Health Information Protection Act (PHIPA) is an asset.
- Working experience in security architecture domain
Required Skills:
- Strong understanding and ability to interpret and communicate risk management concepts.
- Deep Understanding of typical security threats, vulnerabilities and safeguards relevant to application development, test and QA environments, and IT (datacenter) operations.
- Good experience & knowledge of TRA methodologies and other risk assessment methodologies and tools, and familiarity with related security tests and test methodologies
- An adept team player who is action oriented, with a record of accomplishment of motivating other team members to achieve higher goals and improving the impact of technology initiatives.