Job Openings RQ00742 - Security Specialist - Senior

About the job RQ00742 - Security Specialist - Senior

RQ00742 - Security Specialist - Senior

Duration: 7 + Months (151 Business Days)

Location: Hybrid (upto 3 days onsite at manager's discretion) - 525 University Avenue


Must Haves:

  • Risk Management & Assessment – 5–7 years - Proven experience in conducting threat risk assessments using frameworks like ISO 31000, NIST RMF, or FAIR.
  • Threat Modeling – 3–5 years - Practical knowledge of threat modeling techniques (e.g., STRIDE, PASTA, MITRE ATT&CK), including development of data flow diagrams and attack vectors.
  • Information Security Governance – 5+ years-Strong understanding of security policies, standards, and controls aligned with ISO 27001, NIST CSF, and CIS Controls.
  • Communication & Reporting – 5+ years-skilled in writing technical and executive-level reports, risk registers, and presenting to stakeholders and leadership.

Nice to Have Skill:

  • Public Sector Experience (preferred)

Background Information:

This engagement involves driving the end-to-end execution of a Threat Risk Assessment (TRA) to evaluate the security posture of the information system, application, infrastructure, and business process. The objective is to identify potential threats, assess vulnerabilities, and determine the likelihood and impact of various risk scenarios affecting confidentiality, integrity, and availability.

Key activities included:

  • Scoping the assessment in collaboration with business and technical stakeholders.
  • Conducting structured risk analysis using recognized frameworks such as ISO 31000, NIST RMF, or FAIR.
  • Performing threat modeling (e.g., STRIDE, MITRE ATT&CK) to map potential attack vectors and security gaps.
  • Reviewing system architecture, data flows, and existing controls.
  • Assessing compliance with relevant regulatory and organizational security requirements.
  • Documenting findings in a detailed TRA report, including risk ratings and actionable mitigation recommendations.
  • Presenting results to executive leadership and supporting integration of risk treatments into the broader security strategy.

Skills needed:

  • In-depth knowledge of risk management frameworks (e.g., ISO 31000, NIST RMF – Risk Management Framework) and threat modelling methodologies (e.g., STRIDE, DREAD).
  • Expertise in identifying, evaluating, and prioritizing threats and vulnerabilities across physical, cyber, and operational domains.
  • Strong analytical skills to assess potential impacts and likelihoods of various threat scenarios.
  • Proficiency risk assessment matrices
  • Excellent communication and reporting abilities to effectively present findings and risk mitigation strategies to both technical teams and executive stakeholders.
  • Familiarity with legal, regulatory, and compliance requirements, ensuring assessments align with organizational and industry standards (e.g., PHIPAA - Personal Health Information Protection Act).
  • Proactive mindset and situational awareness to anticipate and adapt to emerging threats in a dynamic risk environment.

Responsibilities:

  • Drive end-to-end Threat Risk Assessment (TRA) initiatives across systems, processes, and assets.
  • Develop and apply threat models to assess organizational security posture.
  • Collaborate with stakeholders to align assessments with business objectives and risk tolerance.
  • Analyze vulnerabilities and assess threats to determine likelihood and potential impact.
  • Produce detailed TRA reports, documenting findings, recommendations, and risk ratings.
  • Maintain risk registers and track remediation efforts.
  • Propose actionable mitigation strategies based on assessment outcomes.
  • Ensure alignment with:
    • Regulatory requirements
    • Industry standards
    • Organizational security policies
  • Communicate findings effectively to both technical teams and executive leadership.
  • Support audit and compliance activities as needed.
  • Contribute to the continuous improvement of risk management frameworks and methodologies.
  • Stay informed on emerging threats, vulnerabilities, and security best practices.

Desired Skills:

  • Demonstrated expertise in enterprise risk analysis, with a solid background in applying risk management frameworks such as ISO 31000, FAIR (Factor Analysis of Information Risk), and NIST RMF to identify, evaluate, and prioritize organizational security risks.
  • Hands-on experience conducting structured threat analysis, utilizing methodologies like STRIDE, PASTA (Process for Attack Simulation and Threat Analysis), and MITRE ATT&CK. Familiarity with creating threat models, mapping attack surfaces, and visualizing system flows to uncover security weaknesses.
  • Strong command of cybersecurity governance practices, including the development and enforcement of information security policies and standards. Practical understanding of how to align internal controls with recognized frameworks like ISO 27001, NIST CSF, and the CIS Critical Security Controls.
  • Proven ability to translate technical risk findings into clear business language, producing high-quality documentation such as executive summaries, detailed risk reports, and stakeholder presentations. Skilled in managing communication between technical teams and leadership to drive informed decision-making.

Required Skills:

  • Risk Management & Assessment – 5–7 years - Proven experience in conducting threat risk assessments using frameworks like ISO 31000, NIST RMF, or FAIR.
  • Threat Modeling – 3–5 years - Practical knowledge of threat modeling techniques (e.g., STRIDE, PASTA, MITRE ATT&CK), including development of data flow diagrams and attack vectors.
  • Information Security Governance – 5+ years-Strong understanding of security policies, standards, and controls aligned with ISO 27001, NIST CSF, and CIS Controls.
  • Communication & Reporting – 5+ years-skilled in writing technical and executive-level reports, risk registers, and presenting to stakeholders and leadership.


AI Disclaimer: Source Code may use artificial intelligence (AI) tools to assist in certain aspects of its recruiting and business operations.

Note: The higher end of the range is intended for absolutely exceptional candidates who meet all must-have requirements and most or all nice-to-have qualifications. The client will evaluate candidates based on both rate expectations and overall skill set when shortlisting.

INCORPORATED RATE RANGE (7.25 billable hours per day)

  • $96.55/hr - $115.86/hr Inc.

T4 RATE RANGE (7.25 billable hours per day)

  • $77.24/hr - $92.69/hr T4