About the role
Senior Security Specialist (Threat Risk Assessment) Location: Hybrid – Toronto, ON (University Ave., up to 3 days onsite at manager's discretion) Contract: September 1, 2026 – March 31, 2027 Duration: 151 Business Days Hours: Monday–Friday (Full-Time) Incorp Rate: $95-$105
About the Role Our client is seeking an experienced Senior Security Specialist to lead end-to-end Threat Risk Assessments (TRAs) across enterprise systems, applications, infrastructure, and business processes. In this role, you will identify security risks, evaluate vulnerabilities, and provide practical recommendations to strengthen the organization's overall security posture. Working closely with business and technical stakeholders, you will apply industry-standard risk management and threat modeling frameworks to assess security risks, document findings, and present recommendations to both technical teams and executive leadership.
Key Responsibilities Lead end-to-end Threat Risk Assessments (TRAs) for enterprise systems, applications, and infrastructure. Define assessment scope with business and technical stakeholders. Conduct risk assessments using frameworks such as ISO 31000, NIST RMF, or FAIR. Perform threat modeling using methodologies such as STRIDE, PASTA, and MITRE ATT&CK. Review system architecture, data flows, and existing security controls. Identify threats, vulnerabilities, and potential business impacts. Develop risk registers and track remediation activities. Prepare detailed risk assessment reports with mitigation recommendations. Present findings to technical teams, project stakeholders, and executive leadership. Ensure compliance with organizational policies, security standards, and regulatory requirements, including PHIPA. Support audit and compliance initiatives. Contribute to the continuous improvement of security governance and risk management processes. Stay current on emerging cybersecurity threats, vulnerabilities, and best practices.
Must-Have Qualifications 5–7 years of experience conducting Threat Risk Assessments (TRA) using ISO 31000, NIST RMF, or FAIR. 3–5 years of hands-on experience with threat modeling methodologies such as STRIDE, PASTA, or MITRE ATT&CK. 5+ years of experience in Information Security Governance, including security policies, standards, and controls aligned with ISO 27001, NIST CSF, and CIS Controls. Strong understanding of cybersecurity risk assessment methodologies and risk analysis. Experience creating risk registers, executive reports, and technical documentation. Excellent communication skills with the ability to present technical findings to both technical and executive audiences.
Preferred Qualifications Experience working within the Ontario Public Sector or Healthcare environment. Knowledge of PHIPA and healthcare information security requirements. Experience supporting security audits, compliance initiatives, and governance programs. Strong analytical and problem-solving skills. Ability to manage multiple priorities in a fast-paced environment.
About BITS Recruiting
BITS Recruiting is a Canadian-owned staffing firm, specialized in technicians, manufacturing and administrative verticals.
From the pre-screen to the initial interview, to the background check, we provide every step of the recruitment services essential to our clients. BITS Recruiting facilitates the hiring processes and helps our clients to focus on their core business.
No position is an obstacle for us to fill! Our team specializes in technicians, administrative and manufacturing staffing.
BITS Recruiting finds the right candidates, by exceeding the expectations of our clients in terms of overall quality, reliability and speed to market. We offer temporary, permanent or contract solutions to our clients.
Similar Jobs
About the role
Senior Security Specialist (Threat Risk Assessment) Location: Hybrid – Toronto, ON (University Ave., up to 3 days onsite at manager's discretion) Contract: September 1, 2026 – March 31, 2027 Duration: 151 Business Days Hours: Monday–Friday (Full-Time) Incorp Rate: $95-$105
About the Role Our client is seeking an experienced Senior Security Specialist to lead end-to-end Threat Risk Assessments (TRAs) across enterprise systems, applications, infrastructure, and business processes. In this role, you will identify security risks, evaluate vulnerabilities, and provide practical recommendations to strengthen the organization's overall security posture. Working closely with business and technical stakeholders, you will apply industry-standard risk management and threat modeling frameworks to assess security risks, document findings, and present recommendations to both technical teams and executive leadership.
Key Responsibilities Lead end-to-end Threat Risk Assessments (TRAs) for enterprise systems, applications, and infrastructure. Define assessment scope with business and technical stakeholders. Conduct risk assessments using frameworks such as ISO 31000, NIST RMF, or FAIR. Perform threat modeling using methodologies such as STRIDE, PASTA, and MITRE ATT&CK. Review system architecture, data flows, and existing security controls. Identify threats, vulnerabilities, and potential business impacts. Develop risk registers and track remediation activities. Prepare detailed risk assessment reports with mitigation recommendations. Present findings to technical teams, project stakeholders, and executive leadership. Ensure compliance with organizational policies, security standards, and regulatory requirements, including PHIPA. Support audit and compliance initiatives. Contribute to the continuous improvement of security governance and risk management processes. Stay current on emerging cybersecurity threats, vulnerabilities, and best practices.
Must-Have Qualifications 5–7 years of experience conducting Threat Risk Assessments (TRA) using ISO 31000, NIST RMF, or FAIR. 3–5 years of hands-on experience with threat modeling methodologies such as STRIDE, PASTA, or MITRE ATT&CK. 5+ years of experience in Information Security Governance, including security policies, standards, and controls aligned with ISO 27001, NIST CSF, and CIS Controls. Strong understanding of cybersecurity risk assessment methodologies and risk analysis. Experience creating risk registers, executive reports, and technical documentation. Excellent communication skills with the ability to present technical findings to both technical and executive audiences.
Preferred Qualifications Experience working within the Ontario Public Sector or Healthcare environment. Knowledge of PHIPA and healthcare information security requirements. Experience supporting security audits, compliance initiatives, and governance programs. Strong analytical and problem-solving skills. Ability to manage multiple priorities in a fast-paced environment.
About BITS Recruiting
BITS Recruiting is a Canadian-owned staffing firm, specialized in technicians, manufacturing and administrative verticals.
From the pre-screen to the initial interview, to the background check, we provide every step of the recruitment services essential to our clients. BITS Recruiting facilitates the hiring processes and helps our clients to focus on their core business.
No position is an obstacle for us to fill! Our team specializes in technicians, administrative and manufacturing staffing.
BITS Recruiting finds the right candidates, by exceeding the expectations of our clients in terms of overall quality, reliability and speed to market. We offer temporary, permanent or contract solutions to our clients.