About the role
Stafingo is Hiring – Senior IT Security Specialist | Threat & Risk Assessment-Hybrid-GTA
Stafingo is currently recruiting a Senior IT Security Specialist for a confidential public-sector client in Ontario. We are seeking an experienced cybersecurity professional with strong hands-on experience in Threat Risk Assessments (TRA), threat modelling, security governance, risk management, compliance, and executive reporting.
This is an excellent opportunity for a senior security professional who can work across technical and business teams, assess complex technology environments, identify security risks, and provide practical recommendations to support informed security and business decisions.
Position Details : Position: Senior IT Security Specialist Focus: Threat Risk Assessment / Cybersecurity Risk Location: GTA – Hybrid(3 days onsite, 2 days home) Onsite: Up to 3 days per week, based on project requirements Contract: September 1st, 2026 – March 2027 (with potential for extension) Submission Deadline: Friday, August 17, 2026 at 5 pm EST Public Sector Experience: Preferred Compensation: $90-$110 per hour (depending on skills and experience)
Key Responsibilities Lead end-to-end Threat Risk Assessments (TRAs) covering applications, information systems, infrastructure, business processes, and data. Work with business and technical stakeholders to define assessment scope, understand system architecture, data flows, business requirements, and security controls. Identify and assess threats, vulnerabilities, attack vectors, and security weaknesses. Conduct threat modeling using approaches such as STRIDE, PASTA, MITRE ATT&CK, or similar methodologies. Develop data-flow diagrams, threat models, risk matrices, and risk registers to support security assessments. Evaluate the likelihood and potential business impact of identified risks and establish appropriate risk ratings. Conduct security gap assessments against organizational policies, industry standards, regulatory requirements, and recognized frameworks. Develop practical risk mitigation and remediation plans and support tracking of risks through resolution. Assess security controls and alignment with frameworks such as ISO 27001, NIST CSF, NIST RMF, CIS Controls, and ISO 31000. Prepare detailed TRA reports, executive summaries, risk registers, gap analyses, and remediation recommendations. Translate complex technical security findings into clear business impacts and recommendations for senior leadership. Prepare and deliver executive-level presentation decks to communicate findings, risks, priorities, and recommended actions. Collaborate with cybersecurity, architecture, infrastructure, application, business, and other technology teams. Support compliance, audit, risk treatment, and continuous improvement activities. Maintain clear documentation and provide knowledge transfer to internal teams throughout the engagement.
Required Qualifications : The successful candidate should have: 5–7+ years of experience conducting Threat Risk Assessments or cybersecurity risk assessments. Strong hands-on experience with risk management frameworks such as ISO 31000, NIST RMF, and/or FAIR. 5+ years of information security governance and risk management experience. Practical experience with threat modeling methodologies such as STRIDE, PASTA, MITRE ATT&CK, or comparable approaches. Strong understanding of ISO 27001, NIST CSF, CIS Controls, and security governance practices. Experience identifying, evaluating, and prioritizing cybersecurity threats and vulnerabilities. Experience developing risk assessment matrices, risk registers, TRA reports, gap analyses, and mitigation plans. Experience creating system/data-flow diagrams and threat models. Strong analytical, problem-solving, documentation, and decision-making skills. Excellent written and verbal communication skills, with the ability to communicate effectively with both technical teams and executives. Familiarity with privacy, regulatory, legal, and compliance requirements. Ability to work independently while collaborating effectively with cross-functional teams.
Nice-to-Have Experience : Previous public-sector or government experience. Experience working in highly regulated environments. Experience assessing cloud, SaaS, enterprise applications, and infrastructure. Experience with vulnerability assessment tools such as Nessus, OpenVAS, or similar platforms. Experience supporting privacy, information protection, audit, or regulatory compliance initiatives. Experience presenting cybersecurity findings to senior executives and leadership teams.
Key Deliverables : The successful resource will be expected to produce deliverables including: Comprehensive Threat Risk Assessment (TRA) Reports Risk Registers and risk assessment matrices Threat Modelling and Data-Flow Diagrams Security Gap Analysis Vulnerability assessment findings Asset inventory and classification documentation Risk Mitigation & Remediation Plans Compliance/control mapping Executive summaries Executive Presentation Decks Supporting documentation and knowledge-transfer materials
Stafingo is supporting a confidential public-sector search and will be submitting one qualified resource for this opportunity.
If you have strong experience in Threat Risk Assessment, threat modelling, cybersecurity governance, risk management, and executive-level security reporting, we encourage you to apply to the job posting directly or send your resume to harpreet@stafingo.com for immediate consideration.
About StafinGo
Welcome to StafinGo, a dynamic force in the world of staffing solutions. Elevate your workforce with our tailored recruitment services that blend innovation, expertise, and personalized attention. At StafinGo, we pride ourselves on being more than a staffing agency; we are your strategic staffing partner. With a deep understanding of the evolving job market, we navigate the complexities of recruitment, ensuring your business thrives through the power of exceptional talent.
Our Core Values: Excellence: We strive for excellence in every hiring, connecting businesses with candidates who not only meet the job requirements but also contribute to a culture of success.
Partnership: Your goals are our goals. We believe in collaborative partnerships, working closely with clients and candidates to build lasting connections that drive mutual success.
Innovation: In a rapidly changing world, we embrace innovation in our approach. From cutting-edge sourcing techniques to modern recruitment strategies, we stay ahead to meet your evolving needs.
Our Comprehensive Services: Recruitment and Placement: Tailored solutions for permanent, temporary, and contract staffing needs. Rigorous screening processes to match your company with the most qualified candidates.
Project Staffing: On-demand expertise for short-term projects, ensuring timely and efficient project completion. Access to a diverse talent pool with specialized skills.
Global Talent Acquisition: Expand your horizons with our global talent acquisition services. Navigate international recruitment complexities with ease.
Connect with us to stay updated on the latest industry trends, recruitment insights, and career opportunities. Follow our page for valuable content, job alerts, and more.
Let's build a future of success together. Whether you're a candidate seeking the next career leap or a company looking for the perfect fit, StafinGo is here to make it happen.
Similar Jobs
About the role
Stafingo is Hiring – Senior IT Security Specialist | Threat & Risk Assessment-Hybrid-GTA
Stafingo is currently recruiting a Senior IT Security Specialist for a confidential public-sector client in Ontario. We are seeking an experienced cybersecurity professional with strong hands-on experience in Threat Risk Assessments (TRA), threat modelling, security governance, risk management, compliance, and executive reporting.
This is an excellent opportunity for a senior security professional who can work across technical and business teams, assess complex technology environments, identify security risks, and provide practical recommendations to support informed security and business decisions.
Position Details : Position: Senior IT Security Specialist Focus: Threat Risk Assessment / Cybersecurity Risk Location: GTA – Hybrid(3 days onsite, 2 days home) Onsite: Up to 3 days per week, based on project requirements Contract: September 1st, 2026 – March 2027 (with potential for extension) Submission Deadline: Friday, August 17, 2026 at 5 pm EST Public Sector Experience: Preferred Compensation: $90-$110 per hour (depending on skills and experience)
Key Responsibilities Lead end-to-end Threat Risk Assessments (TRAs) covering applications, information systems, infrastructure, business processes, and data. Work with business and technical stakeholders to define assessment scope, understand system architecture, data flows, business requirements, and security controls. Identify and assess threats, vulnerabilities, attack vectors, and security weaknesses. Conduct threat modeling using approaches such as STRIDE, PASTA, MITRE ATT&CK, or similar methodologies. Develop data-flow diagrams, threat models, risk matrices, and risk registers to support security assessments. Evaluate the likelihood and potential business impact of identified risks and establish appropriate risk ratings. Conduct security gap assessments against organizational policies, industry standards, regulatory requirements, and recognized frameworks. Develop practical risk mitigation and remediation plans and support tracking of risks through resolution. Assess security controls and alignment with frameworks such as ISO 27001, NIST CSF, NIST RMF, CIS Controls, and ISO 31000. Prepare detailed TRA reports, executive summaries, risk registers, gap analyses, and remediation recommendations. Translate complex technical security findings into clear business impacts and recommendations for senior leadership. Prepare and deliver executive-level presentation decks to communicate findings, risks, priorities, and recommended actions. Collaborate with cybersecurity, architecture, infrastructure, application, business, and other technology teams. Support compliance, audit, risk treatment, and continuous improvement activities. Maintain clear documentation and provide knowledge transfer to internal teams throughout the engagement.
Required Qualifications : The successful candidate should have: 5–7+ years of experience conducting Threat Risk Assessments or cybersecurity risk assessments. Strong hands-on experience with risk management frameworks such as ISO 31000, NIST RMF, and/or FAIR. 5+ years of information security governance and risk management experience. Practical experience with threat modeling methodologies such as STRIDE, PASTA, MITRE ATT&CK, or comparable approaches. Strong understanding of ISO 27001, NIST CSF, CIS Controls, and security governance practices. Experience identifying, evaluating, and prioritizing cybersecurity threats and vulnerabilities. Experience developing risk assessment matrices, risk registers, TRA reports, gap analyses, and mitigation plans. Experience creating system/data-flow diagrams and threat models. Strong analytical, problem-solving, documentation, and decision-making skills. Excellent written and verbal communication skills, with the ability to communicate effectively with both technical teams and executives. Familiarity with privacy, regulatory, legal, and compliance requirements. Ability to work independently while collaborating effectively with cross-functional teams.
Nice-to-Have Experience : Previous public-sector or government experience. Experience working in highly regulated environments. Experience assessing cloud, SaaS, enterprise applications, and infrastructure. Experience with vulnerability assessment tools such as Nessus, OpenVAS, or similar platforms. Experience supporting privacy, information protection, audit, or regulatory compliance initiatives. Experience presenting cybersecurity findings to senior executives and leadership teams.
Key Deliverables : The successful resource will be expected to produce deliverables including: Comprehensive Threat Risk Assessment (TRA) Reports Risk Registers and risk assessment matrices Threat Modelling and Data-Flow Diagrams Security Gap Analysis Vulnerability assessment findings Asset inventory and classification documentation Risk Mitigation & Remediation Plans Compliance/control mapping Executive summaries Executive Presentation Decks Supporting documentation and knowledge-transfer materials
Stafingo is supporting a confidential public-sector search and will be submitting one qualified resource for this opportunity.
If you have strong experience in Threat Risk Assessment, threat modelling, cybersecurity governance, risk management, and executive-level security reporting, we encourage you to apply to the job posting directly or send your resume to harpreet@stafingo.com for immediate consideration.
About StafinGo
Welcome to StafinGo, a dynamic force in the world of staffing solutions. Elevate your workforce with our tailored recruitment services that blend innovation, expertise, and personalized attention. At StafinGo, we pride ourselves on being more than a staffing agency; we are your strategic staffing partner. With a deep understanding of the evolving job market, we navigate the complexities of recruitment, ensuring your business thrives through the power of exceptional talent.
Our Core Values: Excellence: We strive for excellence in every hiring, connecting businesses with candidates who not only meet the job requirements but also contribute to a culture of success.
Partnership: Your goals are our goals. We believe in collaborative partnerships, working closely with clients and candidates to build lasting connections that drive mutual success.
Innovation: In a rapidly changing world, we embrace innovation in our approach. From cutting-edge sourcing techniques to modern recruitment strategies, we stay ahead to meet your evolving needs.
Our Comprehensive Services: Recruitment and Placement: Tailored solutions for permanent, temporary, and contract staffing needs. Rigorous screening processes to match your company with the most qualified candidates.
Project Staffing: On-demand expertise for short-term projects, ensuring timely and efficient project completion. Access to a diverse talent pool with specialized skills.
Global Talent Acquisition: Expand your horizons with our global talent acquisition services. Navigate international recruitment complexities with ease.
Connect with us to stay updated on the latest industry trends, recruitment insights, and career opportunities. Follow our page for valuable content, job alerts, and more.
Let's build a future of success together. Whether you're a candidate seeking the next career leap or a company looking for the perfect fit, StafinGo is here to make it happen.