Security Specialist
Job Summary
Our Client is looking for a Senior Security Specialist with strong experience across penetration testing red team exercises threat hunting vulnerability assessments source code review and network and application security.
The successful candidate will support cybersecurity initiatives across Ontario Provincial Police and OPS province wide I&IT infrastructure applications systems and information resources. This role requires hands-on offensive security
expertise strong technical analysis and the ability to document risks and provide recommendations to both technical and executive audiences.
10 plus years of experience in penetration testing red team tactics threat hunting or network and application security
Strong experience conducting penetration tests and vulnerability assessments
Strong experience with red team tools techniques tactics and strategies
Strong experience with network threat hunting and network vulnerability assessments
Experience reviewing source code and identifying security weaknesses
Experience writing security reports documenting risks and presenting recommendations to diverse audiences
Strong understanding of security architecture application security and network security testing
Hands-on experience with web application security testing
Experience identifying and exploiting common application and infrastructure vulnerabilities
Knowledge of vulnerability assessment methodologies tools and techniques
Knowledge of secure system design security safeguards and security controls
Ability to assess security requirements across complex and distributed systems
Knowledge of security technologies such as encryption access controls firewalls authentication digital signatures and malware protection
Working knowledge of security audit procedures and protocols
Experience establishing secure environments at the network operating system or application level
Strong analytical problem-solving and decision-making skills
Strong written and verbal communication skills
Ability to manage competing priorities meet deadlines and work with multiple stakeholders
Public sector experience
Experience in law enforcement public safety or highly sensitive environments
Experience with Windows and Linux operating systems
Experience with programming languages such and Java
Experience with DAST SAST source code review log collection and log analysis
Experience with IDS IPS SIEM network monitoring and threat hunting tools
Experience with incident response forensic investigation business recovery and disaster recovery planning
Experience performing threat and risk assessments
Experience with Public Key Infrastructure
Knowledge of Information Management principles concepts policies and practices
Experience with secure design frameworks and agile delivery environments