TRA & SA&A Analyst

Work set-up: 
Full Remote
Contract: 
Experience: 
Expert & Leadership (>10 years)
Work from: 

Offer summary

Qualifications:

Minimum of 10 years of experience in Threat and Risk / SA&A / C&A in IT security., Educational background in Information Technology or related fields., Knowledge of Federal, Provincial, or Territorial IT security policies and standards., Experience with security certification, accreditation processes, and risk mitigation strategies..

Key responsibilities:

  • Review and analyze IT security policies, standards, and risk mitigation strategies.
  • Identify threats and vulnerabilities in operating systems and wireless architectures.
  • Develop reports such as threat assessments, privacy impact assessments, and risk analyses.
  • Conduct certification and accreditation activities, including security testing and evaluation.

TRM Technologies Inc. logo
TRM Technologies Inc. SME https://www.trm.ca
51 - 200 Employees
See all jobs

Job description


Location Ottawa
Language English Required
Security Clearance Secret Security Clearance Required

We are actively looking for Information Technology Security TRA and C&A Analysts with 10 + years of Threat and Risk SA&A C&A Experience.

Responsibilities could include but are not limited to
  • Review, analyze, andor apply Federal, Provincial or Territorial IT Security policies, System IT Security Certification & Accreditation processes, IT Security products, safeguards and best practices, and the IT Security risk mitigation strategies
  • Identify threats to, and vulnerabilities of operating systems (such as MS, Unix, Linux, and Novell), and wireless architectures
  • Identify personnel, technical, physical, and procedural threats to and vulnerabilities of Federal, Provincial or Territorial IT systems
  • Develop reports such as: Data security analysis, Concepts of operation, Statements of Sensitivity (SoSs), Threat assessments, Privacy Impact Assessments (PIAs), Nontechnical Vulnerability Assessments, Risk assessments, IT Security threat, vulnerability andor risk briefings
  • Conduct Certification activities such as: Develop Security Certification Plans, Verify that security safeguards meet the applicable policies and standards, Validate the security requirements by mapping the systemspecific security policy to the functional security requirements, and mapping the security requirements through the various stages of design documents, Verify that security safeguards have been implemented correctly and that assurance requirement have been met. This includes confirming that the system has been properly configured, and establishing that the safeguards meet applicable standards, Conduct security testing and evaluation (ST&E) to determine if the technical safeguards are functioning correctly, Assess the residual risk provided by the risk assessment to determine if it meets an acceptable level of risk
  • Conduct Accreditation activities such as: Review of the certification results in the design review documentation by the Accreditation Authority to ensure that the system will operate with an acceptable level of risk and that it will comply with the departmental and system security policies and standards and identify the conditions under which a system is to operate (for approval purposes). This may include the following types of approvals:
    • Developmental approval by both the Operational and the Accreditation Authorities to proceed to the next stage in an IT systems life cycle development if sensitive information is to be handled by the system during development
    • Operational written approval for the implemented IT system to operate and process sensitive information if the risk of operating the system is deemed acceptable, and if the system is in compliance with applicable security policies and standards
    • Interim approval—a temporary written approval to process sensitive information under a set of extenuating circumstances where the risk is not yet acceptable, but there is an operational necessity for the system under development
      • Develop and deliver training material relevant to the resource category
        • If you are interested, please email mmarshall@trm.ca
          We would like to thank all those who apply, but we will only contact those candidates selected for an interview.

Required profile

Experience

Level of experience: Expert & Leadership (>10 years)
Spoken language(s):
English
Check out the description to know which languages are mandatory.

Other Skills

  • Report Writing
  • Communication

Financial Analyst Related jobs