Logo for NexGedia Enterprise

Threat, Risk Assessment and Pentest Advisor

Role overview

Qualifications

  • Up-to-date familiarity with NIST Recommended Security Controls (800-53 – version 5)
  • 3+ years of experience in managing large initiatives and public stakeholder engagement in security assessments
  • Experience conducting TRA’s for large scale organizations (3000+ employees)
  • Minimum of 8 years of IT related experience in relevant fields such as Cybersecurity and Risk Management

Responsibilities

  • Ensure alignment with corporate Cybersecurity best practices and guidelines
  • Plan, coordinate, organize and facilitate workshops to identify and assess threats/vulnerabilities/controls against service assets
  • Participate in workshops to elicit, document, and prioritize related tasks and projects
  • Immediate notification to application owner(s) of any identified critical cybersecurity risk during the TRA process

About the company

NexGedia Enterprise logo

NexGedia Enterprise

IT Services & IT Consulting

We develop the future. We have the most creative ideas - Technologies of the 21st century. We have fast online services with the most advanced technologies. We have reliable customer support. For more information, visit our company site:www.nexgedia.com or our career site: jobs.nexgedia.com

Company details

IndustryIT Services & IT Consulting
Company size2 - 10

Your match analysis

See how your profile stacks up against this role.

We compared the job requirements to your profile to show where you're strong and where you fall short.

Job description

Role: Threat, Risk Assessment and Pentest Advisor
Start date: June 12, 2024
End date: March 31, 2025
Duration: 1,567.50 billable hours
Location of Work (Address or City, Province): Halifax, NS
Remote Work be considered? Yes

Description
One of our clients is looking for a Threat, Risk Assessment and Pentest Advisor to work on a major initiative. 

Responsibilities
  • Ensure alignment with corporate Cybersecurity best practices and guidelines.
  • Plan, coordinate, organize and facilitating workshops to identify and assess threats/vulnerabilities/controls against service assets
  • Participate in workshops to elicit, document, and prioritize related tasks and projects
  • Review/analyze results from other available and relevant Threat and Risk Assessments (TRAs) or security scans, conducted as part of the TRA deliverable.
  • The TRA vendor determines if the specific control found within the ‘GNS TRA NIST Checklist’, relative to the specific control baseline, is satisfactory. If the specific control is not evaluated as satisfactory, then it is carried over and documented as a risk within the TRA template.
  • Immediate notification to application owner(s) of any identified critical cybersecurity risk against any digital service as soon as identified while the TRA is in progress.
Knowledge and Experience
  • Must have an up-to-date familiarity and experience in NIST Recommended Security Controls for Federal Information Systems and Organizations (800-53 – version 5) in conducting or participating in assessing digital services.
  • Must have three or more (3+) years of experience in managing large initiatives, group facilitation, gaining consensus and information gathering and consolidation as well as engaging stakeholders in security assessments.
  • Experience in conducting TRA’s for large scale organizations not less than 3000 employees.
  • Demonstrate a minimum of 8 years of IT related experience within one or more of
    the following fields:
    • Cybersecurity and Risk Management assessment methodologies.
    • IT Infrastructure/Networks.
    • Identity, Credential and Access Management.
    • Application Design/Development/Testing.
    • Enterprise Architecture.
    • Privacy.
    • Telecommunications.
    • SaaS, IaaS and PaaS Digital Service Delivery Models.
  • Experience with ISO/IEC 27001:2013 Information security management systems (ISMS) framework.
  • Experience performing intrusion and penetration testing.
  • Have strong writing skills to produce accurate and comprehensive documentation.
  • The Penetration Tester resource will use industry best-practice methodologies and tools to identify, analyze, evaluate and document Penetration Testing risks to the departmental service/project.
  • The resource will review/analyze results from other available and relevant Penetration Tests or security scans conducted as part of the project or as part of a solution provided.
  • The resource will identify the specific PNS function responsible for remediation.

Apply once. Then go straight to the hiring manager.

After you apply, unlock the direct contact details of the people who actually make the call. A quick follow-up makes you 5x more likely to land an interview.

MR

Marcus Rivera

Chief Revenue Officer

m.rivera@company.com
linkedin.com/in/marcusrivera
Unlocked after you apply
·

Risk Management Director Related jobs

Other jobs at NexGedia Enterprise

Premium

Reach out to the hiring manager directly.

Gain access to the contact details of the hiring managers who actually decide, and reach out to network with them directly. That, plus more when you upgrade:

  • Full match report with fit score and gaps
  • Career diagnostics on how recruiters read you
  • Curated company matches and warm intros
  • 48h early access to new roles

Cancel anytime.