Security Specialist (RQ07697)

  • Contract
  • Toronto
  • Applications have closed

Ministry of Public and Business Service Delivery (former MGCS)

Description

Responsibilities: Defines, evaluates, and assesses security architecture requirements for systems environments and IT projects. Ensures the incorporation of IT security and contingency measures in the development of systems. Advises on the identification, analysis, and resolution of specific security factors, risks, vulnerabilities; protection of personal privacy issues; and appropriate industry and international security standards. Carry out information and information technology (I&IT) security projects and tasks in the Ontario Public Service as assigned by Corporate Security or cluster I&IT management General Skills: Strong understanding and expertise in security architecture Knowledge of techniques to secure information assets and the planning, design, and implementation of security technologies Proven techniques to discover gaps or weaknesses in security architecture to identify and mitigate known security threats or inherent weaknesses Knowledge and understanding of relevant legislation and corporate directives related to the security and confidentiality of information (e.g. Freedom of Information and Protection of Privacy Act) in order to identify and assess areas of concern and risk Solid knowledge of current security and contingency technology and techniques (e.g. digital signature, encryption, access controls, fire-walls, authentication, virus protection, etc.); and a proven working knowledge of security audit procedures and protocols Experience in developing enterprise architecture deliverables (e.g. models) Experience in providing specialized security support at the specified experience level Experience in establishing secure environments at a network, operating system or application level Experience with implementing security on complex and distributed systems. Awareness of emerging IT trends and directions, especially as related to security Excellent analytical, problem-solving, and decision-making skills; written and verbal communication skills; interpersonal and negotiation skills A team player with a track record for meeting deadlines, managing competing priorities and client relationship management experience Desirable Skills: Experience in developing enterprise architecture deliverables (e.g. models) based on Ontario Government Enterprise Architecture processes and practice Experience in Threat Risk Assessment methods Knowledge and understanding of Information Management principles, concepts, policies and practices Experience in business recovery and disaster recovery planning. Experience in performing threat and risk assessment. Experience in public key infrastructure development and operation. Experience in security design as part of systems development projects. Experience in intrusion detection systems. Experience in mitigation tools for malicious software. Experience in vulnerability analysis and penetration testing. Experience in network monitoring. Experience in security policy development. Experience in developing and delivering security education. Experience in forensic investigation. Knowledge and understanding of Information Management principles, concepts, policies and practices

Experience Requirements

The Cyber Security Centre of Excellence (COE) is seeking two Senior Cyber Security Specialists to support in strengthening Ontario’s cyber security infrastructure as the province collectively moves more government programs and services online:

1) Digital Transformation: Transforming through a digital first approach to lower the cost of delivery and make services simpler, faster and better for people, businesses and OPS employees priority

2) Service Delivery Excellence: Driving operational excellence and continuous improvement in the delivery of services and transforming and streamlining delivery models across government with private sector partners.

3) Supporting Businesses: Simplifying Ontario’s regulatory framework and reducing the administrative burden on businesses to make it easier to engage with all of government priority

The role requires the following competencies:

Technical Security Architecture Design -25%

• Provides security design expertise and advice to internal stakeholders on design principles and best practices and the development and implementation of security mechanisms to ensure the protection of information assets of client ministries and compliance with legal requirements, and industry best practices.

2. Security Liaison and Advice – 25%

• Maintains on-going liaison with IT cyber security staff and senior client ministry program management to facilitate working relationships on all security planning, implementation and management matters by assessing security needs and assisting asset custodians in the identification, design, and implementation of security architecture.

3. Project Management – 25%

• Leads and/or carries out large scale and sensitive security architecture design projects and/or significant components of other projects with security design elements, to mitigate identified risk to an acceptable level, ensuring compliance and integration with the Enterprise Information Architecture and Cluster architectures; provide supervision/technical direction to teams, coordinate development of design specifications, prepare reports, estimates, and feasibility studies.

4. Communication and Relationship Management Skills – 25%

• Demonstrated communication, consultative and advisory skills to act as a lead technical resource and provide expertise to ongoing contacts.

Supplier Comments

Closing Date/Time: 2024-07-19, 3:45 p.m. EST

Max # of supplier openings: 2 (Two)

Candidate is required to work onsite 3 days per week and 2 remote

This entry was posted in . Bookmark the permalink.