RQ-2026-009813 - Security Specialist - Senior for the Information Security Office
Job Details
Closing Date: Thursday, July 23, 2026 at 12:00 p.m.
Location: 525 University Ave, Toronto, Ontario, Canada
Client: Ontario Health
Department: Digital Excellence in Health
Start Date: 2026-08-17
End Date: 2027-08-13
Work Arrangement: Hybrid
Job Type: Contract
Job ID: 07222
Project Overview
Support and deliver on multiple initiatives related to Security Governance, Risk and Compliance and Cyber Defence Operations, including leading multiple initiatives related to security strategy, security audit and compliance requirements and findings, security governance including policies, standards and processes development and security risk management procedures.
Key Responsibilities
- Development of security policies, standards, procedures, processes.
- Development of frameworks and models for select security capabilities
- Support implementation of new enterprise governance, risk and compliance tool.
- Support development of a cyber security strategy and key aspects of program development including program performance reporting.
- Support on completion of security assessment using tools based on NIST CSF.
- Review of Threat Risk Assessment, VA scan report, Penetration Test report and other security documents.
Qualifications & Requirements
REQUIRED
- Must be able to work onsite as per Hiring Manager discretion
- Minimum 8 years of hands-on experience with IPC (very strong) and OAGO audits.
- Minimum 5 years extensive experience in conducting comprehensive security Threat and Risk Assessment (TRA) using frameworks such as NIST CSF, HTRA, and ISO 27001, including risk assessment, mitigation recommendations and management with a strong focus on identifying vulnerabilities, analyzing potential impacts, and delivering actionable risk mitigation to stakeholders.
- Minimum 5 years of extensive experience with Information security governance, developing policies and standards with a strong ability to identify gaps between the current security posture and industry standards, best practices, and regulatory requirements.
- 5+ years of experience authoring executive-level reports, developing cyber security program and risk registers, and delivering presentations to stakeholders and senior leadership.
- Public Sector experience.
- Knowledge and experience developing and working with security architecture, and IT management frameworks such as SABSA, and CoBIT.
- Technical writing expertise and demonstrated knowledge and experience in developing Information security policies and standards in alignment with PHIPA, IPC requirements and industry standards.
- Strong understanding and ability to interpret and communicate risk management concepts.
- Good experience & knowledge of TRA methodologies and other risk assessment methodologies and tools, and familiarity with related security tests and test methodologies.
- Deep understanding of typical security threats, vulnerabilities and safeguards relevant to IT systems.
- Experience in writing and presenting subject matter information that is both comprehensive and easy to understand.
- Excellent communication and reporting abilities to effectively present findings and risk mitigation strategies to both technical teams and executive stakeholders.
- Experience and working knowledge of risk management lifecycle, processes, and concepts.
- Strong analytical skills to assess potential impacts and likelihoods of various threat scenarios.
- Experience in risk management models for assessing and mitigating various aspects of risk exposure.
- Understanding of risk assessment methodologies such as HTRA and CSF, and frameworks such as NIST and ISO 27001/2.
- Experience with security governance including developing policies, standards, processes and procedures.
- Demonstrated experience in working with various compliance and audit frameworks including PHIPA, SOC 2 Type II, OAGO.
- An adept team player who is action oriented, with a record of accomplishment of motivating other team members to achieve higher goals.
NICE TO HAVE
- 10+ years’ experience in various security domains including third-party risk management, IT audits and/or Security Governance, Risk and Compliance (GRC)
- Bachelor’s or Master’s degree in Computer Science, Information Technology, Cyber Security, Systems or other related field, or equivalent work experience.
- Professional certifications in information/cyber security (e.g. CISSP, CCSP, CISA, CISM, CRISC)
- Knowledge of prevalent industry standards (ISO 27001/27002, NIST, CIS, COBIT)
EVALUATION CRITERIA
- Minimum 5 years extensive experience in conducting comprehensive security Threat and Risk Assessment (TRA) using frameworks such as NIST CSF, HTRA, and ISO 27001. Risk Assessment, mitigation recommendations and management with a strong focus on identifying vulnerabilities, analyzing potential impacts, and delivering actionable risk mitigation to stakeholders. - 25 points
- Minimum 5 years of extensive experience with Information security governance, developing policies and standards with a strong ability to identify gaps between the current security posture and industry standards, best practices, and regulatory requirements. - 25 points
- Minimum 8 years of hands-on experience with IPC and OAGO audits. - 30 points
- 5+ years of experience authoring executive-level reports, developing cyber security program and risk registers, and delivering presentations to stakeholders and senior leadership. - 20 points
Key Skills & Competencies
HTRA, NIST CSF, ISO 27001, ISO 27002, SABSA, COBIT, PHIPA, SOC 2, OAGO, IPC, TRA, CIS, vulnerability assessment, penetration testing, risk assessment, security architecture, IT audits, GRC, third-party risk management
Applications for this position will be accepted until Thursday, July 23, 2026 at 12:00 p.m..
If you meet the requirements for this role, please apply now.
Apply for This Position
Click "Apply." If no email opens, check your pop-up blocker or email your resume directly to
resume@govtechtalentsolutions.ca, including the Requisition Number and Job Title in the subject line.