RQ08435 - Security Specialist - Penetration Testing Senior
Client: Ministry of Public and Business Service Delivery (former MGCS)
Period: 12 months
Start Date: 2025-04-01
End Date: 2026-03-31
Working Hrs.: 7.25 Hrs. / day
Location: 222 Jarvis St.
Hybrid role - Candidate is required to come in office - 3 days a week
MUST HAVES:
Current penetration test experience
Description:
Experience and Skill Set Requirement
PENETRATION TEST EXPERIENCE: 35%
- Demonstrated experience in identifying, analyzing, and exploiting common vulnerabilities using both manual techniques and automated tools for web and network pen testing and vulnerability assessments.
- Demonstrated experience in leading penetration tests, web application vulnerability assessments, code reviews and network vulnerability assessments in a large environment with diverse systems; and in common attacks, common web application vulnerabilities, exploits and best practices for remediation.
- Knowledge of IT security methodologies, tools, techniques, security design and architecture, threat/risk concepts and practices, and encryption technologies.
- Ability to acquire and interpret corporate I&IT security strategy, programs, the government`s trust model, and privacy legislation
TECHNICAL EXPERTISE: 25%
- Experience with multiple operating systems, programming and scripting languages, platforms, and network services and protocols.
- Understanding of emerging I&IT trends, best practices and developments in common attacks, common web application vulnerabilities, exploits and best practices for remediation.
ANALYTICAL AND PROBLEM SOLVING SKILLS: 20%
- Demonstrated analytical and problem solving skills to determine alternative and innovation solutions where guidelines or policies exist but may not address new and emerging I&IT trends.
- Ability to conceptualize, interpret and evaluate security exposures across multiple domains.
COMMUNICATION AND RELATIONSHIP BUILDING SKILLS: 10%
- Experience with writing reports aimed at both the executive/non-technical management level, and technical analyst level.
- Oral and written communication, mediation, negotiation, consultative and advisory skills. Skills to provide training in the use of commercial security assessment tools and scanners.
- Stakeholder management, partnership and relationship building skills to initiate and nurture strong working relationships with internal and external colleagues.
LEADERSHIP AND PROJECT MANAGEMENT SKILLS: 10%
- Proven ability to provide leadership, advice and direction on business risk planning and co-ordination.
- Demonstrated project methodology and management skills