About the Role
We are looking for a Cybersecurity Threat Modeling Specialist to join our growing team. This role serves as the primary Security point of contact for technology initiatives, providing security guidance throughout the project lifecycle and formal sign-off before go-live.
Responsibilities
- Lead threat modeling for new or materially changed applications, systems, services, architecture patterns, and AI use cases using methodologies like STRIDE, MITRE ATT&CK, Mitre Atlas, Maestro, attack chains, and misuse or abuse cases.
- Develop and validate threat-modeling supporting materials, including data flows, architecture diagrams, network diagrams, and process flows.
- Identify critical assets, trust boundaries, entry points, and dependencies.
- Assess threats based on exploitability and potential impact, assign inherent and residual risk ratings, and translate findings into prioritized security requirements, control objectives, mitigations, and go-live acceptance criteria.
- Support critical security activities such as penetration testing, SAST, DAST, secure code reviews, third-party risk assessments, and vulnerability assessments.
- Collaborate with product, architecture, development, engineering, cloud, and risk teams to review designs, facilitate threat-modeling workshops, and embed security into DevSecOps and project governance processes.
- Manage Security Findings in platforms like JIRA, including ownership, remediation, escalation, compensating controls, risk acceptance, and closure.
- Provide ad hoc security advice and document recommendations and follow-up actions.
- Use threat modeling to support the three lines of risk management.
- Enhance threat modeling accuracy and recommendations using post-incident lessons learned and threat intelligence.
- Lead improvement and scale the threat-modeling capability through reusable methodologies, templates, patterns, guidance, tooling, training, and self-service workshops.
- Stay ahead of emerging technology and frameworks, particularly across AI and modern application architectures.
- Report on threat-modeling coverage, recurring gaps, overdue actions, and trends to relevant committees and stakeholders.
- Communicate complex technical risks, recommendations, and risk-based decisions clearly to technical and non-technical stakeholders.
- Teach and mentor immediate team members on threat modeling, secure design, risk management, and security practices.
Requirements
- Bachelor’s degree in Computer Science, Engineering, or a related field, or an equivalent combination of education and experience.
- At least ten (10) years of experience in Information Technology, including a minimum of five (5) years in Information Security.
- Demonstrated experience in one or more of the following areas: application or cloud security, security architecture, threat modeling, risk assessment, threat intelligence, incident response, SOC or SIEM operations, vulnerability management, red teaming, or penetration testing.
- Strong understanding of application, infrastructure, network, and data security across multi-cloud environments, including AWS, Azure, and GCP.
- Familiarity with vulnerability management and DevSecOps principles, including secure design and CI/CD security.
- For candidates located in Quebec, bilingualism is required.
- Must be eligible to work in Canada.
Skills
- STRIDE
- MITRE ATT&CK
- Mitre Atlas
- Maestro
- Attack chains
- Misuse or abuse cases
- Application security
- Cloud security
- Security architecture
- Threat modeling
- Risk assessment
- Threat intelligence
- Incident response
- SOC operations
- SIEM operations
- Vulnerability management
- Red teaming
- Penetration testing
- AWS
- Azure
- GCP
- DevSecOps
- Secure design
- CI/CD security
- Scripting
- Automation
- Microsoft Threat Modeling Tool
- IriusRisk
- Threat Dragon
- draw.io
- Lucidchart
- Visio
- PlantUML
- Excellent oral and written communication skills
- Positive attitude
- Team spirit
- Critical mindset
- Bilingualism (Quebec)
Location
- Hybrid
Work Type
- Hybrid
- Full-time
Experience Level
- 10+ years of experience in Information Technology
- 5+ years of experience in Information Security
Education Level
- Bachelor’s degree in Computer Science, Engineering, or a related field
- Relevant professional certifications (CISSP, CISA, CISM, CGEIT, CRISC, GSEC, GISP, CCSP, SSCP, CSSLP, OSCP, SABSA, CEH, GCIH, GCTI, or GCFE)
Salary/Compensations
- 118,700 - 145,100 (for a 35-hour workweek)
- 15% Annual bonus target with potential payout up to double the target
- Up to 12% of salary in share plan & other savings
Benefits
- Flexible work arrangements
- Hybrid work model
- Possibility to purchase up to 5 extra days off per year
- Telemedicine
- Wellness account
- Share plan
- Savings plan
- Guaranteed income for life via defined benefit pension plan
- Intact matching 50% of your net shares in ESPP
About the Company
- Our employees are at the heart of everything we do. Together, we help people, businesses, and society prosper in good times and be resilient in bad times.
- Our employee promise represents Intact’s commitment to you in exchange for living our Values, striving to do your best work, being open to change and investing in your career.
- In return, we promise to provide support, opportunities and performance-led financial rewards at a workplace where you can shape the future, win as a team and grow with us.
- Pay at Intact is about much more than just salary.
Equal Opportunity
- We are an equal opportunity employer.
- At Intact, our Value of respect is founded on seeing diversity as a strength.
- We strive to create an accessible workplace where employees feel valued, included and encouraged to share their unique perspectives.
- We encourage applications from individuals who are members of equity-deserving groups, including but not limited to women, Indigenous peoples, persons with disabilities, Black people, and members of the 2SLGBTQI+ community.
- As part of Intact’s commitment to reconciliation, we acknowledge that we work, meet and travel across the land currently called Canada, originally inhabited by First Nations, Metis and Inuit people.
- We have policies to ensure equal access and participation for people with disabilities, including providing workplace adjustments (accommodations).
- If we can provide a specific adjustment to make the recruitment process more accessible for you, please let us know when we reach out about a job opportunity. We’ll work with you to meet your needs.
