Security Risk Assessment (SRA) Lead
Website Confidential
Lead the end-to-end Security Risk Assessment of SNB’s Digital Trust solution. Own the assessment methodology, coordinate the specialist team, integrate all findings into a single risk picture, author the SRA report, and serve as the primary point of contact for SNB’s Departmental Information Security Officer (DISO), Security Strategist, and Project Manager.
Key Responsibilities:
– Define and lead the SRA methodology, blending OWASP (ASVS/MASVS) with an enhanced framework mix (e.g., NIST, MITRE ATT&CK) for complete coverage
– Conduct the architectural / end-to-end risk assessment across mobile apps, vendor components, portals, cloud, and internal government assets and services
– Perform the vendor assessment, leveraging existing third-party assurance (Ping’s SOC 2 Type 2) rather than re-testing platform-level controls
– Consolidate findings from all workstreams, risk-rate by likelihood and impact, and produce prioritized, actionable remediation guidance
– Author the consolidated SRA report and deliverables; run QA over all outputs
– Coordinate the team, manage the 20-day schedule and dependencies, and lead all SNB meetings and progress reporting
Deliverables Owned:
– Deliverable 1 (Vendor Assessment)
– Deliverable 5 (Document Results)
– Deliverable 6 (Meetings)
– Overall accountability for a complete, on-time assessment
Skills: Security Risk Assessment, OWASP, ASVS, MASVS, NIST, MITRE ATT&CK, Vendor Assessment, SOC 2, Risk Rating, SRA Report Writing, Team Coordination, Threat Modeling, STRIDE, PASTA, Digital Identity, Verifiable Credentials, ISO/IEC 27005
Location: Fredericton, NB
To apply for this job please visit fokuspro.net.