General Skills Strong understanding and expertise in security architecture Experience in the application of Cyber Security methodology and tools to define scope, critical business processes and functions, identify critical assets and dependencies in reports to clients (TRA or other security assessments) Experience and ability to plan and facilitate Threat Risk Assessment and/or other workshops with business clients Experience and ability to apply Harmonized Threat Risk Assessment (HTRA) or equivalent methodology Knowledge of techniques to secure information assets and the planning, design, and implementation of security technologies. Proven techniques to discover gaps or weaknesses in security architecture to identify and mitigate known security threats or inherent weaknesses. Knowledge and understanding of relevant legislation and corporate directives related to the security and confidentiality of information (e.g. Freedom of Information and Protection of Privacy Act) in order to identify and assess areas of concern and risk Solid knowledge of current security and contingency technology and techniques (e.g. digital signature, encryption, access controls, fire-walls, authentication, virus protection, etc.); and a proven working knowledge of security audit procedures and protocols. Experience in developing enterprise architecture deliverables (e.g. models) Experience in providing specialized security support at the specified experience level. Experience in establishing secure environments at a network, operating system or application level. Experience with implementing security on complex and distributed systems. Experience in conducting in depth analysis and provide recommendations with all required sign-off in the prescribed timelines as given (TRA reports or other security assessment reports) Experience and knowledge to provide security requirements for procurement documents and participate in security evaluations as part of the procurement process Ability to assess Information Security Risk, Business Continuity Planning and Business Impact Analysis technical issues for any of the technical environments and delivery channels across the Ontario Provincial Government including Mainframe, Unix and Windows. Awareness of emerging IT trends and directions, especially as related to security. Excellent analytical, problem-solving, and decision-making skills; written and verbal communication skills; interpersonal and negotiation skills A team player with a track record for meeting deadlines, managing competing priorities and client relationship management experience Desirable Skills Experience in developing enterprise architecture deliverables (e.g. models) based on Ontario Government Enterprise Architecture processes and practice Knowledge and understanding of Information Management principles, concepts, policies and practices Experience in business recovery and disaster recovery planning. Experience in performing threat and risk assessment. Experience in public key infrastructure development and operation. Experience in security design as part of systems development projects. Experience in intrusion detection systems. Experience in mitigation tools for malicious software. Experience in vulnerability analysis and penetration testing. Experience in network monitoring. Experience in security policy development. Experience in developing and delivering security education. Experience in forensic investigation. Knowledge and understanding of Information Management principles, concepts, policies and practices