Information Security Advisor
Location
Canada
Posted
6 days ago
Salary
0
Seniority
Senior
Job Description
Information Security Advisor
TEHORA inc.
• Participate in the development and implementation of information security strategies; • Conduct security assessments and provide recommendations; • Lead and support IT security audits; • Participate in penetration testing; • Develop, document, and maintain security policies and procedures; • Perform risk assessments and propose mitigation measures; • Monitor emerging threats and vulnerabilities; • Advise technology teams on security best practices; • Take part in security incident investigations and analysis; • Produce documentation, reports, and recommendations for stakeholders; • Facilitate workshops, meetings, and security awareness activities.
Job Requirements
- Bachelor's degree in Computer Science or a related field;
- Minimum of five (5) years of experience in IT;
- CISSP certification (or equivalent as required by the client);
- Active membership in a professional information security association;
- At least five (5) years of experience as an information security advisor;
- Experience leading IT security audits;
- Experience participating in penetration tests;
- Experience drafting and enforcing security policies;
- Strong knowledge of infrastructure, network, and systems security principles;
- Familiarity with Windows, Linux, Cisco, Active Directory, and Microsoft 365 environments;
- Hands-on experience with security tools such as Nessus, Nmap, OpenVAS, Metasploit, and Wireshark;
- Knowledge of firewall technologies, encryption, and PKI infrastructures;
- Excellent ability to gather and analyze requirements;
- Strong communication, facilitation, and technical writing skills;
- Demonstrated autonomy, attention to detail, and excellent teamwork.
Benefits
- Remote work and flexibility to accommodate family commitments
- Entrepreneurial culture that encourages creativity and innovation
- Flexible hours (depending on employment contract)
- Sick leave and leave for family events
- Appropriate IT equipment
- A supportive and motivating workspace
- Social and environmental initiatives
- On-the-job learning program
- Career development path
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
• Auditing key clients ranging from SMEs to Global super brands • Building great relationships with clients • Carrying out audits both on site and remotely • Auditing against ISO 27001 and ISO 22301 standards • Playing a pivotal role in improving clients' business performances
Cybersecurity SME, Splunk
A.C.Coy CompanyStaffing and consulting firm specializing in IT, Accounting & Finance, Engineering and Sales placements.
• Design, deploy, and maintain on-premises and cloud based Splunk environments to support enterprise-level monitoring, alerting, and reporting. • Execute new projects as well as data and user onboarding. • Manage knowledge objects (fields, extractions, tags, event types, lookups, workflow actions, aliases, macros, and so on) – through automations, scripting, management server functions; to include .conf and .cfg files in scope of the last four Splunk Enterprise versions. • Mentor and guide junior researchers or team members. • Support off-hours and weekend efforts for incident investigations and systems maintenance.
• Build, scale, and modernize enterprise security program • Translate strategy into execution • Lead a growing team • Partner closely with IT, Product, Sales, and Operations • Drive company-wide security awareness initiatives and training programs • Develop governance frameworks for internal AI tools • Partner with engineering and product teams to secure AI-powered services • Identify and implement automation for high-volume, repeatable tasks • Oversee vulnerability management lifecycle • Lead incident response planning, detection, monitoring, and testing • Maintain compliance across SOC 2, HIPAA, and other frameworks • Advise leadership on risks, vulnerabilities, and emerging threats
• Ensure the implementation and governance of secure cloud architectures across platforms. • Continue development, enforcement, and governance of cyber security controls (including identity, access management, and workload protection). • Partner with engineering teams to embed security into cloud-native development and DevOps processes (DevSecOps). • Evolve the organization’s security risk management program. • Conduct risk assessments, threat modeling, and control evaluations. • Translate technical risks into business impact and present recommendations to senior leadership. • Develop and maintain advanced automation frameworks and scripts to improve detection, response, and compliance capabilities. • Lead efforts to integrate security tooling (SIEM, EDR, CSPM, etc.) into a cohesive security ecosystem. • Oversee monitoring and detection strategies across networks, endpoints, and cloud environments. • Lead incident response efforts, including triage, containment, root cause analysis, and post-incident improvements. • Drive continuous improvement of detection use cases and response playbooks. • Lead vulnerability management lifecycle, including scanning, prioritization, and remediation strategies. • Coordinate perform penetration testing and adversary simulations. • Support and help shape governance, risk, and compliance initiatives (e.g., NIST, ISO, SOC 2). • Lead security assessments, audits, and third-party risk reviews. • Contribute to long-term cybersecurity strategy, roadmap planning, and security metrics reporting. • Act as a technical mentor and escalation point for junior analysts and engineers. • Oversee the career development of security team members. • Collaborate with IT, engineering, and business stakeholders to align security initiatives with organizational goals. • Stay ahead of emerging threats, technologies, and industry trends, bringing proactive recommendations to leadership.




