ProServeIT is a leading IT solutions provider that specializes in delivering innovative technology solutions to help businesses thrive. With over 20 years of experience, we've established ourselves as a trusted partner in the ever-evolving world of technology.
We’re searching for someone who has a genuine interest in technology and security who will lead several aspects of security for our clients, as our projects are varied both in nature, size, and location. You will be a subject matter expert in cyber security and a member of a team that manages IT security on behalf of customers to reduce the impact of security incidents and system compromises. This team provides security monitoring, event investigation, event analysis, and countermeasure proposals.
Life at ProServeIT is fast paced, performance-driven, rewarding, and fun! We value and support our team members' career growth and ongoing professional development. And we recognize their achievements and outstanding results on a regular basis. We work hard and play hard.
People Matter. Be like gumby. Do it right." These are the three values we follow every day. These truly represent who we are and what we care about.
Excited? Read on and apply! Looking forward to hearing from you.
Responsibilities
- Provide security recommendations around Microsoft Security products.
- Deploy Microsoft Security products to enhance customers security postures.
- Conduct Microsoft Security Workshops.
- Perform penetration tests on computer systems, networks and applications.
- Conduct vulnerability assessments for networks, applications and operating systems.
- Create new testing methods to identify vulnerabilities.
- Pinpoint methods and entry points that attackers may use to exploit vulnerabilities or weaknesses.
- Identify critical flaws in applications and systems that cyber attackers could exploit.
- Research, evaluate, document and discuss findings with IT teams and management.
- Review and provide feedback for information security fixes.
- Establish improvements for existing security services, including hardware, software, policies and procedures.
- Identify areas where improvement is needed in security education and awareness for users.
- Be sensitive to corporate considerations when performing testing (i.e. minimize downtime and loss of employee productivity).
- Stay updated on the latest malware and security threats.
- Write and present comprehensive Vulnerability Assessment and Penetration Testing reports.
- Provide security advisory & consultation services for various client projects including product/service acquisition, solution design, implementation and management of major IT systems, projects, initiatives and new product development.
- Review and interpret requirements documentation, architecture diagrams and solution designs to help determine the feasibility of a project and its security risk
- Lead the cybersecurity risk and control design reviews for application, process, operations, and overall enterprise initiatives.
- Perform thorough and timely threat risk assessment (TRA) on applications, systems, processes and solution integrations, including cloud-based solutions for clients.
- Must understand risk-based approach, balancing business needs against potential risks. To provide effective and cost beneficial risk treatment strategies and facilitate remediation tasks with other operational teams.
- Define, develop, implement and manage Security Policies, Standards & Procedures that mitigate risk and maximize security, service availability, efficiency and effectiveness.
- Work with various stakeholders and project teams to ensure the design and implementation of resilient security architecture and technologies for optimal threat protection, monitoring and incident response.
- Develop on-going technology risk reporting, monitoring key trends and defining security metrics to measure control effectiveness, compliance and continuous improvement.
- Monitor and advise on cyber security compliance related to IT to ensure internal security controls are functioning appropriately.
- Advise the organization about emerging cyber security threats, technologies and related regulatory requirements.
- Consult on regulatory compliance requirements, reporting and enquiries.
- Provide support and consultation for audits and assist with formulating management responses and appropriate remediation activities.
Qualifications
- 10+ years in Cyber Security consultative roles, preferably within the IT consultancy industry.
- Professional certification: Security certification of one or more of the following: CISSP, CRISC, CCSP, CISM, CISA, SC-100.
- High degree of professionalism, work ethic, integrity and passion for Information Technology and Security.
- Proven leadership qualities and ability to build strong working relationships.
- Self-directed with ability to work independently, prioritize and execute autonomously.
- A Team player with ability to communicate and collaborate effectively across the organization and operate effectively with multiple cross-departmental teams towards a shared goal.
- Strong problem solving and critical thinking skills.
- Practical and deep knowledge of security risk management methodologies and frameworks.
- Demonstrated strong technical writing and communication skills.
- Extensive cybersecurity consulting experience for large IT projects.
- Experience in assessing third party service providers.
- Experience with enterprise security platforms and architectural design. Strong preference to candidates with proven Cloud Computing experience.
- Familiarity with latest security vulnerabilities, advisories, incidents, penetration techniques, attack vectors, and countermeasures.
- Strong understanding of cyber security concepts, protocols, industry best practices, strategies, frameworks and regulations such as International Standards Organization (ISO) 2700x, NIST Cybersecurity Framework, Payment.
- Card Industry Data Security Standard (PCI DSS), Sarbanes-Oxley (SOX).
- Understanding of the Software Development Life Cycle and Development Operations (DevOps) principals.
- Experience working in Agile Framework a definite asset
- Experience with Microsoft Security stack, Defender for Business, Azure Sentinel, Purview, etc.
Application Process
To ensure a fair and efficient recruitment process, we use AI-powered screening tools to assist in the initial review of applications. These tools help us identify candidates whose qualifications closely match the job requirements. All final hiring decisions are made by our human recruitment team.
Diversity, Inclusion and Accessibility
ProServeIT values diversity of thought and is proud to be an equal opportunity employer. We are committed to creating a diverse and inclusive environment where all people feel supported, connected, and belonging at work. All applications will receive consideration for employment without regard to race, colour, creed, gender, gender identity or expression, ancestry, citizenship, sex, sexual orientation, marital status, family status, ethnic origin, place of origin, disability, or age. Please let us know if you require any accommodations or support during the recruitment process.
This job post is for an existing vacancy.