IT Security Threat & Risk Assessment & Certification & Accreditation Analyst
- Contract
Company Description
ADGA Group is a proudly Canadian-owned and operated defence and security technology company specializing in purpose-built solutions for government and industry. We deliver mission-critical solutions in systems engineering, simulation and training, and program management as well as in cyber, infrastructure, and operational domains. Through embedded teams, advisory services, and integrated project delivery, we apply deep expertise and innovative thinking to strengthen Canada’s national security.
For nearly 60 years, we’ve recruited veterans and citizens whose leadership, technical expertise, and operational experience align with the work we do for clients such as the Department of National Defence, Public Safety Canada, and other federal agencies. Guided by a social mandate, we create meaningful employment opportunities for veterans of the CAF and RCMP, their families, and citizens who share a passion for the safety and security of Canadians.
We bring together people who share a passion for purpose, growth, and contributing to Canada’s safety and security. We prioritize your success by fostering internal growth in a safe, inclusive, and agile workplace. Our employees have access to a wide variety of developmental opportunities, including the chance to work on different projects and technologies, on-the-job training, cross-training, online courses, and formal education subsidies.
Job Description
REF: 001
ADGA Group is currently hiring a Senior IT Security Threat and Risk Assessment (TRA) and Certification and Accreditation Analyst to join our Defence contract in support of the Strategic Radio Capability project during the Option Analysis and Definition phases as well as other related radio frequency communications systems activities on an as and when required basis.
- Able to obtain and maintain a Canadian Government NATO Secret clearance.
- Must be available to work “on-site” on a full-time basis in Ottawa office.
- Potential travel outside the NCR.
- Length of contract – 10 months to start (potential for extension)
Tasks will include but not limited to:
- Review, analyze, and/or apply the Information Technology IT Security Policies, Procedures and
- Guidelines of International government, Federal, Provincial or Territorial government.
- Review, analyze, and apply the best practices, national or international computer law and ethics, IT Security architecture, and IT Security Risk Management Methodology.
- Develop vision papers delineating the way ahead to ensure that IT Security and cyber protection are included as enablers of project(s).
- Conduct business function analysis and business impact assessments to determine impacts of IT Security.
- Brief DND and stakeholder senior managers on IT Security matters.
- Provide strategic assessments on IT Security technology trends and emerging technologies.
- Provide IT Security strategic planning and advice.
- Conduct feasibility studies, technology assessments and cost-benefit analyses, and propose system implementation plans for IT Security.
- Develop advanced Research and Development (R&D) policy/strategy.
- Collect, collate and prioritize client IT Security and Information Infrastructure Protection requirements.
- Evaluate and provide technical expertise in the selection of enterprise-wide IT Security Technology tools.
- Review and prioritize IT Security and Information Infrastructure Protection programs.
- Develop strategic IT Security architecture vision, strategies and designs using the Business Transformation Enablement Program (BTEP) methodology and the Government Strategic Reference Model (GSRM).
- Develop IT Security programs and service designs using the following GSRM models: Program Logic Model, Program and Service Alignment Model, Service Integration and Accountability Model, State Transition Model, Information Model and Performance Model.
- Develop IT security training material relevant to the resource category and deliver the training to DND employees and stakeholders; and
- Perform any other work related to this category
Qualifications
- 10 years+ of experience within the last 20 years as an IT Security TRA and C&A Analyst.
- Must have one of the following: (copies must be provided)
- A Diploma or Certificate (minimum 2 years from a recognized college) in an Information Management or Information Technology field.
- An Engineering or Science degree from a recognized Canadian University or
- A non-Canadian Engineering or Science degree that must be accredited by one of the following institutions:
- Canadian Information Centre for International Credentials (CICIC)
- World Education Services (WES) or
- University of Toronto Comparative Education Services
- Must have one of the following recognized certifications such as:
- CISM (Certified Information Security Manager)
- CRISC (Certified in Risk and Information Systems Control)
- CISSP (Certified Information Systems Security Professional)
- 5+ years of experience within he last 10 years performing each of the following tasks:
- IT Security Threat Risk Assessment (TRA) and Certification and Accreditation (C&A) or Security Assessment and Authorization (SA&A) services on IMT/IT projects valued $5 million or more.
- Conducting Security Test and Evaluations and Network Vulnerability Assessment.
- Developing IT security reports such as Data security analysis, Concepts of operations, Statements of Sensitivity, Threat Assessments, Privacy Impact Assessments, Non-technical Vulnerability Assessments, Risk Assessments, IT Security threats, Vulnerability and/or risk briefings.
Additional Information
- Candidates that currently hold a Secret level clearance, or NATO Secret will get preference.
Work-Life Balance
We strongly support a healthy and productive work-life balance. This starts with a flexible approach to work, and policies designed to support employees through their day-to-day routines and major life events. For example, we offer a Maternity/Parental Top-Up (up to 52 weeks) and a Reservist Leave Top-Up (up to 180 days).
Belong@ADGA
ADGA continuously strives to integrate advanced Diversity, Equity & Inclusion (DEI) approaches and practices into our work culture. Our employee-based DEI Committee explores activities and invites discussions that foster an environment where all employees feel valued, respected, and heard.
Compensation
Above and beyond our commitment to offer a competitive base salary, ADGA has a company-wide profit-sharing plan for all full-time and part-time employees.
Comprehensive Benefits and Total Rewards
We offer a comprehensive benefit program, providing employees with the choice between base or enhanced plans. Depending on the plan, ADGA pays for Health & Dental, a Health Spending Account, Short-Term Disability, an Employee Assistance Program, and a Telemedicine service. Also offered: discounts on gym memberships, 5,000+ perks through Perkoplis, a Deferred Profit Sharing Plan, and access to a wide range of other employee-centric services and savings programs.