Security Advisor Specialist - Threat Modelling

Posted Yesterday
Be an Early Applicant
7 Locations
Remote or Hybrid
119K-145K Annually
Expert/Leader
Insurance • Financial Services
The Role
Leads cybersecurity threat modeling for applications, systems, cloud environments, architecture patterns, and AI use cases. Assesses risks, defines security requirements and mitigations, supports testing and assurance activities, manages findings, and advises technology teams throughout project lifecycles. The role scales threat-modeling capabilities through methodologies, tooling, training, and reporting while integrating security into DevSecOps and governance. It also communicates risks to technical and executive stakeholders and mentors team members.
Summary Generated by Built In

Our employees are at the heart of everything we do. Together, we help people, businesses, and society prosper in good times and be resilient in bad times.

Our employee promise represents Intact’s commitment to you in exchange for living our Values, striving to do your best work, being open to change and investing in your career. In return, we promise to provide support, opportunities and performance-led financial rewards at a workplace where you can shape the future, win as a team and grow with us.

Pay at Intact is about much more than just salary.

  • Flexible work arrangements and a hybrid work model

  • Possibility to purchase up to 5 extra days off per year

  • Multiple benefits offered to support physical and mental wellbeing, including telemedicine, Wellness account and much more

  • Share plan & other savings: up to 12% of salary or even more (ask how you could earn guaranteed income for life)

Salary range (but not limited to):

118,700 - 145,100

Annual bonus target, based on the base salary, with a potential payout of up to double the target (subject to personal and company performance):

15%

As part of our commitment to Win As A Team, we share our success with employees through our annual bonus plan and Employee Share Purchase Plan (ESPP) – with Intact matching 50% of your net shares.

Our pension offerings provide flexibility and long-term security for our employees beyond their careers. We are one of the few companies offering the opportunity to receive guaranteed income for life via our defined benefit pension plan.

Salary for the candidate will be determined taking into consideration a number of factors including: experience, skills, qualifications, anticipated contribution to role, internal equity, etc. The salary range presented above is based on a 35-hour workweek and would represent a majority of different candidate profiles. However, we encourage candidates who may fall outside of this range to apply as well.

About the role

We’re looking for a Cybersecurity Threat Modeling Specialist to join our growing team!
What you'll do here:

  • Serve as the primary Security point of contact for technology initiatives, providing security guidance throughout the project lifecycle and formal sign-off before go-live.
  • Lead threat modeling for new or materially changed applications, systems, services, architecture patterns, and AI use cases. Apply appropriate methodologies, including STRIDE, MITRE ATT&CK, Mitre Atlas, Maestro, attack chains, and misuse or abuse cases.
  • Develop and validate threat-modeling supporting materials, such as: data flows, architecture diagrams, network diagrams and process flows. Identify critical assets, trust boundaries, entry points, and dependencies.
  • Assess threats based on exploitability and potential impact; assign inherent and residual risk ratings; and translate findings into prioritized security requirements, control objectives, mitigations, and go-live acceptance criteria.
  • Support the completion of critical security activities, including penetration testing, SAST, DAST, secure code reviews, third-party risk assessments, vulnerability assessments, and other assurance activities to support technology readiness.
  • Collaborate with product, architecture, development, engineering, cloud, and risk teams to review designs and technical decisions, facilitate threat-modeling workshops, and embed security into DevSecOps and project governance processes.
  • Manage Security Findings in platforms such as JIRA, including ownership, remediation, escalation, compensating controls, risk acceptance, and closure. Provide ad hoc security advice and document recommendations and follow-up actions.
  • Use threat modeling to support the three lines of risk management by helping first-line teams manage security risks, informing second-line oversight, and supporting third-line system audits.
  • Use post-incident lessons learned and threat intelligence to enhance threat modeling accuracy and recommendations.
  • Lead improvement and scale the threat-modeling capability through reusable methodologies, templates, patterns, guidance, tooling, training, and self-service workshops.
  • Stay ahead of emerging technology and frameworks, particularly across AI and modern application architectures to effectively support security risks management.
  • Report on threat-modeling coverage, recurring gaps, overdue actions, and trends to relevant committees and stakeholders.
  • Communicate complex technical risks, recommendations, and risk-based decisions clearly to technical and non-technical stakeholders.
  • Teach and mentor immediate team members on threat modeling, secure design, risk management, and security practices.

What you bring to the table:

  • Bachelor’s degree in Computer Science, Engineering, or a related field - or an equivalent combination of education and experience.
  • At least ten (10) years of experience in Information Technology, including a minimum of five (5) years in Information Security. Demonstrated experience in one or more of the following areas: application or cloud security, security architecture, threat modeling, risk assessment, threat intelligence, incident response, SOC or SIEM operations, vulnerability management, red teaming, or penetration testing.
  • Relevant professional certifications, such as but not limited to: CISSP, CISA, CISM, CGEIT, CRISC, GSEC, GISP, CCSP, SSCP, CSSLP, OSCP, SABSA, CEH, GCIH, GCTI, or GCFE.
  • Strong understanding of application, infrastructure, network, and data security across multi-cloud environments, including AWS, Azure, and GCP.
  • Familiarity with vulnerability management and DevSecOps principles, including secure design and CI/CD security.
  • Experience with scripting and automation to support threat modeling, security assessments, evidence collection, risk analysis, and the integration of security practices into development and delivery workflows is an asset.
  • Experience using threat-modeling tools, such as Microsoft Threat Modeling Tool, IriusRisk, Threat Dragon, or internally developed tools, is an asset.
  • Experience using diagramming tools, such as draw.io, Lucidchart, or Visio, or creating code-based diagrams using tools such as PlantUML, is an asset.
  • Excellent oral and written communication skills.
  • Positive attitude, team spirit and critical mindset.
  • For candidates located in Quebec, bilingualism is required considering the necessity to interact on a regular basis with English-speaking colleagues across the country
  • No Canadian work experience required however must be eligible to work in Canada

#LI-Hybrid

Il s'agit d'un nouveau rôle au sein de notre équipe en pleine croissance | This role is a new member of our growing team.


We are an equal opportunity employer

At Intact, our Value of respect is founded on seeing diversity as a strength. We strive to create an accessible workplace where employees feel valued, included and encouraged to share their unique perspectives.

We encourage applications from individuals who are members of equity-deserving groups, including but not limited to women, Indigenous peoples, persons with disabilities, Black people, and members of the 2SLGBTQI+ community.

As part of Intact’s commitment to reconciliation, we acknowledge that we work, meet and travel across the land currently called Canada, originally inhabited by First Nations, Metis and Inuit people. This history extends through many centuries and continues to evolve today.

We have policies to ensure equal access and participation for people with disabilities, including providing workplace adjustments (accommodations). A copy of applicable policies is available on request.

If we can provide a specific adjustment to make the recruitment process more accessible for you, please let us know when we reach out about a job opportunity. We’ll work with you to meet your needs.

Learn more about our recruitment process and your candidate journey here.

Please note that Intact does not provide sponsorship or other support for immigration-related matters including but not limited to employer-specific closed work permits. Candidates must be eligible to work in Canada from the anticipated start date and throughout their employment and are solely responsible for maintaining their work eligibility.

If you are an employee of Intact or belairdirect, please apply for this role on Internal Career Site.

Skills Required

  • Bachelor's degree in Computer Science, Engineering, or a related field, or equivalent education and experience
  • At least 10 years of Information Technology experience, including at least 5 years in Information Security
  • Experience in application security, cloud security, security architecture, threat modeling, risk assessment, threat intelligence, incident response, SOC or SIEM operations, vulnerability management, red teaming, or penetration testing
  • Relevant professional certification such as CISSP, CISA, CISM, CGEIT, CRISC, GSEC, GISP, CCSP, SSCP, CSSLP, OSCP, SABSA, CEH, GCIH, GCTI, or GCFE
  • Strong understanding of application, infrastructure, network, and data security across AWS, Azure, and GCP multi-cloud environments
  • Familiarity with vulnerability management and DevSecOps principles, including secure design and CI/CD security
  • Experience with scripting and automation for threat modeling, security assessments, evidence collection, risk analysis, or development workflows
  • Experience with threat-modeling tools such as Microsoft Threat Modeling Tool, IriusRisk, Threat Dragon, or internally developed tools
  • Experience with diagramming tools such as draw.io, Lucidchart, Visio, or PlantUML
  • Excellent oral and written communication skills
  • For Quebec-based candidates, bilingualism in English and French
  • Eligibility to work in Canada

Intact (intactfc.com) Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Intact (intactfc.com) and has not been reviewed or approved by Intact (intactfc.com).

  • Fair & Transparent Compensation Pay is often framed as competitive for core roles like tech, underwriting, and claims, with base pay and total compensation commonly positioned above typical sector benchmarks. Salary ranges and bonus targets are frequently presented as explicit components of the package, which supports clarity on what compensation is intended to include.
  • Retirement Support Retirement offerings stand out through RRSP matching and pension options that emphasize long-term security. A defined benefit pension option is also described, which is often treated as a differentiator versus many large employers.
  • Healthcare Strength Health coverage is described as comprehensive across medical, dental, vision, and prescriptions, with additional support such as EAP services and access to virtual care. Wellness accounts and reimbursements are also included, adding breadth beyond core insurance coverage.

Intact (intactfc.com) Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Toronto
18,239 Employees
Year Founded: 1809

What We Do

We are here to help people, businesses and society prosper in good times and be resilient in bad times. This is our purpose and the foundation of our company – it drives everything we do and gives meaning to our work. - Nous sommes là pour aider les gens, les entreprises et la société à aller de l'avant dans les bons moments et à être résilients dans les moments difficiles. C'est notre raison d'être et l'essence même de notre entreprise

Similar Jobs

Sailor Health Logo Sailor Health

Care Concierge (Remote)

Healthtech • Social Impact • Telehealth
Remote
Canada
20 Employees
40K-50K Annually

DFIN Logo DFIN

Account Executive

Fintech • Software
Remote or Hybrid
Canada
1750 Employees

Coursera + Udemy  Logo Coursera + Udemy

Senior Product Designer

Artificial Intelligence • Consumer Web • Edtech • Enterprise Web • HR Tech • Social Impact • Generative AI
Remote or Hybrid
Canada
1500 Employees
124K-155K Annually

Coursera + Udemy  Logo Coursera + Udemy

Program Manager

Artificial Intelligence • Consumer Web • Edtech • Enterprise Web • HR Tech • Social Impact • Generative AI
Remote or Hybrid
Canada
1500 Employees
78K-98K Annually

Similar Companies Hiring

Granted Thumbnail
Artificial Intelligence • Healthtech • Insurance • Mobile • Financial Services
New York, New York
23 Employees
Hanover Park Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
42 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account