Position Overview

Calian ITCS is currently seeking a Senior IT Security TRA Analyst for an upcoming contract.

Responsibilities

  • Review the security requirements traceability matrix (SRTM) and evidences
  • Set clear expectations per control (or group of controls) of the SRTM as to what is required to confirm these controls are in place and functioning as expected.
  • Develop/update/maintain the Security Requirements Traceability Matrix (SRTM) and the Security Assessment Report and Security Requirements Traceability Matrix (SRTM)
  • Evaluate, against the Government of Canada Security Control Profile for GC Services, the current posture of tenant. This will require grading (PASS, FAIL) for each requirement.
  • Set clear expectations per control (or group of controls) as to what is required to confirm these controls are in place and functioning as expected.
  • Security Assessment Report
  • Prepare a final Security Assessment Report summarizing the findings following SRTM evaluation.
  • Work in line with the following:
  • Evaluation to be conducted against the Government of Canada Security Control Profile for cloud-based GC Services (4. GC Cloud PBMM Security Control Profile).

Qualifications

  • Clearance: Secret (mandatory)
  • Language: English
  • 10 years’ relevant experience in Security Assessment & Authorization (SA&A) and TRA work
  • 5+ years’ direct experience performing SA&A work for Azure and working in cloud environments
  • 5+ years’ direct experience in the assessment of evidence and writing of formal Security Assessment reports (ITSG-33 based).
  • 5+ years’ project experience & direct working knowledge of the GC standards, policies and guidelines and the principles of security and privacy by design.
  • 5+ years’ experience reviewing the following documents:
  • Experience in the development of the following:
  • 5+ years’ experience working as a TRA Analyst with experience developing and updating TRAs
  • Experience understanding and applying GC IT Security policies
  • 5+ years’ experience undertaking developing interpreting and applying IT C&A/SA&A methodology and policies instruments.

#LI-LL1# #ID-LL1#

Loading...