Position Overview
Calian ITCS is currently seeking a Senior IT Security TRA Analyst for an upcoming contract.
Responsibilities
- Review the security requirements traceability matrix (SRTM) and evidences
- Set clear expectations per control (or group of controls) of the SRTM as to what is required to confirm these controls are in place and functioning as expected.
- Develop/update/maintain the Security Requirements Traceability Matrix (SRTM) and the Security Assessment Report and Security Requirements Traceability Matrix (SRTM)
- Evaluate, against the Government of Canada Security Control Profile for GC Services, the current posture of tenant. This will require grading (PASS, FAIL) for each requirement.
- Set clear expectations per control (or group of controls) as to what is required to confirm these controls are in place and functioning as expected.
- Security Assessment Report
- Prepare a final Security Assessment Report summarizing the findings following SRTM evaluation.
- Work in line with the following:
- Evaluation to be conducted against the Government of Canada Security Control Profile for cloud-based GC Services (4. GC Cloud PBMM Security Control Profile).
Qualifications
- Clearance: Secret (mandatory)
- Language: English
- 10 years’ relevant experience in Security Assessment & Authorization (SA&A) and TRA work
- 5+ years’ direct experience performing SA&A work for Azure and working in cloud environments
- 5+ years’ direct experience in the assessment of evidence and writing of formal Security Assessment reports (ITSG-33 based).
- 5+ years’ project experience & direct working knowledge of the GC standards, policies and guidelines and the principles of security and privacy by design.
- 5+ years’ experience reviewing the following documents:
- Experience in the development of the following:
- 5+ years’ experience working as a TRA Analyst with experience developing and updating TRAs
- Experience understanding and applying GC IT Security policies
- 5+ years’ experience undertaking developing interpreting and applying IT C&A/SA&A methodology and policies instruments.
#LI-LL1# #ID-LL1#