Join one of Canada's Best Workplaces

Senior Technical Security Consultant

Location
Nova Scotia
Department
Information Security
Role Type
Permanent
Salary
To be discussed
Closing Date
11/30/2022
Apply now

Technology is at the heart of driving Admiral’s business.

About Admiral Tech

With a history of innovation, the Admiral Group are bringing our world-class Tech department to Canada for the first time ever.

From Cloud through to DevOps, our Technology department consists of over 600 people and is an exciting and fast-paced environment to work in. If you’re looking for a technically challenging and rewarding role, with outstanding support and opportunities for progression, you’ve come to the right place.

More on Admiral Tech 

About Admiral Canada

We’re more than you think.

One of the UK’s most recognizable insurance and financial service providers, Admiral offers insurance, loans, and various other products to over 9.1 million international customers.

In 2007, Admiral launched its Canadian office in Halifax with a small group of 20 staff. Today, we employ 500 people throughout Nova Scotia who support our UK customers with home and motor insurance policies.

We’ve been recognized as one of Canada’s Great Places to Work every year since 2010 and have also been named one of Nova Scotia’s and Atlantic Canada’s Top Employers annually since 2015. In 2022, the Great Place to Work® Institute ranked Admiral as the 4th Best Workplace in Canada.

The next chapter in the Admiral Canada’s success story is bringing Admiral Tech to Canada. This role is an exceptional opportunity to be the architect of Admiral Tech in Canada and influence its foundation.

About the Job

We are looking for a senior level consultant to work as part of our Security Consultancy team to support the delivery of business change as we move capabilities to the cloud in a scaled agile environment with a strong and evolving DevSecOps approach. Work to support fast-paced change in an exciting and growing business as Admiral continues to develop its offerings placing the customer at the centre of everything we do.  

As a Senior Technical Security Consultant your main responsibilities will be:

  • Understand the Strategic Business Objectives, actively contribute to achieving them. 
  • Provide technical security consultancy to the change delivery functions – agile & waterfall.
  • Assess security posture in CI/CD pipelines and support improvement.
  • Support the Security Champions Programme and DevSecOps.
  • Liaise and collaborate with technical stakeholders within Agile Tribes, Projects, and Programmes. 
  • Assess changes for technical vulnerabilities, threat models, assess security risk exposure, and identify appropriate controls to bring the risk within tolerance.
  • Engage effectively with specialists in Security Architecture, Security Operations, Security. Culture, Security Delivery, and Security Risk and Governance teams to ensure completeness and consistency of the advice provided to delivery functions.
  • Perform design reviews to ensure security principles and controls are included from design phase. 
  • Ensure advice provided is of a high standard and based on best practice, supported by Security Leadership and withing the cost and risk tolerance of the organisation.
  • Work closely with specialists in Security Operations to develop operational use cases for detect and respond capabilities by ensuring Logging and Monitoring, Incident Response, and Threat Intelligence are all considered and included in security requirements, are implemented, tested, and validated by the business change delivery owner.
  • Collaborate with all areas of Infosec to provide continuous improvement of the advice provided from knowledge gained from analysing and resolving information security incidents that can be used to reduce the likelihood and/or impact of future incidents.
  • Apply the information security risk assessment process to identify risks within the scope of the information security management system and identify the risk owners.
  • Act as a champion for information security initiatives and maintain high standards of integrity and professionalism.
  • Delivering risk assessment reports, threat modelling, and risk treatment recommendations in a timely and repeatable manner.
  • Contribute to, and maintain, an effective risk management mechanism to ensure that system owners have accurate and current a view of information risk exposure.
  • Meeting the InfoSec strategic objectives. 
  • Continuously develop technical security skills and capabilities in line with the organisation’s strategic objectives.
  • Development of security playbooks and component specifications.
  • Mentor junior consultants in the team.
  • Support the Technical Security Consultancy Team Manager with workload management and artefact reviews as required.
  • Support the Technical Security Consultancy Team Manager with delivering roadmaps to the department.

Experience and Qualifications Required

Essential skills 

  • Technical background, with knowledge of one or more of the following, Development, IT support, Data Science, networking or system administration. 
  • Deep knowledge and understanding of Cloud migration and Application Security development lifecycle and DevSecOps principles, automation, and familiarity with security architecture modelling. 
  • Knowledge and experience of securing Azure and/or Google Cloud Platforms.
  • Knowledge and experience of using at least one risk methodology.
  • Security Software as a Service implementations.
  • Strong stakeholder management and communication skills and a proven track record of working with businesses to meet strategic objectives.
  • Ability to discuss highly complex and technical problems and solutions in business language.
  • Confident in presenting recommendations to the Security Leadership for go / no-go meetings.
  • Great influencer, enabling the business to deliver safely and at pace.
  • Proactive and can work on own initiative with the ability to effectively prioritise work.
  • Experienced in cyber security frameworks such as NIST, CIS20, MITRE Attack and STRIDE.

Desirable 

  • Experience of threat modelling, risk/posture assessments, and control implementation. 
  • Educated to degree level related to information security risk management. 
  • Experience of agile and waterfall delivery environments. 
  • Recognised security professional qualifications (e.g., CISSP, CCSP, CISMP).
  • Cloud specific qualifications (e.g., CSA CCSK, CCSP, AZ-900, GCP fundamentals).

Salary, Benefits, and Work-Life Balance

We do not have a set salary for this position, as it will be dependent on the successful candidate’s experience. We are happy to see CVs from all candidates who meet the requirements and will be happy to discuss the remuneration package.

At Admiral, we are proud to be a diverse business where we put our people and customers first. We have great benefits to ensure employees have a great work-life balance; it's one of the reasons we’re consistently ranked nationally as one of Canada’s (and the world’s) best workplaces. To that end, you will have an element of scheduling autonomy to strike an appropriate balance between personal flexibility and business needs.

All colleagues will receive 31 days of paid time off (including Statutory holidays) annually when you join us, and this will increase with length of service, up to a maximum of 38 days (including statutory holidays).

You can view some of our other key benefits here 

Our Commitment to You

As an equal opportunity employer, Admiral is committed to fostering a diverse and inclusive workplace free from discrimination based on race, national origin, gender, gender identity, sexual orientation, ability, age, family status or any other legally protected status. All qualified applicants will receive equal consideration for employment on that basis.

All qualified applicants will receive equal consideration for employment.