Intact Financial Corporation

Security Advisor Specialist - Threat Modelling

Intact Financial Corporation$118K — $145K *
Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor’s degree in Computer Science, Engineering, or a related field, or equivalent experience.
  • At least 10 years of IT experience, with a minimum of 5 years in Information Security.
  • Proven expertise in application/cloud security, security architecture, or threat modeling.
  • Relevant certifications like CISSP, CISA, or OSCP are preferred.
  • Strong knowledge of multi-cloud security (AWS, Azure, GCP) and DevSecOps principles.
  • Familiarity with security tools (threat modeling, vulnerability management) is beneficial.
  • Excellent communication skills, with a requirement for bilingualism in Quebec.

Responsibilities

  • Serve as the primary Security contact for technology projects, offering guidance throughout the project lifecycle.
  • Lead threat modeling activities using methodologies like STRIDE and MITRE ATT&CK.
  • Develop threat-modeling materials, assessing threats and translating findings into security requirements.
  • Support security activities such as penetration testing and vulnerability assessments for technology readiness.
  • Collaborate with multiple teams to embed security into projects and facilitate threat modeling workshops.
  • Manage and document security findings in platforms like JIRA, ensuring appropriate remediation actions.
  • Enhance threat modeling capabilities through methodologies, templates, and training.
  • Stay updated on emerging technologies to effectively manage security risks.

Benefits

  • Flexible work arrangements and a hybrid work model.
  • Option to purchase up to 5 extra days off per year.
  • Comprehensive benefits supporting physical and mental wellbeing, including telemedicine and wellness accounts.
  • Employee Share Purchase Plan with company matching and guaranteed income options from a pension plan.
Full Job Description

Pay at Intact is about much more than just salary.

  • Flexible work arrangements and a hybrid work model

  • Possibility to purchase up to 5 extra days off per year

  • Multiple benefits offered to support physical and mental wellbeing, including telemedicine, Wellness account and much more

  • Share plan & other savings: up to 12% of salary or even more (ask how you could earn guaranteed income for life)

Salary range (but not limited to):

118,700 - 145,100

Annual bonus target, based on the base salary, with a potential payout of up to double the target (subject to personal and company performance):

15%

As part of our commitment to Win As A Team, we share our success with employees through our annual bonus plan and Employee Share Purchase Plan (ESPP) 6 with Intact matching 50% of your net shares.

Our pension offerings provide flexibility and long-term security for our employees beyond their careers. We are one of the few companies offering the opportunity to receive guaranteed income for life via our defined benefit pension plan.

Salary for the candidate will be determined taking into consideration a number of factors including: experience, skills, qualifications, anticipated contribution to role, internal equity, etc. The salary range presented above is based on a 35-hour workweek and would represent a majority of different candidate profiles. However, we encourage candidates who may fall outside of this range to apply as well.


About the role

We92re looking for a Cybersecurity Threat Modeling Specialist to join our growing team!

What you92ll do here:

  • Serve as the primary Security point of contact for technology initiatives, providing security guidance throughout the project lifecycle and formal sign-off before go-live.
  • Lead threat modeling for new or materially changed applications, systems, services, architecture patterns, and AI use cases. Apply appropriate methodologies, including STRIDE, MITRE ATT&CK, Mitre Atlas, Maestro, attack chains, and misuse or abuse cases.
  • Develop and validate threat-modeling supporting materials, such as: data flows, architecture diagrams, network diagrams and process flows. Identify critical assets, trust boundaries, entry points, and dependencies.
  • Assess threats based on exploitability and potential impact; assign inherent and residual risk ratings; and translate findings into prioritized security requirements, control objectives, mitigations, and go-live acceptance criteria.
  • Support the completion of critical security activities, including penetration testing, SAST, DAST, secure code reviews, third-party risk assessments, vulnerability assessments, and other assurance activities to support technology readiness.
  • Collaborate with product, architecture, development, engineering, cloud, and risk teams to review designs and technical decisions, facilitate threat-modeling workshops, and embed security into DevSecOps and project governance processes.
  • Manage Security Findings in platforms such as JIRA, including ownership, remediation, escalation, compensating controls, risk acceptance, and closure. Provide ad hoc security advice and document recommendations and follow-up actions.
  • Use threat modeling to support the three lines of risk management by helping first-line teams manage security risks, informing second-line oversight, and supporting third-line system audits.
  • Use post-incident lessons learned and threat intelligence to enhance threat modeling accuracy and recommendations.
  • Lead improvement and scale the threat-modeling capability through reusable methodologies, templates, patterns, guidance, tooling, training, and self-service workshops.
  • Stay ahead of emerging technology and frameworks, particularly across AI and modern application architectures to effectively support security risks management.
  • Report on threat-modeling coverage, recurring gaps, overdue actions, and trends to relevant committees and stakeholders.
  • Communicate complex technical risks, recommendations, and risk-based decisions clearly to technical and non-technical stakeholders.
  • Teach and mentor immediate team members on threat modeling, secure design, risk management, and security practices.

What you bring to the table:

  • Bachelor92s degree in Computer Science, Engineering, or a related field - or an equivalent combination of education and experience.
  • At least ten (10) years of experience in Information Technology, including a minimum of five (5) years in Information Security. Demonstrated experience in one or more of the following areas: application or cloud security, security architecture, threat modeling, risk assessment, threat intelligence, incident response, SOC or SIEM operations, vulnerability management, red teaming, or penetration testing.
  • Relevant professional certifications, such as but not limited to: CISSP, CISA, CISM, CGEIT, CRISC, GSEC, GISP, CCSP, SSCP, CSSLP, OSCP, SABSA, CEH, GCIH, GCTI, or GCFE.
  • Strong understanding of application, infrastructure, network, and data security across multi-cloud environments, including AWS, Azure, and GCP.
  • Familiarity with vulnerability management and DevSecOps principles, including secure design and CI/CD security.
  • Experience with scripting and automation to support threat modeling, security assessments, evidence collection, risk analysis, and the integration of security practices into development and delivery workflows is an asset.
  • Experience using threat-modeling tools, such as Microsoft Threat Modeling Tool, IriusRisk, Threat Dragon, or internally developed tools, is an asset.
  • Experience using diagramming tools, such as draw.io, Lucidchart, or Visio, or creating code-based diagrams using tools such as PlantUML, is an asset.
  • Excellent oral and written communication skills.
  • Positive attitude, team spirit and critical mindset.
  • For candidates located in Quebec, bilingualism is required considering the necessity to interact on a regular basis with English-speaking colleagues across the country
  • No Canadian work experience required however must be eligible to work in Canada


#LI-Hybrid

Il s92agit d99un nouveau rf4le au sein de notre e9quipe en pleine croissance | This role is a new member of our growing team.

About Intact Financial Corporation

Intact Financial Corporation is a Canadian insurance company that provides property and casualty insurance to individuals and businesses. The company operates in Canada and the United States and offers a range of insurance products, including auto, home, and commercial insurance. Intact Financial Corporation was founded in 1809 and is headquartered in Toronto, Canada.
Learn more about Intact Financial Corporation
Size
16,000 employees
Industry

Similar Jobs

More Jobs at Intact Financial Corporation

More Information Technology Jobs

Find similar Security Advisor Specialist - Threat Modelling jobs: