Intact Financial Corporation

Senior Security Advisor, Threat Modeller

Intact Financial Corporation$101K — $124K *
Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in computer science or equivalent experience
  • Minimum of 10 years in IT with at least 5 years in information security
  • Experience in application/cloud security, threat modelling, or incident response
  • Strong understanding of web and cloud application vulnerabilities
  • Relevant certifications such as CISSP, CISM, OSCP, etc.
  • Excellent communication skills for cross-functional collaboration
  • Experience working in a Security Operations Centre (SOC) or with threat modelling tools

Responsibilities

  • Perform structured threat modelling using frameworks like STRIDE and MITRE ATT&CK
  • Identify assets, trust boundaries, and potential attack paths
  • Translate threat modelling outcomes into security requirements and controls
  • Collaborate with teams to review proposed architectures for security implications
  • Integrate threat modelling into product development workflows
  • Participate in secure code reviews to facilitate security requirements
  • Communicate technical risks clearly to both technical and non-technical stakeholders

Benefits

  • Annual bonus plan with potential payout of up to double the target
  • Employee Share Purchase Plan (ESPP) with company matching
  • Comprehensive defined benefit pension plan for guaranteed income
  • Flexible pension offerings for long-term security
  • Support for professional development and continuous learning
Full Job Description
Salary range (but not limited to): 101,800 - 124,400 Annual bonus target, based on the base salary, with a potential payout of up to double the target (subject to personal and company performance): 12% As part of our commitment to Win As A Team, we share our success with employees through our annual bonus plan and Employee Share Purchase Plan (ESPP) - with Intact matching 50% of your net shares. Our pension offerings provide flexibility and long-term security for our employees beyond their careers. We are one of the few companies offering the opportunity to receive guaranteed income for life via our defined benefit pension plan. Salary for the candidate will be determined taking into consideration a number of factors including: experience, skills, qualifications, anticipated contribution to role, internal equity, etc. The salary range presented above is based on a 35-hour workweek and would represent a majority of different candidate profiles. However, we encourage candidates who may fall outside of this range to apply as well. About the role We're looking for a Senior Security Advisor (Threat Modeller) to join our growing team! What you'll do here:
  • Perform structured threat modelling (e.g., STRIDE, MITRE ATT&CK, kill chain, attack trees, misuse/abuse cases) for applications, systems, and architecture patterns.
  • Work with data flow diagrams (DFDs), and architecture diagrams for new and existing systems.
  • Identify assets, trust boundaries, entry points, and potential attack paths.
  • Assess the likelihood and impact of identified threats, and assign inherent and residual risk ratings.
  • Translate threat modelling outcomes into clear security requirements and recommended controls. Document control gaps and track remediation activities through to closure.
  • Collaborate with product, architect, developers, and engineers to support solution design by reviewing proposed architectures, patterns, and design decisions for security implications and providing recommendations.
  • Work with stakeholders to integrate threat modelling into product development workflows (e.g., SDLC, Agile, project delivery) across the organization.
  • Participate in secure code reviews to support security requirements and threat mitigations.
  • Plan and facilitate threat modelling workshops.
  • Communicate complex technical risks in clear, business-relevant language to both technical and non-technical stakeholders.
  • Contribute to the development and continuous improvement of threat modelling methodologies, templates, and tooling.
  • Support incident response and post-incident reviews by mapping exploited paths back to threat models and identifying improvements.
  • Maintain an up-to-date understanding of the threat landscape, including tactics, techniques, and procedures (TTPs), including those relevant to AI-related technologies. This includes staying current with relevant threat intelligence.
  • Apply the Maestro framework (or similar) to structure and standardize threat modelling activities for use cases involving AI agents.
What you bring to the table:
  • Bachelor's degree in computer science, or any combination of equivalent education and experience.
  • Minimum ten (10) years of experience in information technology, including at least five (5) years in information security, with demonstrated experience in one or more of the following areas: application/cloud security, security architecture, threat modelling or risk assessment, threat intel, incident response, SOC, SIEM, vulnerability management, and red teaming or penetration testing.
  • Strong knowledge of information security management principles and practices.
  • Strong ethical principles and understanding of business and information security ethics.
  • Good knowledge of common security vulnerabilities of web and cloud applications and operating techniques from sources such as SANS, OWASP Top 10 and Cloud Security Alliance (CSA).
  • Relevant certifications include (but are not limited to): CISSP, CISA, CISM, CGEIT, CRISC, GSEC, GISP, CCSP, SSCP, CSSLP, OSCP, SABSA, CEH, GCIH, GCTI, GCFE.
  • Excellent oral and written communication skills - Need to interact on a regular basis with colleagues across the country.
  • Positive attitude, team spirit and eagerness to learn.
  • Critical mind.
  • Experience working in a Security Operations Centre.
  • Master the digital investigation concepts such as the chain of custody and the digital evidence.
  • Demonstrated commitment to training, self-learning and maintaining proficiency in the technical cybersecurity domain.
  • Experience with threat modelling tools is an asset (e.g., Microsoft Threat Modeling Tool, IriusRisk, Threat Dragon, in-house tools).
  • Experience working with diagramming tools is an asset (e.g., draw.io, Lucidchart, Visio) or code-based diagrams (e.g., PlantUML).
  • Proficiency in English is required; fluency in French is a plus.
  • No Canadian work experience required however must be eligible to work in Canada.
#LI-Hybrid Ce poste jouera un rôle essentiel au sein de notre équipe. | This position will fill an essential role in our team.

About Intact Financial Corporation

Intact Financial Corporation is a Canadian insurance company that provides property and casualty insurance to individuals and businesses. The company operates in Canada and the United States and offers a range of insurance products, including auto, home, and commercial insurance. Intact Financial Corporation was founded in 1809 and is headquartered in Toronto, Canada.
Learn more about Intact Financial Corporation
Size
16,000 employees
Industry

Similar Jobs

More Jobs at Intact Financial Corporation

More Information Technology Jobs

Find similar Senior Security Advisor, Threat Modeller jobs: