- Company Name
- The Salvation Army in Canada
- Job Title
- Solution Specialist, Information Security
- Job Description
-
**Job Title:** Solution Specialist, Information Security
**Role Summary:**
Responsible for protecting the organization’s critical data by designing, implementing, and governing security controls across cloud and on‑premise environments. Leads security architecture initiatives, conducts risk assessments, ensures compliance with standards, and collaborates with stakeholders to embed secure practices throughout the enterprise.
**Expectations:**
- Define and drive the security architecture roadmap.
- Deliver secure cloud solutions aligned with business and architectural standards.
- Conduct continuous vulnerability management and incident response.
- Maintain compliance with ISO 27001, NIST CSF, PCI DSS, and internal policies.
- Provide security awareness training and act as a trusted advisor to business units.
**Key Responsibilities:**
- Lead the development and adoption of security architecture strategy.
- Design, configure, and deploy cloud‑based security solutions (AWS, Azure, GCP).
- Perform vulnerability scans, penetration tests, and security audits; remediate findings.
- Manage security alerts, resolve tickets, and document incident investigations.
- Create and maintain security policies, playbooks, and incident‑response documentation.
- Review IT procurements and project designs for architectural compliance.
- Engage with business stakeholders to translate requirements into secure designs.
- Conduct security awareness sessions and training for employees.
- Monitor emerging threats and recommend proactive mitigation measures.
- Own architectural reviews and sign‑offs, ensuring reuse of secure components.
**Required Skills:**
- 10+ years experience with vulnerability scanners, EDR, and SIEM platforms.
- Strong expertise in AWS, Azure, and GCP security services.
- Deep knowledge of ISO 27001, NIST CSF, PCI DSS frameworks.
- Proficient scripting (Python, Perl, Shell) for automation.
- Hands‑on experience with WAFs, email gateways, firewalls, encryption protocols.
- Incident response and computer forensics skills.
- Experience in Microsoft infrastructure, network design, data management, and application development.
- System integration, API‑led design, and ESB platform familiarity.
- Excellent presentation, negotiation, and relationship‑building abilities.
**Required Education & Certifications:**
- University degree in Computer Science or related field.
- Professional certifications such as CISSP, CISA, CEH, and Security+.