Sr. TRA/Threat Modeling Security Consultant

Post Date

Jul 02, 2026

Location

Toronto,
Ontario

ZIP/Postal Code

M5J 0
Canada
Sep 21, 2026 Insight Global

Job Type

Contract

Category

Security Engineering

Req #

TOR-0bfc0c13-e9e3-4ed8-b8fe-1cbd5e62d636

Pay Rate

$54 - $68 (hourly estimate)

Who Can Apply

  • Candidates must be legally authorized to work in Canada

Job Description

• Strategic Leadership and Governance – You will drive the creation and ongoing refinement of the Application Security strategy, with a particular emphasis on advancing threat modeling and security testing methodologies and tools. This role requires strong cross-functional collaboration to gather requirements, develop business cases and lead projects, including proof of concepts, in the capacity of a product owner. Having a continuous improvement mindset is essential, as you will be responsible for identifying and implementing opportunities to enhance both security testing processes and operational efficiency within the domain.
• Security Testing and Assessment – You will oversee the implementation, management, and continuous improvement of threat modeling services, security testing services such as Enterprise SaaS Application Security, and supporting our risk advisory partners during threat risk assessments. You will measure and report on the effectiveness of these activities to ensure comprehensive coverage and timely remediation of identified vulnerabilities. Additionally, you will conduct regular reviews and analysis of testing results, trends, and emerging threats, using these insights to inform and strengthen risk mitigation strategies.
• Communication and Advocacy – You will prepare and delivery clear, compelling documentation and presentations to executive leadership, effectively articulating the value and necessity of threat modeling and security testing initiatives. You will also drive awareness and provide training to application development teams, ensuring they understand the importance and effective use of threat modeling and security testing tools and processes. Your role will include evaluating business needs against current and emerging risks and providing actionable recommendations to strengthen the organization’s security posture.
• Advisory and Relationship Management – You will act as a trusted advisor to development teams, operations, infrastructure and risk advisory teams, guiding them to integrate threat modeling and security testing into their workflows and prioritize remediation efforts based on risk. You will oversee the identification, assessment and management of security risks and design flaws in key applications, offering practical and prioritized solutions. Staying current with the evolving threat landscape and cultivating partnerships with industry peers and vendors will be essential to ensuring the bank remains at the forefront of application security.

We are a company committed to creating diverse and inclusive environments where people can bring their full, authentic selves to work every day. We are an equal opportunity/affirmative action employer that believes everyone matters. Qualified candidates will receive consideration for employment regardless of their race, color, ethnicity, religion, sex (including pregnancy), sexual orientation, gender identity and expression, marital status, national origin, ancestry, genetic factors, age, disability, protected veteran status, military or uniformed service member status, or any other status or characteristic protected by applicable laws, regulations, and ordinances. If you need assistance and/or a reasonable accommodation due to a disability during the application or recruiting process, please send a request to HR@insightglobal.com.To learn more about how we collect, keep, and process your private information, please review Insight Global's Workforce Privacy Policy: https://insightglobal.com/workforce-privacy-policy/.

Required Skills & Experience

- 7-10+ years of experience working within Information Security with a focus on building processes and frameworks within Threat Modeling/TRA's at large enterprises
- Assist with implementing the strategy on how STRIDE methodology will integrate with SDLC and have developers work-in this methodology when they're developing
- Experience with creating the framework on how to build out TRA's appropriately
• You can demonstrate experience in Application Security, Vulnerability Management, and data security standards and best practices. You bring senior-level experience in application security or similar security services. It is considered an asset if you have threat modeling knowledge and experience. You can demonstrate experience in dynamic and static application security testing, penetration testing, web application firewalls, runtime protection, mobile application security, and broader threat and vulnerability management capabilities.

Benefit packages for this role will start on the 1st day of employment and include medical, dental, and vision insurance, as well as HSA, FSA, and DCFSA account options, and 401k retirement account access with employer matching. Employees in this role are also entitled to paid sick leave and/or other paid time off as provided by applicable law.