3 month contract (not being extended)
Hybrid 1x per week in Toronto
Pay: $45-65/hr incorp
Required Qualifications
- 2-5+ years of hands-on experience in network/security engineering or security operations with strong firewall exposure.
- Working experience reviewing and interpreting firewall rules/policies, including the ability to analyze rule intent and map it to applications/services.
- Experience hands on in vulnerability management and threat detection
- Experience with enterprise firewall technologies, specifically Palo Alto and/or Check Point
- Familiarity with Cisco security technologies such as Cisco Firepower / Cisco IDS/IPS / ASA.
- Comfort working in a regulated environment with governance/compliance requirements
- Experience with ticketing systems and change management processes (creating change records, supporting CAB routines).
- Strong documentation skills and ability to work through high-volume, detail-oriented tasks accurately.
Nice-to-Have Qualifications
- Experience with Broadcom security products (e.g., web/SSL-related controls).
- Broader exposure to multiple security appliances/platforms (the more, the better).
- Prior experience updating/maintaining network or security architecture diagrams.
Job Description
Insight Global is looking for two Cybersecurity Specialists (Firewall & Threat Defense) to support a major Canadian financial institution’s cybersecurity team on a short-term engagement from August through October (3 months; no extension beyond October). These resources will help relieve full-time employees who are tied up on higher-priority initiatives by taking on firewall rule accreditation work and targeted BAU/security operations support across multiple security platforms.
Key Responsibilities
Firewall Rule Accreditation (Primary Deliverable)
- Review and analyze large volumes of firewall policies/rules (approximately 20,000 rules).
- Interpret firewall rule policies (source/destination, ports/services, zones, management/common rules).
- Associate/attest rules to the correct internal application codes and document findings as required for annual governance/compliance.
Firewall Operations Support (BAU)
- Assist with day-to-day firewall-related requests and administrative activities.
- Create and manage service tickets/requests as needed (certificates, access/changes, etc.).
- Change Management Support
- Create and maintain change records (CRs) in the change management system.
- Participate in/prepare for weekly Change Advisory Board (CAB) reviews and support change execution activities.
Technical Security Standards (TSS) & Compliance Support
- Support compliance activities for security appliances (identify misconfigurations, assist with remediation planning/execution via CRs).
Vulnerability Management Support (BAU)
- Support remediation efforts for lower-severity vulnerabilities (primarily P2/P3), escalating P1s to full-time team members per process.
Threat Defense Support (as needed)
- Support Cisco threat defense activities, including IDS/IPS context and tasks such as Snort signature update support (where applicable).
Documentation / Diagram Updates
- Update and maintain network/security diagrams to reflect current infrastructure and in-line/spanning deployments of security appliances.
We may use artificial intelligence tools to assist with the screening, assessment, or selection of potential applicants for this position.