IT Advisor - Technology Cybersecurity
Job Description & How to Apply Below
Hours of work: Full-time (37.5 hrs/week)
No. of positions: 1
What you’ll do- Reporting to the Technology Cybersecurity Manager, the IT Advisor will conduct cybersecurity security reviews, risk, and compliance activities within the Technology KBU.
- Conduct cybersecurity risk, threat, vulnerability, and security impact assessments for technology and corporate initiatives. Identify risks, assess control effectiveness, recommend improvements, and support risk-informed business decisions.
- Determine, document, and monitor risk treatment plans and risk acceptance decisions in accordance with organizational risk management processes.
- Support cybersecurity governance activities through the development, maintenance, and application of cybersecurity policies, standards, procedures, and control frameworks.
- Maintain knowledge of emerging cyber threats, industry standards, regulatory requirements, and internal policies and procedures.
- Lead and coordinate third party penetration testing activities and track remediation of identified findings.
- Conduct internal penetration testing, vulnerability assessments, and security reviews using approved tools and methodologies.
- Lead and coordinate third party cybersecurity risk assessments, including evaluating vendor security posture, assurance reports (e.g., SOC 2 Type II), and compliance with security and regulatory requirements.
- Review Privacy Impact Assessments (PIAs) and assess the adequacy of security controls and privacy safeguards.
- Participate as a cybersecurity risk and governance SME on projects and initiatives to improve BC Hydro's cybersecurity posture.
- Develop cybersecurity risk reporting, communicate risk findings and recommendations to stakeholders, and support responses to internal and external audits, assessments, and compliance reviews.
- University degree or experience in relevant discipline or equivalent combination of education and experience.
- Ability to obtain security clearance for a Security Sensitive Position classification.
- Minimum of 7 years of progressively responsible experience in cybersecurity, information security, governance, risk, compliance, audit, or security assurance.
- Experience across cybersecurity governance, risk management, security reviews, vulnerability management, third party risk, compliance, or control assessments.
- Knowledge of cybersecurity frameworks, standards, policies, and regulatory requirements, such as NIST, ISO 27001/27002, COBIT, and NERC CIP.
- Ability to communicate cybersecurity risks, controls, vulnerabilities, and recommendations clearly to technical and non-technical stakeholders.
- Strong relationship-building, influencing, presentation, documentation, facilitation, and prioritization skills.
- Cybersecurity certification (e.g. CISSP, GSEC, GCIA, GCWN, CISA, CISM, CCNA, GPEN) would be considered an asset.
- Experience in Industrial Control Systems (ICS) including SCADA and other Operational Technology (OT) used in the Energy sector would be considered an asset.
- A minimum of 15 paid vacation days
- Flexible work model, depending on your role type
- Training and development courses
For more information on the benefits we offer, visit
What else you should knowDon't forget to update your Candidate Profile with your current resume and copies of your certifications. This will ensure we have all the necessary information to assess your application without any delays.
#J-18808-LjbffrNote that applications are not being accepted from your jurisdiction for this job currently via this jobsite. Candidate preferences are the decision of the Employer or Recruiting Agent, and are controlled by them alone.
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search:
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search:
Search for further Jobs Here:
×