×
Register Here to Apply for Jobs or Post Jobs. X

Security Risk Management Lead

Job in Winnipeg, Manitoba, A3C, Canada
Listing for: Manitoba Hydro
Full Time position
Listed on 2026-08-18
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security & Data Protection
Salary/Wage Range or Industry Benchmark: 73000 - 100000 CAD Yearly CAD 73000.00 100000.00 YEAR
Job Description & How to Apply Below

Manitoba Hydro is consistently recognized as one of Manitoba's Top Employers! We are a leader among energy companies in North America, recognized for providing highly reliable service and exceptional customer satisfaction. Join our team of Manitoba's best as we continue to build a company that champions safety, supports innovation, and delivers on our commitment to customer service - while actively fostering a diverse, equitable, and inclusive workplace reflective of the communities we serve.

  • Competitive salary and comprehensive benefits package.
  • Nine-day work cycle, typically resulting in every other Monday off to support a balanced approach to work, family life and community.
Position Overview:

Under the general direction of the Security Portfolio Governance Risk & Compliance Lead, you will supervise and lead the Security Risk Management team responsible for delivering enterprise security risk management services, including security risk assessments, third-party security risk reviews, risk acceptance and exception management, risk registers, remediation tracking, audit support, investigation support, and post-loss assessment activities. This position provides day-to-day leadership, oversight, quality review, and risk reporting to ensure security risks are consistently identified, documented, communicated, tracked, and escalated in support of informed business decisions and effective security risk governance across Manitoba Hydro.

Responsibilities:
  • Provide leadership, guidance, and direction to the Security Risk Management section.
  • Provide Cyber Security consulting services to the Enterprise, including EMS/SCADA systems support and Telecommunications, to ensure consistency of Cyber Security practices across all systems and networks.
  • Responsible for translating business unit goals into specific strategic actions and measures within the section and taking remedial action necessary to ensure goals are achieved.
  • Plan for the short-term and assist with the long-term utilization of available resources (human, financial, and technology) to meet corporate plans and priorities in a systematic and economical manner as it pertains to Enterprise cyber security.
  • Support the security risk acceptance process, including intake, analysis, documentation, escalation, approval tracking, expiry monitoring, and reporting of accepted risks and exceptions.
  • Develop and maintain security risk reporting for leadership and stakeholders, including risk trends, open issues, remediation status, exceptions, third-party risks, and other key indicators.
  • Coordinate risk registers and related risk management records, including evidence management, remediation tracking, exception management, status updates, and follow-up with accountable owners.
  • Conduct Cyber Security risk assessments and reviews of technology, systems, applications, networks, processes, and controls.
  • Maintain contact with industry cyber security standards setting groups, and an awareness of legislation and regulations pertaining to Cyber.
  • Stay abreast of and inform Enterprise stakeholders and technical support staff of applicable global and Canadian cyber security developments and trends.
  • Ensure adequate performance measures are in place; develop and implement plans to meet performance objectives, reporting results, and follow up on exceptions.
  • Interview, evaluate, and recommend staff replacements, promotions, suspensions, and dismissals. Prepare performance reviews, job development planning, job descriptions, and review responsibilities to ensure positions are properly classified.
Qualifications:
  • Four-year degree in a relevant discipline such as cybersecurity, information systems, computer science, engineering, business, risk management, or a related field from a university of recognized standing, plus six years of progressively responsible related experience in security risk management, cybersecurity governance, third-party risk management, audit support, or related functions, including three years of supervisory or team leadership experience;
  • OR
  • Two-year diploma in a relevant discipline such as cybersecurity, information systems, computer science, engineering, business,…
Note that applications are not being accepted from your jurisdiction for this job currently via this jobsite. Candidate preferences are the decision of the Employer or Recruiting Agent, and are controlled by them alone.
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search:
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary