Security Risk Oversight Specialist
Manitoba Hydro is consistently recognized as one of Manitoba's Top Employers! We are a leader among energy companies in North America, recognized for providing highly reliable service and exceptional customer satisfaction. Join our team of Manitoba's best as we continue to build a company that champions safety, supports innovation, and delivers on our commitment to customer service - while actively fostering a diverse, equitable, and inclusive workplace reflective of the communities we serve.
- Competitive salary and comprehensive benefits package.
- Nine-day work cycle, typically resulting in every other Monday off to support a balanced approach to work, family life and community.
Position Overview:
Under the general guidance of the Security Risk Management Lead, this position supports the execution and continuous improvement of security risk oversight activities across Manitoba Hydro. The role is responsible for supporting regulatory and security requirements, internal and external audit coordination, evidence management, remediation tracking, exception management, risk register maintenance, investigation support, and post-loss assessment activities. The position helps ensure security-related records, issues, decisions, and reporting practices are maintained, monitored, and aligned with corporate priorities, regulatory expectations, risk management practices, and stakeholder requirements.
Responsibilities:
- Provide recommendations for Technology Security planning and direction.
- Provide Technology Security consulting services to the IT Services Division and the Corporation, including EMS/SCADA systems support, to ensure consistency of security practices across all systems and networks.
- Provide Technology Security Incident Management (manage the reporting, investigation and resolution of data security incidents).
- Conduct Technology Security assessments of systems, applications and networks.
- Support Investigations and Post-Loss Assessments.
- Report on Security Risk and Oversight Activities.
- Track Remediation, Exceptions, and Risk Register Updates.
- Maintain contact with industry security standards setting groups, and an awareness of legislation and regulations pertaining to information security.
- Provide support to all Technology Security compliance requirements.
- Coordinate support for internal and external audits.
- Conduct Technology Security research and keep current on all Technology Security-related issues.
Qualifications:
- A four-year degree in Computer Science from an institute of recognized standing with a minimum of five years of related experience including information technology (IT) or industrial control system (ICS) Support experience, including cyber risk management, governance, policy, risk reduction and mitigation, IT and ICSS protection, and regulatory requirements related to cybersecurity;
- OR
- A two year diploma in Computer Technology from an institute of recognized standing with a minimum of seven years of related experience including information technology (IT) or industrial control system (ICS) Support experience, including cyber risk management, governance, policy, risk reduction and mitigation, IT and ICSS protection, and regulatory requirements related to cybersecurity.
- Certified or be willing to obtain certification as a Certified Information System Security Professional (CISSP) from (ISC)². Certifications such as Cyber Security specific (CISM, CRISC, OSCP, CEH, CGIH, GPE, SANS, ISAACA CSX Cybersecurity Practitioner (CSX-P)), would be an asset.
- An in-depth understanding of Manitoba Hydro's computing and network infrastructures (IT and ICSS/CIP) and security programs process and technology.
- In-depth knowledge of best and industry-leading cyber risk management, cyber security concepts, controls, frameworks, policies, standards, tools.
- Strong written and verbal communication skills with a demonstrated ability to communicate effectively, deliver reports, recommendations, and presentations, and the ability to build and maintain harmonious working relationships with staff across the enterprise at all levels.
- Experience supporting data security incident reporting, investigation, resolution tracking, and escalation in accordance with established incident management processes.
- Experience maintaining or supporting a risk register, including tracking risks, issues, remediation actions, exceptions, decisions, and status updates.
- Demonstrated initiative and ability to prioritize and achieve results in a timely manner.
- Experience supporting security investigations, post-loss assessments, root cause analysis, documentation of findings, and tracking of corrective actions.
- Capacity to deal effectively with groups and individuals from all levels of the Corporation.
- Capacity to deal effectively with external organizations and groups.
- Effective communication and presentation skills.
- Excellent writing skills for developing both informational materials and security documentation.
- Capacity to deal effectively with the rapidly changing arena of…
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search: