Description:
Raise is currently hiring an IT Cyber Security Consultant on behalf of our client. They’re expanding their team to meet growing needs, making this a unique opportunity to work with an industry leader. Our Client, is one of the largest electrical energy suppliers in Canada
Note: The primary pay rate is based on T4 classification; however, we will also consider applications from candidates interested in an INC classification, where applicable.
Description
The IT Cybersecurity Consultant specializing in Cybersecurity Policy, Governance, and Risk. Reporting directly to the Cybersecurity Governance and Performance Lead, will play a critical role in developing, reviewing, and modernizing ’s cybersecurity policies and standards. This role bridges the gap between high-level governance frameworks and practical technology implementations across both Enterprise IT and Operational Technology (OT) environments. You will serve as a trusted advisor across business units, identifying security control gaps and driving action plans that protect the organizations critical infrastructure while ensuring strict regulatory compliance.
Responsibilities
- Policy & Governance Development
- Framework & Standard Development: Draft, review, and refine ’s cybersecurity policies and baseline technical standards, aligning them with established frameworks (NIST CSF / 800-53r5, ISO 27001/2, COBIT) and evolving domains like cloud security and AI risk.
- Control Gap Identification: Perform comprehensive reviews to identify policy and control gaps; recommend prioritized, tailored remediations for both IT and OT environments.
- Stakeholder Engagement: Collaborate closely with internal business units and technical leads to address concerns surrounding policy implementation, operational impact, and regulatory requirements.
- Risk Management & Regulatory Compliance
- Regulatory Compliance Support: Support compliance readiness initiatives, with a specific focus on North American Electric Reliability Corporation Critical Infrastructure Protection (NERC CIP) standards and BC FIPPA regulations.
- Compliance Impact Assessments: Conduct assessments for IT and OT projects to ensure new systems comply with internal policies, external mandates, and industry best practices.
- Continuous Modernization: Evaluate emerging technology risks—including Artificial Intelligence (AI) and cloud adoption—to integrate appropriate governance and risk management controls into ’s security posture.
- Project & Operational Alignment
- Security Requirements Guidance: Assist business units in defining security requirements, design considerations, and implementation strategies during project lifecycles.
- Operational Transition Support: Support the smooth transition of new security frameworks and tools from project phase to ongoing operations.
- Program Support: Assist with ad-hoc governance, risk assessment, and incident management support tasks as needed across the broader Cybersecurity & Compliance team.
Qualifications
- 5 years of overall experience in Information Technology with at least three (3) years focused directly on Cybersecurity (or equivalent).