Sr IT Security Specialist

Hydro One
Brossard, QC, Canada
$212 a day (estimated)
Full-time
We are sorry. The job offer you are looking for is no longer available.

Hydro One is proud to be the largest electricity transmission and distribution provider in Ontario, serving nearly 1.4millioncustomers.

We have a long history in the industry with our roots dating back over 110 years to 1906. Since then, we have worked to grow and evolve to meet the changing needs of our customers and communities across Ontario.

Today, we’re focused on providing exceptional customer service and ensuring we are building safe communities where we live, work and play.

It’s an exciting time to join the team at Hydro One!

Specific Accountabilities :

  • Support the Manager, CIP Compliance Sustainment in effectively designing and developing strategies consistent with Hydro One positions related to standards and compliance requirements.
  • Support the Critical Infrastructure Protection (CIP) Senior Manager and / or Delegate in the successful sustainment of compliance to NERC CIP standards.
  • Oversee compliance sustainment and continuous improvement efforts associated with Hydro One’s NERC CIP compliance program.

Review NERC CIP related security incidents for systemic problems and opportunities for process improvements.

  • Support the Governance Delegates (GDs), Execution Delegates (EDs) and Process Owners (POs) accountable for the CIP standards / processes within the Hydro One Internal Compliance Program (ICP).
  • Advise the GDs on areas to focus when new changes are introduced to the NERC CIP standards. Coordinate with GDs / POs to help facilitate institutionalizing CIP compliance into Hydro One work processes.
  • Advise GD and ED in creation of non-compliance reports and remediation planning.
  • Provide oversight and ensure that an overall CIP process metrics dashboard is established with input from all stakeholders and is maintained in accordance with the reporting cycles.
  • Advise GDs / EDs in creation of non-compliance reports and remediation planning.
  • Ensure that the CIP Process Architecture is maintained and kept current.
  • Assist CIP GDs / POs with updating high impact or high complexity processes based on specific improvement or remediation efforts.
  • Assist CIP GDs / POs in identifying and rolling out complex key changes in support of specific improvement or remediation efforts.
  • Provide governance support to Process Owners in respect to escalating issues and concerns as well as formalizing support requests to create formalized projects and continuous improvement initiatives.
  • Perform preliminary reviews of Physical Security Plans, Cyber Security Policies and Technical Feasibility Exceptions related to CIP Standards and other related policies on an annual basis and report out to Manager.
  • Provide advice and deliver training and other communications to internal stakeholders, corporate and operations staff to assist in their understanding of security compliance processes.

This may include websites, toolkits, seminars and other employee engagement tools.

  • Collaborate with Reliability Standards Readiness and Strategy to provide direction to CIP GDs / POs. Support Reliability Compliance Assurance’s evidence audit operations and actioning of audit results
  • Enforce compliance with IT Security Policies and Standards across the enterprise using the compliance tracking framework.
  • Coordinate compliance enforcement activities with outsource service providers.
  • Develop and present management compliance reports to various stakeholders.
  • Engage and manage third parties to perform compliance exercises as necessary.
  • Participate in development and maintenance of IT Security Policies and Standards.
  • Manage compliance remediation activities.
  • Manage and motivate staff and contractors in projects.

Selection Criteria :

  • The candidate is expected to have demonstrated capability in the following areas :
  • University degree or related studies, or equivalent experience.
  • 10+ years experience in IT Security.
  • 5+ years relevant experience in a senior Information Security or IT Security role.
  • Demonstrated understanding of relevant standards and regulatory requirements (NERC CIP, Bill C-198, PCI, PIPEDA, etc.).
  • Relevant experience in IT security governance with the capacity to enforce standards and liaise with stakeholders.
  • Strong organizational and communication skills.
  • Ability to lead and work in a multi-team environment and drive completion of deliverables.
  • Ability to assess enterprise risk with proper recommendation on mitigation.
  • Proven ability to meet deadlines and manage priorities.
  • Good communications skills with the ability to work / liaise effectively with business, IT stakeholders, and vendor representatives.
  • Relevant experience in utility sector is preferred.
  • Ability to apply discretion when dealing with confidential information.

At Hydro One we understand that the success and strength of our business rests with our people. When we develop their skills, we are investing in both their success and ours.

To secure the best talent, we seek to create a workforce that reflects the diverse populations of the communities where we live and work and to create a culture based on safety, innovation and inclusiveness.

We are honoured to be recognized by Forbes in its list of Canada’s Best Employers for 2024.

Thank you for considering a career with Hydro One, we welcome applications from all qualified candidates. If you are having difficulty using our online application system and you need an accommodation due to a disability, please email careers@hydroone.

com. Hydro One will provide reasonable accommodation for qualified individuals with disabilities in the job application process.

Please note this email is only for accommodation requests. Resumes sent to this email address will not be considered.

Deadline : May 29, 2024

In the event you are experiencing difficulties applying to this job please consult our help page here .

Explore more InfoSec / Cybersecurity career opportunities

Find even more open roles in Ethical Hacking, Pen Testing, Security Engineering, Threat Research, Vulnerability Management, Cryptography, Digital Forensics and Cyber Security in general - ordered by popularity of job title or skills, toolset and products used - below.

J-18808-Ljbffr

2 days ago
Related jobs
Promoted
Infogain
Montreal, Quebec

Work closely with the different IT security teams to get endpoint secured based on the different security regulations and compliance’s. Work closely with the different business departments and IT teams to gather their requirements on a business level. As a System Administrator – Endpoints Security E...

Promoted
Infogain
Montreal, Quebec

Work closely with the different IT security teams to get endpoint secured based on the different security regulations and compliance’s. Work closely with the different business departments and IT teams to gather their requirements on a business level. Develop and enforce security policies related to...

CB Canada
Montreal, Quebec

As a part of its agreements with its various clients, Procom is currently seeking a Sr. Project Manager - IT Security for a company in the construction sector. Key responsibilities for this position include:. Divide the project into manageable tasks and establish an effective organizational structur...

Promoted
Arista Networks
Canada

BS Computer Science/Electrical Engineering/Computer Engineering + 8 years experience, or MS Computer Science/Electrical Engineering/Computer Engineering + 6 years experience, or Ph. Arista Networks is an industry leader in data-driven, client-to-cloud networking for large data center, campus and rou...

Promoted
LanceSoft, Inc.
Montreal, Quebec

Development of the detailed project plan and tracking the progress. Identify and assist in resolution of risks and issues that will adversely affect planned project milestones. ...

Promoted
Akkodis
Canada

Security Analyst for a contract position with a client in Toronto, ON (Hybrid). Title: Product Owner - 5/IT Security Analyst. IT Security with focus on application security and/or DevOps. API Security, 3+ years experience with CI/CD Pipeline tools and processes like BitBucket/GitHub, Jfrog Artifacto...

Promoted
iVedha Inc.
Canada

You will work closely with cross-functional teams, including developers, security professionals, and system administrators. Define and enforce security policies related to machine identities using automation and workflows. Work closely with security teams to discover and manage machine identities. U...

Promoted
Myticas Consulting
Montreal, Quebec

The Network Solution Engineer is a highly skilled internetworking professional with comprehensive IP knowledge who performs end-to-end services for clients using a consultative approach. This professional, architects, designs, integrates, tests, troubleshoots IP networks to successfully deliver IP n...

Promoted
Open Systems Technologies
Montreal, Quebec

Job Title: Cyber Security Specialist. Experience with the CRI Cyber Profile, FFICE Cyber Assessment Tool, CSA CCM, etc. Conduct risk assessment using CRI Cyber Profile. Build strong positive relationships with the Information Security / Risk community, Internal Audit, Operational Risk Department, an...

Promoted
Recochem Inc.
Greater Montreal Metropolitan Area, Canada

Maintain essential IT infrastructure, including operating systems, security tools, applications, servers, email systems, laptops, desktops, software, and hardware daily requests/incident. Maintain and configure computer systems, network servers, server roles, and virtualization for reliable operatio...