Description :
Major Responsibilities :
o Provide security requirements to projects and operational areas,
based on Security Standards and best practice.
o Identify security design gaps in existing and proposed
architectures and recommend changes or enhancements in the
form of threat / risk assessments.
o Align standards, frameworks and security with overall business
and technology strategy.
o Participate in identifying and collaborating with other project
staff and Technology and Security experts on identifying suitable
solutions
o Consult with Enterprise Architecture and Data Architecture on
roadmaps, strategies and visions
o Collaborate and share information, tools, priorities and processes
o Develop Technology Roadmaps based on current / future state
reference architecture vision and roadmaps
o Define standards, patterns and best practices to promote
predictable and consistent designs
o Create standardized forms or reusable artifacts
o Facilitate, contribute and / or minute regular meetings with other
project staff
o Utilize SaskPower’s information management systems, software,
etc. to ensure vital contract and technical documents are
maintained.
o Maintain knowledge of industry developments and best practices
related to area of specialization and adapt them to SaskPower’s
operational environment
Deliverables / Quality of Service :
- Security threat-risk assessments of current state and proposed solutions
- Security Standards and re-usable security requirements
- Security roadmaps and artifacts.
- Critical Infrastructure reliability architecture specific to electrical utilities connected to Bulk Electric System (BES)
- TRA reports on future recommendations (including budgetary information)
- Contribution to concept, methodology, component definition, improvement
- Contribution to industry directions and best practices
- Contribution to documenting the current cyber security landscape and developing strategy (1-5 years)
Desired Education / Certifications
Computer Engineering / Computer Science degree or equivalent
CISSP, SCCP, GIAC or similar security training.
TOGAF certification is an asset
Desired Experience :
Experience in implementing Cloud Solutions (Azure / O365) would be an asset, as would experience in a utility or other critical Infrastructure.