RESPONSIBILITIES:
- Contribute to the development, implementation, sustainment, and continuous improvement of cyber security programs
including (but not limited) to threat intelligence, policy management, NERC CIP, Industrial Control System Cyber Security Risk
Management, incident response and disaster recovery, and application security.
- Conduct security risk assessments on applications to prevent vulnerabilities and entry points that attackers can exploit.
- Contribute to security risk identification, assessment, and mitigation strategies to resolve vulnerabilities and recommend and
support security changes to system or system components as needed.
- Participate on project teams to provide security guidance and ensure security controls and requirements are ‘baked in’ and
addressed during the project.
- Lead or assist with various cyber security awareness program initiatives including cyber security awareness training, and
simulated phishing campaigns.
- Assist with the third-party Enterprise Technology Security Assessment and manage the resulting recommendations and action
plans.
- Direct activities of external suppliers and support establishing and overseeing monitoring, selection and termination of
suppliers.
- Develop and maintain good working relationships with industry contacts for the purpose of information exchange and to keep
abreast of technology innovation and directions. Develop and maintain good working relationships with contacts within D&T,
ICS teams, and
- stakeholders throughout Manitoba Hydro including subsidiaries.
- Support the development, implementation, maintenance, and improvement of D&T’s overall NERC Critical Infrastructure
Protection (CIP) processes and procedures and Industrial Control System Cyber Security Risk Management initiatives.
of five years related IT or ICS Support experience of which at least three years must be in a system support role.
- Entry level cyber security certification(s) with organizations such as ISACA or ISC 2 would be an asset.
- General understanding of technology and how it is deployed to support the Enterprise including information technology (IT)