Job Overview
We are seeking an experienced Cybersecurity Professional to ensure that regulated entities are fully aligned with cybersecurity standards and best practices. This role involves reviewing cybersecurity incidents, ensuring compliance with NERC and provincial reliability standards, and advising on cybersecurity frameworks such as NIST SSDF and OWASP. This position requires a proactive approach to identify vulnerabilities and provide actionable recommendations to enhance the security posture of critical infrastructure.
Key Responsibilities:
•Cybersecurity Incident Review & Compliance: Review all reported cybersecurity incidents and ensure regulated entities are compliant with industry standards and best practices.
•Critical Infrastructure Protection: Oversee the implementation of security practices for cyber assets, personnel, and training, as well as physical and electronic security perimeters.
•Standards & Framework Implementation: Ensure compliance with industry standards, including NERC and Provincial Approved Reliability Standards, and implement proven cybersecurity frameworks such as NIST SSDF, OWASP SAMM, and BSIMM.
•Remediation Recommendations: Identify security vulnerabilities, develop practical recommendations for remediation, and communicate these to both technical and business stakeholders.
•Stakeholder Management: Manage communications with internal teams and external clients, providing status updates, presentations, and reports on cybersecurity initiatives.
•Social Engineering & Phishing: Lead social engineering activities, including phishing campaigns (emails, websites), reconnaissance, and development of malicious payloads to assess vulnerabilities.
•Threat Landscape Awareness: Stay updated on current cybersecurity threats, control environments, and emerging issues to apply modern security controls.
•Security Best Practices Implementation: Create, implement, and continuously improve security best practices in line with industry standards and emerging cybersecurity trends.
Requirements:
Experience:
•10+ years of experience in IT/OT, with at least 5+ years of relevant work in application and/or system cybersecurity or Critical Infrastructure Protection.
•Hands-on experience in cybersecurity operations, security assessments, incident response, and risk management.
•Proven experience in stakeholder management, with the ability to communicate complex security issues to technical and non-technical stakeholders.
Skills & Knowledge:
•Strong understanding of NERC, Provincial Approved Reliability Standards, and industry cybersecurity frameworks (NIST SSDF, OWASP SAMM, BSIMM).
•Expertise in social engineering and phishing techniques, including campaign design, reconnaissance, and security testing.
•In-depth knowledge of cybersecurity threat landscape, risk mitigation strategies, and best practices for securing critical infrastructure.
•Ability to implement security controls for both physical and cyber environments, and manage incident reporting and response protocols.
•Proficiency in analyzing and remediating cybersecurity issues, providing actionable recommendations to improve security posture.
Education & Certifications:
•Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, or a related discipline (e.g., Business Administration or Information Systems Management).
•Relevant security certifications (e.g., CISA, CISSP, CISM, CIRSC, CEH) are considered an asset.
Job Type: Full-time
Application question(s):
•What is your expected hourly rate or annual salary for this role?
Education:
•Bachelor's Degree (preferred)
Experience:
•System cybersecurity: 6 years (preferred)
•Critical Infrastructure Protection: 7 years (preferred)
•Cybersecurity operations: 6 years (preferred)
•Stakeholder management: 6 years (preferred)
•Industry cybersecurity frameworks: 6 years (preferred)
•Social engineering and Phishing techniques: 5 years (preferred)
•Security assessments: 6 years (preferred)
Licence/Certification:
•Security certifications e.g., CISA, CISSP, CISM, CIRSC, CEH (preferred)
Location:
•Vancouver, BC (required)
Work Location: In person