Compliance Specialist assessing cybersecurity compliance for TC Energy. Collaborating with teams on security standards and regulatory requirements.
Responsibilities
Perform assessments and report on cybersecurity compliance across TC Energy
Conduct internal Cybersecurity audits
Coordinate Cybersecurity Compliance attestations
Drive automation of security controls with a focus on continuous monitoring
Partner with our Strategy and Performance team to develop key metrics and create dashboards that leverage available data sources for leadership review and decision-making
Collaborate with governance and risk teams to enhance our GRC practices by optimizing processes related to people, procedures, and technology
Review security tools to identify vulnerabilities or insecure configurations and provide guidance on remediation strategies
Interpret and translate cybersecurity standards and regulatory requirements into actionable security controls, ensuring their effective implementation within the organization’s technical and procedural frameworks
Coordinate and organize evidence for regulatory audits by collecting relevant documents, confirming compliance, and ensuring materials are ready for auditor review.
Coordinate with internal teams to support timely audit responses
Requirements
Bachelor’s degree in Computer Science, Information Security, Computer Engineering or a technical diploma in a related discipline
A minimum of 2 or more (2+) years of Cybersecurity or related IT analytical experience is a requirement
Familiar with TCP/IP, WAN/LAN concepts, operating systems, and firewall security policies
Knowledge of cybersecurity frameworks such as the NIST Cybersecurity Framework (CSF) and Zero Trust security principles, with the ability to apply these frameworks to compliance assessments and control design
Ability to present ideas and results to technical and non-technical audiences in both verbal and written communications
Certified Information Systems Auditor (CISA) designation or equivalent certification (preferred)
Proven experience and comprehensive understanding of cyber regulatory standards, including TSA, CER and Z246.1.
Demonstrated ability creating and updating security controls for compliance requirements
ICS/SCADA experience (preferred)
Knowledge of business intelligence tools (Power BI, Tableau) for creating dashboards for reporting (preferred)
Intermediate SOC Analyst monitoring and responding to security incidents for Long View, a North American IT provider. Managing SIEM tools, cloud environments, escalations, and 24x7 operations.
Azure AD Security Analyst leading identity and access management for Intact, a Canadian insurer. Integrating Azure AD, supporting IAM architecture, automation, privileged access, and major incidents.
Analyste sécurité informatique chez Beneva, compagnie d’assurance et de services financiers. Intégration des contrôles IAM, analyse des exigences de sécurité et accompagnement des équipes applicatives.
Security Analyst leading Cyber Threat Exposure Management transformation for iA Financial Group, a Canadian insurance and wealth - management provider. Coordinating risk reduction, governance, and cross - functional CTEM initiatives.
Senior Security Risk Analyst at Twilio enhancing security risk management and collaborating with cross - functional teams. Focused on identifying and mitigating cyber risks effectively and ensuring compliance.
Experienced Workday Reporting, Security & HRIS Analyst supporting HR, Payroll, IT, Finance teams with Workday solutions. Involves configuration, reporting, and collaboration with various business units.