Security Compliance Specialist at TC Energy performing cybersecurity compliance assessments and collaborating with governance teams on risk management and control processes.
Responsibilities
Perform assessments and report on cybersecurity compliance across TC Energy
Conduct internal Cybersecurity audits
Coordinate Cybersecurity Compliance attestations
Drive automation of security controls with a focus on continuous monitoring
Partner with our Strategy and Performance team to develop key metrics and create dashboards that leverage available data sources for leadership review and decision-making
Collaborate with governance and risk teams to enhance our GRC practices by optimizing processes related to people, procedures, and technology
Review security tools to identify vulnerabilities or insecure configurations and provide guidance on remediation strategies
Interpret and translate cybersecurity standards and regulatory requirements into actionable security controls, ensuring their effective implementation within the organization’s technical and procedural frameworks
Coordinate and organize evidence for regulatory audits by collecting relevant documents, confirming compliance, and ensuring materials are ready for auditor review.
Coordinate with internal teams to support timely audit responses
Requirements
Bachelor's degree in Computer Science, Information Security, Computer Engineering or a technical diploma in a related discipline
A minimum of 6 or more (6+) years of Cybersecurity or related IT analytical experience is a requirement
Familiar with TCP/IP, WAN/LAN concepts, operating systems, and firewall security policies
Knowledge of cybersecurity frameworks such as the NIST Cybersecurity Framework (CSF) and Zero Trust security principles, with the ability to apply these frameworks to compliance assessments and control design
Ability to present ideas and results to technical and non-technical audiences in both verbal and written communications
Experience and knowledge of the Corporate Security and Business Continuity disciplines would be considered an asset
Certified Information Systems Auditor (CISA) designation or equivalent certification
Proven experience and comprehensive understanding of cyber regulatory standards, including TSA, CER and Z246.1.
Demonstrated ability creating and updating security controls for compliance requirements
Experience managing a Governance, Risk and Compliance (GRC) tool
ICS/SCADA experience
Knowledge of business intelligence tools (Power BI, Tableau) for creating dashboards for reporting
Demonstrated understanding of business processes, risk management, cybersecurity controls and related standards
Regional Health & Safety Manager leading health, safety, and regulatory compliance for GFL’s environmental services operations in Quebec. Conducting audits, incident management, training oversight, and regional site visits.
Information Security Student supporting vulnerability management and cloud security at Nasdaq Verafin. Assisting with remediation, security posture enforcement, and cloud environment protection.
Senior Principal Security Architect shaping enterprise security architecture for Invesco, a global investment - management firm. Leading cloud, identity, network, data - protection, and risk initiatives.
Principal Security Architect securing Menlo Security’s browser and AI - agent protection platform. Leading cryptography, cloud, vulnerability, and product security architecture.
BDC banking manager overseeing commercial loan security and disbursements across Western Canada. Coordinating due diligence, risk evaluation, lending partners and compliant loan funding.
Cybersecurity new graduate rotating through Intact’s 24 - month tech development program. Supporting threat detection, incident response, infrastructure security, and AI - enhanced security insights.