Security Compliance Specialist at TC Energy performing cybersecurity compliance assessments and collaborating with governance teams on risk management and control processes.
Responsibilities
Perform assessments and report on cybersecurity compliance across TC Energy
Conduct internal Cybersecurity audits
Coordinate Cybersecurity Compliance attestations
Drive automation of security controls with a focus on continuous monitoring
Partner with our Strategy and Performance team to develop key metrics and create dashboards that leverage available data sources for leadership review and decision-making
Collaborate with governance and risk teams to enhance our GRC practices by optimizing processes related to people, procedures, and technology
Review security tools to identify vulnerabilities or insecure configurations and provide guidance on remediation strategies
Interpret and translate cybersecurity standards and regulatory requirements into actionable security controls, ensuring their effective implementation within the organization’s technical and procedural frameworks
Coordinate and organize evidence for regulatory audits by collecting relevant documents, confirming compliance, and ensuring materials are ready for auditor review.
Coordinate with internal teams to support timely audit responses
Requirements
Bachelor's degree in Computer Science, Information Security, Computer Engineering or a technical diploma in a related discipline
A minimum of 6 or more (6+) years of Cybersecurity or related IT analytical experience is a requirement
Familiar with TCP/IP, WAN/LAN concepts, operating systems, and firewall security policies
Knowledge of cybersecurity frameworks such as the NIST Cybersecurity Framework (CSF) and Zero Trust security principles, with the ability to apply these frameworks to compliance assessments and control design
Ability to present ideas and results to technical and non-technical audiences in both verbal and written communications
Experience and knowledge of the Corporate Security and Business Continuity disciplines would be considered an asset
Certified Information Systems Auditor (CISA) designation or equivalent certification
Proven experience and comprehensive understanding of cyber regulatory standards, including TSA, CER and Z246.1.
Demonstrated ability creating and updating security controls for compliance requirements
Experience managing a Governance, Risk and Compliance (GRC) tool
ICS/SCADA experience
Knowledge of business intelligence tools (Power BI, Tableau) for creating dashboards for reporting
Demonstrated understanding of business processes, risk management, cybersecurity controls and related standards
Développeur.euse sécurité cloud protégeant l’infrastructure de nesto, plateforme de financement hypothécaire canadienne. Conception de contrôles cloud, automatisation DevSecOps et réponse aux incidents.
Lead SCADA and cybersecurity engineer designing compliant electric - substation systems for GE Vernova. Coordinating multidisciplinary teams, vendors, testing, estimates, and project risk for decarbonized energy infrastructure.
Join RBC's Application Security Group to develop innovative security solutions, mentor junior staff, and collaborate across teams to enhance decision - making and automate tasks.
Lead SCADA and cybersecurity engineer designing compliant substation systems for GE Vernova. Guiding project teams, vendor designs, estimates, and acceptance testing for cleaner energy infrastructure.
Senior security advisor simulating cyber threats and strengthening defenses for Desjardins, North America's largest cooperative financial group. Leading complex initiatives, methodologies and cybersecurity risk mitigation.
SA&A Lead securing Azure applications and Microsoft platforms for PLATO, Canada’s Indigenous - owned software testing company. Leading authorization, control testing, evidence collection, and risk remediation.
Senior security advisor simulating and mitigating cyberthreats for Desjardins, North America's largest cooperative financial group. Leading offensive security methodologies, tools and strategic initiatives.
Staff Product Security Engineer building customer identity and authentication services for Affirm’s buy - now - pay - later platform. Designing secure, scalable CIAM backend systems and integrations.
Senior Security Engineer securing AWS infrastructure, production systems, and AI - driven workflows. Building guardrails, vulnerability remediation, monitoring, and incident response for a rapidly scaling platform.