Reference Code: CO57226894-01
business, risk management, or a related field from a university of recognized standing, plus six years of progressively
responsible related experience in security risk management, cybersecurity governance, third-party risk management, audit
support, or related functions, including three years of supervisory or team leadership experience;
OR
- Two-year diploma in a relevant discipline such as cybersecurity, information systems, computer science, engineering,
business, risk management, or a related field from a institution of recognized standing, plus eight years of progressively
responsible related experience in security risk management, cybersecurity governance, third-party risk management, audit
support, or related functions, including three years of supervisory or team leadership experience.
- Membership as a Professional Engineer with EGM would be considered an asset where engineering experience is directly
relevant to the position.
- Certified or be willing to obtain certification as a Certified in Risk and Information Systems Control (CRISC), Certified
Information Systems Security Professional (CISSP), Certified Information Systems Auditor (CISA), Certified Information
Security Manager (CISM), or equivalent.
- Ability to plan, manage, evaluate, and supervise programs and personnel.
- Ability to effectively lead teams in multiple projects.
- Demonstrated ability to identify, assess, document, communicate, and monitor cybersecurity and security-related risks,
including the development of appropriate risk mitigation, acceptance, escalation, and reporting strategies.
- Effective communication skills, with a demonstrated ability to articulate complex technical concepts to non-technical
audiences, fostering understanding and collaboration between technical and business stakeholders.
- Knowledge of cybersecurity principles and practices, including risk management, security controls, security investigations,
incident response processes, and post-loss assessment activities.
- Experience with cybersecurity frameworks, standards, and regulatory requirements such as the NIST Cybersecurity
Framework, CIS Critical Security Controls, and NERC CIP where applicable.
- Experience supporting risk acceptance, exception management, risk registers, remediation tracking, evidence management,
and follow-up with accountable owners.
- Experience supporting third-party security risk management activities, including vendor risk reviews, security requirements in
contracts, penetration testing coordination, issue tracking, and escalation of material vendor risks.
- Experience coordinating internal and external audit support activities, including control testing, evidence collection, audit
response, management action plans, and remediation tracking.
- Ability to develop and maintain meaningful security risk reporting for leadership and stakeholders, including trends, open
issues, remediation status, exceptions, third-party risks, and key performance indicators.
- Knowledge of methodologies and best practices in conducting risk assessments, implementing risk mitigation strategies, and
monitoring risk management effectiveness.
- Ability to effectively work with other cybersecurity teams, such as Threat and Vulnerability, to help prioritize systems that need
remediation or containment.
- Possess a valid Province of Manitoba Driver's Licence.
- Must obtain and maintain a current Personnel Risk Assessment and a "Clear" security rating in accordance with Manitoba
Hydro policy P513.
- Must complete Manitoba Hydro Standards of Conduct training.
- NERC Critical Infrastructure Protection (CIP) Training is required and must be completed prior to transfer date and renewed
annually.
Salary Range
Starting salary will be commensurate with qualifications and experience. The range for the classification is $52.88-$72.45 Hourly,
$101,332.40-$138,828.30 Annually.
Apply Now!
Ready to join a team that energizes Manitoba and puts safety, innovation, and inclusion at the heart of everything we do? Visit
www.hydro.mb.ca/careers to learn more about this position and to apply online.
Application deadline: AUGUST 25, 2026.
We appreciate your interest in Manitoba Hydro and thank all applicants. Only those selected for the next stage of the selection
process will be contacted.
If you require accommodations during the recruitment process or need this posting in an accessible format, please let us
know - we're committed to a barrier-free experience for all candidates.
#IND1