IT Cyber Security Consultant -L2
Offre en anglaisThe consultant is responsible for mitigating security risks and protecting critical infrastructure across enterprise IT and Operational Technology environments. Key duties include performing vulnerability assessments, developing cybersecurity policies, and supporting incident response and compliance initiatives.
- Hybride
- BC
- Publié 9 sept. 2026
- Postuler avant le 9 oct. 2026
- 1 poste
Ouvre un site externe
D’autres postes auxquels postuler directement
Des possibilités semblables publiées par des employeurs qui recrutent sur Jobs.ca, sans formulaire externe.
Connectability Inc.
Technical Sales Specialist
- Hybride
Coaching Association of Canada
GESTIONNAIRE, SERVICES AUX PARTENAIRES ET PROJETS
- Hybride
PGS Equipment ltd
Electrician for farm equipment
- Hybride
Résumé du poste
IT Cyber Security Consultant -L2 (6 month contract) Location: Burnaby, BC / Hybrid Staffing Placement Opportunity General Description The IT Cyber Security Consultant – Level 2 is responsible for activities that reduce and mitigate security risks, protect critical information infrastructure, and support compliance with digital technology and cybersecurity regulations and policies. The successful candidate will have a strong understanding of cybersecurity risks and technologies across enterprise IT and Operational Technology (OT) environments, with experience in cybersecurity policy development, review, and implementation. Experience And Role Accountabilities Identify potential cybersecurity risks and incidents by performing vulnerability assessments, coordinating with internal teams and stakeholders, and monitoring external events and security logs to support contingency planning. Determine remediation options and recommend solutions by analyzing security test results, assessing the impact of security risks, and validating baseline security configurations for operating systems, applications, networking tools, and telecommunications equipment. Provide support during and after critical systems experience breaches, outages, errors, or unexpected activities by preparing security operations documentation, including incident reports, and collaborating with incident response leads and subject matter experts. Assist business groups in defining and delivering security requirements, security design, security testing, and implementation support. Support the transition of new security systems and devices from project delivery to operations to strengthen cybersecurity across the organization. Provide guidance on cybersecurity-related action items within IT projects by conducting compliance impact assessments and collaborating with project managers to ensure the application of cybersecurity best practices and compliance with applicable regulations and policies. Assist with the development and maintenance of cybersecurity standards and guidelines. Develop, tune, and implement threat detection analytics. Review existing security controls, event data, and other data sources to identify opportunities for continuous improvement in security effectiveness and capabilities. Develop and review cybersecurity policies and standards in collaboration with stakeholders. Identify control gaps against applicable policies and standards and recommend prioritized actions. Act as a trusted advisor to stakeholders, addressing their concerns and supporting the implementation of cybersecurity policies and standards. Assist with other tasks required by cybersecurity and compliance programs or initiatives. Required Qualifications And Experience Minimum five (5) years of experience in Information Technology, including at least three (3) years of experience in cybersecurity or an equivalent combination of education and experience. Minimum two (2) years of experience in cybersecurity policy development and review. Bachelor’s degree or technical diploma in Computer Science, Information Security, or a related field, or an equivalent combination of education and experience. Strong understanding of cybersecurity risks and technologies across enterprise IT and OT environments. Ability to obtain a security clearance for a Security Sensitive Position classification. Excellent written and verbal communication skills in a professional environment. Technical Knowledge And Skills IT Processes Internet policy enforcement Network architecture Active Directory Log management Vulnerability scanning Penetration testing Auditing Configuration management Asset management Continuous monitoring Web content filtering Encryption and strong authentication Security Technologies Intrusion Prevention and Detection Systems (network, host, and wireless) Wireless Intrusion Prevention Systems (WIDS) Security Information and Event Management (SIEM) Virtual Private Networks (VPN) Next-Generation Firewalls (NGFW) Web Application Firewalls (WAF) Database Activity Monitoring (DAM) Public Key Infrastructure (PKI) Data Loss Prevention (DLP) Identity and Access Management (IAM) solutions Industry Standards and Frameworks ISO 27001/27002 National Institute of Standards and Technology (NIST) frameworks NIST Cybersecurity Framework (CSF) NIST SP 800-53 Revision 5 Risk Management Framework (RMF) NIST AI Risk Management Framework (AI RMF) Control Objectives for Information and Related Technologies (COBIT) British Columbia’s Freedom of Information and Protection of Privacy Act (BC FIPPA) North American Electric Reliability Corporation Critical Infrastructure Protection (NERC CIP) Additional Skills And Experience Knowledge and experience with cloud security and AI risk management. Ability to identify control gaps against policies and standards and recommend prioritized actions. Experience tailoring appropriate policies and standards to meet organizational requirements. Experience developing and reviewing cybersecurity policies and standards in close collaboration with stakeholders. Ability to provide guidance and support related to cybersecurity and compliance programs. Experience working with both enterprise IT and OT systems. Preferred Qualifications Seven (7) years of experience in Information Technology, including at least five (5) years of experience in cybersecurity or an equivalent combination of education and experience. CISSP, CISM, CISA, CCSP, or an equivalent certification. Experience working with Operational Technology (OT) environments. Experience with NERC CIP compliance. Certification in one or more of the following areas is considered an asset: Certified Information Systems Security Professional (CISSP) Certified in Risk and Information Systems Control (CRISC) Certified Information Systems Auditor (CISA) Certified Information Security Manager (CISM) GIAC Certified Incident Handler (GCIH) GIAC Certified Penetration Tester (GPEN) Note: this is an opportunity with a Microserve client
Ce que vous ferez
The consultant is responsible for mitigating security risks and protecting critical infrastructure across enterprise IT and Operational Technology environments. Key duties include performing vulnerability assessments, developing cybersecurity policies, and supporting incident response and compliance initiatives.
Exigences
Requires a minimum of five years of IT experience, including three years in cybersecurity and two years in policy development. A bachelor's degree or technical diploma in a related field is required, along with the ability to obtain security clearance.
Compétences indiquées
- Policy developmentSouhaitée
Autres compétences pertinentes
Relevées dans la description du poste. Confirmez les exigences importantes ci-dessus.
- Cybersecurity Risk Management
- Vulnerability Assessment
- Policy Development
- Incident Response
- SIEM
- Next-Generation Firewalls
- Identity and Access Management
- NIST Framework
- ISO 27001
- NERC CIP
- Cloud Security
- AI Risk Management
- Penetration Testing
- Network Architecture
- Log Management
- Compliance Auditing
Domaines d’emploi
- Security & Safety
- Technology
- Consulting
- Software
- Engineering
Renseignements supplémentaires
- Formation minimale
- Diplôme professionnel
- Expérience minimale
- 5+ ans
- Postuler avant le
- 9 oct. 2026
- Langue de l’offre
- anglais
- Heures de travail
- 40 heures par semaine
- Niveau d’expérience
- Mid-Senior level