A workplace powered by you
At BC Hydro, we’re working towards creating a cleaner and more sustainable future for all British Columbians and need
people like you to help us. A career at BC Hydro is meaningful and provides you the opportunity to be part of a talented,
inclusive, and diverse team. We offer a healthy work-life balance, competitive wages, a comprehensive benefits package,
and training opportunities to support you in your career growth. We're proud to be ranked as one of B.C.'s Top Employers
and one of Canada's Best Diversity Employers.
We invite you to join us as we build an even cleaner B.C. We welcome applications from all qualified job seekers. If you’re a
person with a disability, please let us know by emailing RecruitmentHelp@bchydro.com, as adjustments can be made to
help support you in your application process.
IT Compliance Analyst (FTT)
Number of positions: 1 Job Location: Dunsmuir 08
Employment type: Temporary Region: Lower Mainland
Hours of work: Full-time (37.5 hrs/wk) Flexible Work Role: Hybrid
Annual salary: $ 70,800.00 - 76,300.00
Position Highlights
Provides support on the sustainment of BC Hydro’s cybersecurity/IT compliance with various regulatory compliance
requirements (such as North American Reliability Corporation (NERC) Critical Infrastructure Protection (CIP)).
What you'll do
- Oversees the review of compliance workflows (such as Critical Infrastructure Protection (CIP) change requests, patch
management and vulnerability assessments) in the compliance management system to ensure adherence to timelines and
established procedures. Identifies compliance issues with documentation and reviews with internal teams or external
service providers to negotiate solutions and provide recommendations for next steps. Approves or declines compliance
workflows for accuracy and completeness for next steps in the process.
- Identifies, develops and implements new or revised compliance processes/procedures (such as access management,
Transient Cyber Assets (TCA)). Solicits feedback from applicable stakeholders. Recommends process/procedural
improvements to address concerns and gaps. Develops and maintains documentation in knowledge management
repositories. Reviews and publishes knowledge articles to business-facing knowledge bases.
- Coordinates the access management review process by: preparing quarterly and annual access review reports; verifying
the business justification to maintain access for access holders with BC Hydro managers; reviewing access revocation
records from various systems; and preparing compliance documentation as required.
- Coordinates the external vendor TCA authorization process for usage and security controls of devices by: reviewing
authorization requests for quality and accuracy; approving or declining authorization requests; conducting random audits on
the security controls of TCA devices to ensure compliance with policies and procedures; following-up with external vendors
to resolve compliance issues; and rejecting devices and removing users from access groups for non-compliance with BC
Hydro’s security control and compliance requirements.
- Coordinates the collection of compliance documentation for the annual certification process or audits. Monitors progress of
completing the Reliability Standard Audit Worksheets (RSAW). Populates or reviews RSAW and related compliance
documentation and narratives for accuracy and completeness. Follows-up with internal teams and external service
providers on areas requiring clarification or action.
- Recommends minor enhancements to enterprise compliance access management systems to IT Compliance Analyst
Work Leader. Under guidance of IT Compliance Analyst Work Leader, works with IT System Developers to implement
minor enhancements. Carries out user acceptance testing to ensure minor enhancements meet functional and operational
efficiency and effectiveness requirements.
- Prepares training materials and conducts formal/informal training sessions and presentations on compliance programs,
compliance processes and procedures to internal teams, co-op students and external service providers.
- Assists management with NERC CIP incident investigations by: preparing the documentation related to incident; carrying
out root cause mapping analysis of incident under management’s direction and guidance; maintaining evidence