- Pay Rate: $54.00/hour, depending on experience
- Contract Length: 6 Months
- Location: Vancouver, British Columbia
Raise is currently hiring an IT Cyber Security Consultant on behalf of our client. They’re expanding their team to meet growing needs, making this a unique opportunity to work with an industry leader. Our Client, is one of the largest electrical energy suppliers in Canada
Note: The primary pay rate is based on T4 classification; however, we will also consider applications from candidates interested in an INC classification, where applicable.
Description
The IT Cybersecurity Consultant specializing in Cybersecurity Policy, Governance, and Risk. Reporting directly to the Cybersecurity Governance and Performance Lead, will play a critical role in developing, reviewing, and modernizing ’s cybersecurity policies and standards. This role bridges the gap between high-level governance frameworks and practical technology implementations across both Enterprise IT and Operational Technology (OT) environments. You will serve as a trusted advisor across business units, identifying security control gaps and driving action plans that protect the organizations critical infrastructure while ensuring strict regulatory compliance.
Responsibilities
- Policy & Governance Development
- Framework & Standard Development: Draft, review, and refine ’s cybersecurity policies and baseline technical standards, aligning them with established frameworks (NIST CSF / 800-53r5, ISO 27001/2, COBIT) and evolving domains like cloud security and AI risk.
- Control Gap Identification: Perform comprehensive reviews to identify policy and control gaps; recommend prioritized, tailored remediations for both IT and OT environments.
- Stakeholder Engagement: Collaborate closely with internal business units and technical leads to address concerns surrounding policy implementation, operational impact, and regulatory requirements.
- Risk Management & Regulatory Compliance
- Regulatory Compliance Support: Support compliance readiness initiatives, with a specific focus on North American Electric Reliability Corporation Critical Infrastructure Protection (NERC CIP) standards and BC FIPPA regulations.
- Compliance Impact Assessments: Conduct assessments for IT and OT projects to ensure new systems comply with internal policies, external mandates, and industry best practices.
- Continuous Modernization: Evaluate emerging technology risks—including Artificial Intelligence (AI) and cloud adoption—to integrate appropriate governance and risk management controls into ’s security posture.
- Project & Operational Alignment
- Security Requirements Guidance: Assist business units in defining security requirements, design considerations, and implementation strategies during project lifecycles.
- Operational Transition Support: Support the smooth transition of new security frameworks and tools from project phase to ongoing operations.
- Program Support: Assist with ad-hoc governance, risk assessment, and incident management support tasks as needed across the broader Cybersecurity & Compliance team.
Qualifications
- 5 years of overall experience in Information Technology with at least three (3) years focused directly on Cybersecurity (or equivalent).
- 2 years dedicated to policy development, review, and implementation.
- Preferred / Ideal Profile:
- 7 years of IT experience with five (5) years in Cybersecurity with Practical background supporting Operational Technology (OT) environments or utility-sector compliance (NERC CIP).
- Strong demonstrated background as a trusted policy advisor within a large, regulated enterprise.
- Technical Skills & Knowledge Areas
- Governance, Risk, & Compliance (GRC)
- Industry Frameworks: Deep practical knowledge of NIST CSF, NIST 800-53r5, Risk Management Framework (RMF), AI RMF, COBIT, and ISO 27001/2.
- Regulatory: Understanding of NERC CIP standards and British Columbia’s Freedom of Information and Protection of Privacy Act (BC FIPPA).
- Domain Exposure: Knowledge of cloud security controls, AI risk management, and identity/access control strategies.
- Technical & System Competencies
- IT/OT Security Concepts: Familiarity with both enterprise network architecture and industrial control systems (ICS/OT).
- Infrastructure & Security Domains: Exposure to Active Directory, log management/SIEM, vulnerability scanning, network segmentation, encryption, PKI, IAM, and Data Loss Prevention (DLP).
- Professional & Interpersonal Attributes
- Stakeholder Management: Exceptional capability to translate complex technical/regulatory requirements into clear, actionable advice for non-technical stakeholders.
- Problem-Solving: Strong analytical mindset to evaluate complex control environments and prioritize pragmatic risk remediations.
- Clear, concise, and professional written and verbal communication skills.
- Education and Certifications
- Bachelor’s degree or technical diploma in Computer Science, Information Security, or an equivalent technical field.
- Certifications (Asset): Active professional certification in good standing, such as:
- Certified Information Systems Security Professional (CISSP)
- Certified Information Security Manager (CISM)
- Certified Information Systems Auditor (CISA)
- Certified in Risk Information Systems Control (CRISC)
- Certified Cloud Security Professional (CCSP)
- GIAC (GCIH, GPEN) or equivalent.
Additional Information
- Every contractor must supply their own Windows 11 Laptop computer for the duration of the assignment.
- Every contractor must supply their own “Smart Phone”. This is needed to gain access to the Organizations network.
Looking for meaningful work? We can help!
Raise is an established hiring firm with over 65 years of experience. We believe strongly in making the world a better place through work, which is why we’re a certified B Corporation and donate 10% of our profits to charity.
We strive to build teams that reflect the diversity of the communities we work in. We encourage all qualified applicants to apply, including people from traditionally underrepresented groups such as women, visible minorities, Indigenous peoples, people identifying as LGBTQ2SI, veterans, and people with visible/nonvisible disabilities.
We have a dedicated webpage for accommodations where you can learn more about what we offer and request accommodation: https://raise.jobs/accommodations/
In order to submit candidates for roles, our clients will sometimes require personal information to confirm the identity of applicants and their legal status to work. Raise will never ask you for personal or banking information unless you have been selected for a job. If you are ever unsure about the legitimacy of this or any other Raise job posting (or have any other questions), please contact us at +1 800-567-9675 or hello@raiserecruiting.com.
#WES