Business Analyst/Cyber & Audit Governance

TC Energy

$80K — $95K *
Business Services
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in Business, Information Systems, Computer Science, Project Management, or equivalent experience
  • 4+ years in business analysis, QA, project coordination, IT operations, or related roles
  • SQL proficiency for data validation
  • Strong organizational and time-management skills
  • Strong written and verbal communication skills
  • Advanced Microsoft Office skills - Excel, PowerPoint, Teams, SharePoint, Outlook, and Copilot
  • Experience maintaining requirements, action logs, and status reports

Responsibilities

  • Gather, refine, and document requirements from business stakeholders
  • Validate that delivered functionality meets business requirements
  • Support quality assurance and coordinate with the development team
  • Confirm data and outputs are correct across environments
  • Coordinate with business users for feedback and sign-off before production deployment
  • Manage the intake, triage, and tracking of vulnerability findings
  • Prepare reports on vulnerability management metrics and remediation progress

Benefits

  • Hybrid work model
  • Flexible dress code
  • Collaborative work environment
  • Opportunities to leverage AI tools in daily workflows
Full Job Description
BA/QA on a small, high-ownership team within a large enterprise environment, responsible for business analysis, requirements, and quality assurance for the TC eConnects commercial gas pipeline operations system - with an added focus on coordinating cyber vulnerability management, remediation tracking, and governance across the Commercial IS portfolio.

The role bridges business stakeholders, development, cybersecurity, and infrastructure teams - translating business needs into actionable requirements, validating that delivered solutions work as intended, and ensuring vulnerabilities, mitigation plans, and governance action items are consistently managed from initiation through completion. You'll leverage AI tools daily to accelerate research, documentation, analysis, and remediation tracking. As roles evolve within the team, you may participate in the full AI-driven development lifecycle (AIDLC) - from requirements through development and QA.

In this role, you'll support a business-critical system where complex, domain-specific rules drive real financial and regulatory outcomes. As part of a small, highly collaborative team within a large enterprise, you'll play an active role in shaping and executing the quality and vulnerability management strategy while supporting a platform that operates 24/7. You'll work at the intersection of delivery, quality, and cybersecurity compliance, partnering directly with business stakeholders and technical subject matter experts to ensure the reliability and security of a production-critical environment. As our use of AI-enabled development practices continues to evolve, you'll leverage AI tools as part of your daily workflow and have opportunities to contribute across the full application development lifecycle, extending beyond traditional business analysis and quality assurance responsibilities.

What You'll Do

  • Gather, refine, and document requirements from business stakeholders, translating operational needs into clear, actionable work items
  • Validate that delivered functionality meets business requirements and behaves correctly across the application
  • Support quality assurance across the platform, coordinating with the development team to confirm changes work as intended before release
  • Verify data and outputs across environments - confirming that changes produce correct, expected results
  • Coordinate with business users to gather feedback and ensure sign-off before production deployment
  • Work with technical SMEs to understand system behavior, identify risk areas, and ensure requirements are feasible
  • Coordinate the intake, triage, and tracking of vulnerability findings from scanning and security teams - ensuring each moves from discovery through remediation with clear ownership and timelines
  • Track remediation activities in Azure DevOps, monitor remediation timelines and SLA compliance, and manage escalations when commitments are at risk
  • Coordinate documentation of mitigation plans, compensating controls, and risk exceptions, and support triage/review meetings across Cyber Security, DAMs, Infrastructure, and Development teams
  • Support audit preparation and evidence collection, and maintain documentation supporting SOX, cybersecurity, and operational compliance requirements
  • Prepare status reports, vulnerability management metrics, remediation trend analysis, and executive dashboards for leadership and cybersecurity stakeholders
  • Leverage AI-assisted tools and SQL-based analysis to validate functionality, investigate issues, verify data, and support vulnerability remediation, documentation, and continuous improvement efforts
  • Collaborate across the full software delivery lifecycle by working directly within development, test, and staging environments, while managing requirements, defects, and remediation activities through Azure DevOps
  • Serve as a key liaison between Development, Product Owners, Project Managers, Cyber Security, Infrastructure teams, and business stakeholders, ensuring alignment on delivery, quality, compliance, remediation progress, and user acceptance
  • Support and enhance gas pipeline commercial operations by working with business processes related to contract administration, nominations, scheduling, billing, invoicing, allocations, and customer transactions
  • Coordinate and support cybersecurity vulnerability management, compliance, and audit activities, including remediation tracking, SOX controls, risk mitigation efforts, and regulatory reporting
  • TC eConnects - enterprise commercial gas pipeline operations platform (SQL Server back-end)
  • Leverage enterprise business applications, SQL Server, Azure DevOps, and AI-powered tools to analyze data, validate system functionality, support remediation efforts, and deliver actionable insights
  • Manage and track requirements, defects, vulnerabilities, and governance activities using Azure DevOps while ensuring accurate documentation, reporting, and compliance tracking
  • Utilize Microsoft 365 tools, including Excel, PowerPoint, Teams, SharePoint, Outlook, and Copilot, to collaborate with stakeholders, communicate progress, and support operational excellence


Minimum Qualifications

  • Bachelor's degree in Business, Information Systems, Computer Science, Project Management, or equivalent experience
  • 4+ years in business analysis, QA, project coordination, IT operations, or related roles


Preferred Qualifications

  • SQL proficiency for data validation
  • Strong organizational and time-management skills; experience coordinating multiple concurrent initiatives
  • Strong written and verbal communication skills, including preparing executive reports and presentations
  • Advanced Microsoft Office skills - Excel, PowerPoint, Teams, SharePoint, Outlook, and Copilot
  • Experience maintaining requirements, action logs, and status reports
  • Knowledge of software development lifecycle (SDLC) processes
  • Familiarity with Azure DevOps or similar work-management platforms
  • Understanding of cybersecurity vulnerability management concepts and exposure to remediation processes / CVE tracking
  • Experience supporting audit, compliance, or governance initiatives
  • Experience working with cross-functional technical teams


To remain competitive, support our high-performance culture and allow for more flexibility in the way we work, we offer a hybrid work model and flexible dress code for our eligible office-based workforce in Canada, the U.S. and Mexico. #LI-Hybrid

Similar Jobs

More Jobs at TC Energy

More Business Services Jobs

Find similar Business Analyst/Cyber & Audit Governance jobs: