Stantec

Cyber Security Analyst

Stantec$88K — $105K *
Energy & Utilities
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in computer science, cybersecurity, information systems, or electrical engineering required.
  • CompTIA Security+, Systems Security Certified Practitioner (SSCP) or equivalent cybersecurity/OT security certification required.
  • Minimum of 8 years of relevant professional experience in cybersecurity or related technology disciplines.
  • Strong written and verbal communication skills for technical deliverables and client interactions.
  • Working knowledge of cybersecurity frameworks such as NIST CSF 2.0 and applicable water-sector regulations.

Responsibilities

  • Perform cybersecurity risk assessments and governance evaluations for water utility clients.
  • Document IT/OT/ICS installations and verify existing records and configurations.
  • Analyze and summarize assessments from network monitoring and vulnerability scanning.
  • Develop technical memoranda and client-ready reports with findings and recommendations.
  • Participate in client workshops and facilitate discussions as necessary.
  • Manage project tasks, schedules, deliverables, and coordination with stakeholders.
  • Maintain current knowledge of the cybersecurity field and pursue relevant certifications.

Benefits

  • Opportunities for continuous professional development and advancement.
  • Support for obtaining advanced professional cybersecurity certifications.
  • Collaborative team environment focused on client engagement and improvement.
  • Flexibility with partial remote work.
  • Occasional travel to client sites and industry events.
Full Job Description
Job Description

This mid-level opportunity is intended for an experienced cybersecurity, OT/ICS, SCADA, or controls professional who can contribute independently to client engagements, perform and document cybersecurity assessments, develop practical recommendations, and support implementation of cybersecurity improvements across water and wastewater environments.
Your Opportunity
You will be part of a collaborative, client-facing team that values sound technical judgment, adaptability, and continuous improvement. This role is expected to take ownership of defined workstreams, interact directly with utility stakeholders, and clearly communicate cybersecurity and OT/ICS concepts to a range of audiences-from operators and engineers to executive leadership.
Key Responsibilities
  • Perform and support cybersecurity risk assessments, program reviews, and governance-focused security evaluations for water utility clients. Independently execute defined portions of engagements and contribute technical judgment to project findings and recommendations. This may include:
  • Collection, review, and field verification of record documents, network diagrams, asset inventories, and system configurations
  • Detailed field documentation of undocumented IT/OT/ICS installations, including lifecycle, maintenance, and obsolescence considerations
  • Capture, analysis, and summary of network monitoring, vulnerability scanning, and other technical assessment results
  • Technical research and evaluation of cybersecurity technologies, architectures, standards, and control approaches
  • Develop assessment findings, remediation recommendations, technical memoranda, and client-ready reports
  • Develop, review, and harmonize cybersecurity policies, standards, procedures, incident response plans, and strategies.
  • Manage assigned tasks, budgets, schedules, deliverables, and coordination activities; contribute to overall project management as needed
  • Evaluate and incorporate findings from third-party penetration testing, vulnerability scanning, and other technical service providers into comprehensive client risk profiles and remediation plans.
  • Participate actively in client workshops, interviews, field investigations, design reviews, and presentations; facilitate defined portions of client meetings when appropriate.
  • Maintain current technical and industry knowledge and take ownership of continued professional development, including:
  • Maintenance and pursuit of relevant cybersecurity, networking, OT/ICS, and vendor certifications
  • Continued development of practical skills with network monitoring, vulnerability assessment, system scanning, analysis, and penetration-testing tools
  • Active engagement in key manufacturer, water-sector, OT/ICS cybersecurity, and industry-sponsored user groups


Qualifications

Capabilities and Credentials
  • Working knowledge of cybersecurity principles, governance, risk management, network security, and OT/ICS security practices, with the ability to apply them in client environments.
  • Strong written and verbal communication skills, including the ability to develop client-ready technical deliverables and explain technical risk and recommendations to non-technical stakeholders.
  • Ability to work independently on assigned workstreams while collaborating effectively with clients, internal engineering teams, cybersecurity specialists, and third-party partners.
  • Strong organizational and project execution skills for balancing multiple concurrent projects, priorities, and deadlines.
  • Working knowledge of cybersecurity frameworks and guidance such as NIST CSF 2.0, NIST SP 800-53, NIST SP 800-82, ISA/IEC 62443, AWWA cybersecurity guidance, and applicable water-sector regulatory requirements. Familiarity with SCADA architectures, industrial networking, virtualization, Windows Server/Active Directory, SIEM/IDS/IPS, vulnerability management, or related OT technologies is highly desirable.
Education and Experience
  • Bachelor's degree in computer science, cybersecurity, information systems, or electrical engineering required. Other 4-year undergraduate engineering degrees will be considered. Relevant graduate education and/or evidenced directly applicable experience desirable.
  • CompTIA Security+, Systems Security Certified Practitioner (SSCP) or equivalent cybersecurity/OT security certification required
  • Certified Information Security Manager (CISA) and/or Certified Information Security Systems Professional (CISSP) desirable
  • Minimum of 8 years of relevant professional experience in cybersecurity, IT/OT networking, SCADA/industrial control networks, systems engineering, or related technology disciplines, including demonstrated cybersecurity responsibilities.
  • Water/wastewater or other critical-infrastructure experience strongly preferred.
  • Must have good driving record and valid driver's license
  1. Continued advancement will be supported through progressively greater responsibility for technical leadership, client delivery, and project management. Attainment of advanced professional certifications, including CISSP, CISA, CISM or equivalent, will be required.
Additional Information
  • Reports to: Cybersecurity Practice Lead, Water Utilities
  • Location: Partially remote (strong preference for candidates near an existing office)
  • Travel: Occasional travel to client sites or industry events (up to 50%)
  • Office work: Typical office desktop workstation environment.
  • Field work: typically at sites with treatment equipment in active use and/or active construction activities. Exposure to the elements including inclement weather is probable.

This description is not a comprehensive listing of activities, duties or responsibilities that may be required of the employee. Other duties, responsibilities and activities may be assigned or may be changed at any time with or without notice.

About the Team

About Stantec

Stantec Inc. is a global engineering consulting firm headquartered in Edmonton, Alberta, Canada. The company provides professional consulting services in the areas of infrastructure, water, environment, buildings, and energy. Stantec has over 22,000 employees working in more than 400 locations across six continents. The company has a diverse client base that includes public and private sector clients. Stantec is committed to sustainability and has implemented green practices in its operations. The company has received numerous awards for its work, including the American Council of Engineering Companies' National Recognition Award for exemplary engineering achievement.
Learn more about Stantec
Size
25,000 employees
Market Cap
$5.1 billion
Industry
Founded
1954
5 Year Trend
+3.3%
NASDAQ

Similar Jobs

More Jobs at Stantec

More Energy & Utilities Jobs

Find similar Cyber Security Analyst jobs: