Security Compliance Specialist

TC Energy

$90K — $120K *
Energy & Utilities
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in Computer Science, Information Security, or a related discipline
  • 6+ years of cybersecurity or related IT analytical experience
  • Familiarity with TCP/IP, WAN/LAN, and firewall security policies
  • Knowledge of NIST Cybersecurity Framework and Zero Trust principles
  • Ability to communicate technical ideas to diverse audiences
  • Certified Information Systems Auditor (CISA) or equivalent certification preferred
  • Experience managing a Governance, Risk and Compliance (GRC) tool

Responsibilities

  • Perform cybersecurity compliance assessments across TC Energy
  • Conduct internal audits related to cybersecurity
  • Coordinate Cybersecurity Compliance attestations
  • Drive the automation of security controls for continuous monitoring
  • Develop key metrics and dashboards in collaboration with the Strategy and Performance team
  • Collaborate with governance and risk teams to enhance GRC practices
  • Identify vulnerabilities in security tools and suggest remediation strategies
  • Prepare and organize evidence for regulatory audits

Benefits

  • Hybrid work model
  • Flexible dress code for eligible employees
  • Support for a high-performance culture
  • Opportunity for professional growth within a leading organization
Full Job Description
Our Governance, Risk, Compliance and Resilience (GRCR) team is evolving to meet the needs of our growing business, and we are expanding our presence in Calgary, Alberta to support the Enterprise Security department.

We are seeking an energetic Security Compliance Specialist who is looking to build their knowledge and experience in the areas of primarily in the area Cybersecurity. You will be accountable for enabling compliance to TC Energy policies & standards, performing compliance assessments, and preparing compliance reporting.

In collaboration with other security team members, and other IS and business teams, the specialist will support the complete lifecycle of cybersecurity compliance assessments for corporate and ICS environments. Further, the specialist will identify current/emerging security risks based on the output of the assessments.

What you'll do

  • Perform assessments and report on cybersecurity compliance across TC Energy
  • Conduct internal Cybersecurity audits
  • Coordinate Cybersecurity Compliance attestations
  • Drive automation of security controls with a focus on continuous monitoring
  • Partner with our Strategy and Performance team to develop key metrics and create dashboards that leverage available data sources for leadership review and decision-making
  • Collaborate with governance and risk teams to enhance our GRC practices by optimizing processes related to people, procedures, and technology
  • Review security tools to identify vulnerabilities or insecure configurations and provide guidance on remediation strategies
  • Interpret and translate cybersecurity standards and regulatory requirements into actionable security controls, ensuring their effective implementation within the organization's technical and procedural frameworks
  • Coordinate and organize evidence for regulatory audits by collecting relevant documents, confirming compliance, and ensuring materials are ready for auditor review. Coordinate with internal teams to support timely audit responses


Minimum Qualifications

  • Bachelor's degree in Computer Science, Information Security, Computer Engineering or a technical diploma in a related discipline
  • A minimum of 6 or more (6+) years of Cybersecurity or related IT analytical experience is a requirement


Preferred Qualifications

  • Familiar with TCP/IP, WAN/LAN concepts, operating systems, and firewall security policies
  • Knowledge of cybersecurity frameworks such as the NIST Cybersecurity Framework (CSF) and Zero Trust security principles, with the ability to apply these frameworks to compliance assessments and control design
  • Ability to present ideas and results to technical and non-technical audiences in both verbal and written communications
  • Experience and knowledge of the Corporate Security and Business Continuity disciplines would be considered an asset
  • Certified Information Systems Auditor (CISA) designation or equivalent certification
  • Proven experience and comprehensive understanding of cyber regulatory standards, including TSA, CER and Z246.1.
  • Demonstrated ability creating and updating security controls for compliance requirements
  • Experience managing a Governance, Risk and Compliance (GRC) tool
  • ICS/SCADA experience
  • Knowledge of business intelligence tools (Power BI, Tableau) for creating dashboards for reporting
  • Demonstrated understanding of business processes, risk management, cybersecurity controls and related standards


To remain competitive, support our high-performance culture and allow for more flexibility in the way we work, we offer a hybrid work model and flexible dress code for our eligible office-based workforce in Canada, the U.S. and Mexico. #LI-Hybrid

Thank you for considering TC Energy in your career journey.

Similar Jobs

More Jobs at TC Energy

More Energy & Utilities Jobs

Find similar Security Compliance Specialist jobs: