Our Governance, Risk, Compliance and Resilience (GRCR) team is evolving to meet the needs of our growing business, and we are expanding our presence in Calgary, Alberta to support the Enterprise Security department.
We are seeking an energetic Security Compliance Specialist who is looking to build their knowledge and experience in the areas of primarily in the area Cybersecurity. You will be accountable for enabling compliance to TC Energy policies & standards, performing compliance assessments, and preparing compliance reporting.
In collaboration with other security team members, and other IS and business teams, the specialist will support the complete lifecycle of cybersecurity compliance assessments for corporate and ICS environments. Further, the specialist will identify current/emerging security risks based on the output of the assessments.
What you'll do- Perform assessments and report on cybersecurity compliance across TC Energy
- Conduct internal Cybersecurity audits
- Coordinate Cybersecurity Compliance attestations
- Drive automation of security controls with a focus on continuous monitoring
- Partner with our Strategy and Performance team to develop key metrics and create dashboards that leverage available data sources for leadership review and decision-making
- Collaborate with governance and risk teams to enhance our GRC practices by optimizing processes related to people, procedures, and technology
- Review security tools to identify vulnerabilities or insecure configurations and provide guidance on remediation strategies
- Interpret and translate cybersecurity standards and regulatory requirements into actionable security controls, ensuring their effective implementation within the organization's technical and procedural frameworks
- Coordinate and organize evidence for regulatory audits by collecting relevant documents, confirming compliance, and ensuring materials are ready for auditor review. Coordinate with internal teams to support timely audit responses
Minimum Qualifications- Bachelor's degree in Computer Science, Information Security, Computer Engineering or a technical diploma in a related discipline
- A minimum of 6 or more (6+) years of Cybersecurity or related IT analytical experience is a requirement
Preferred Qualifications- Familiar with TCP/IP, WAN/LAN concepts, operating systems, and firewall security policies
- Knowledge of cybersecurity frameworks such as the NIST Cybersecurity Framework (CSF) and Zero Trust security principles, with the ability to apply these frameworks to compliance assessments and control design
- Ability to present ideas and results to technical and non-technical audiences in both verbal and written communications
- Experience and knowledge of the Corporate Security and Business Continuity disciplines would be considered an asset
- Certified Information Systems Auditor (CISA) designation or equivalent certification
- Proven experience and comprehensive understanding of cyber regulatory standards, including TSA, CER and Z246.1.
- Demonstrated ability creating and updating security controls for compliance requirements
- Experience managing a Governance, Risk and Compliance (GRC) tool
- ICS/SCADA experience
- Knowledge of business intelligence tools (Power BI, Tableau) for creating dashboards for reporting
- Demonstrated understanding of business processes, risk management, cybersecurity controls and related standards
To remain competitive, support our high-performance culture and allow for more flexibility in the way we work, we offer a hybrid work model and flexible dress code for our eligible office-based workforce in Canada, the U.S. and Mexico.
#LI-Hybrid Thank you for considering TC Energy in your career journey.