03 Aug
|
Manitoba Liquor & Lotteries
|
Canada
03 Aug
Manitoba Liquor & Lotteries
Canada
All Manitoba Liquor & Lotteries employees may apply. Manitoba Liquor and Lotteries is committed to Diversity, Equity and Inclusion. We strive to hire a workforce that reflects the community we serve. Employment equity will be considered therefore applicants who identify as women, Indigenous people, members of racialized groups, and persons with a disability are encouraged to apply.
If you require an accommodation at any time during the recruitment process, please let us know how we can meet your needs.
Job Purpose
Reporting to the Manager, Information Security, the Senior Information Security Specialist is responsible for the systems that provide information security and protect Manitoba Liquor & Lotteries (MBLL) from cyber threats. As a senior resource within the Information Security Department, the position lead aspects of the security program, conduct, and review complex security assessments, as well as provide specialized security expertise inclusive of, but is not limited to, MBLL information technology infrastructure, cloud services, First Nation Casinos and other associated technologies, processes and personnel that are managed or operated by MBLL.
Job Responsibilities
Cyber Security Operations
- Perform assigned daily tasks from the information security runbook to ensure ongoing security and that detected issues are promptly addressed.
- Coordinate the resolution of information security work requests through assigned IT Service management (ITSM) tickets, emails, phone calls, etc.
- Lead aspects of MBLL’s information security programs as a senior Subject Matter Expert (SME), including Vulnerability Management, Security Events Information Management (SIEM), Endpoint Detection & Response (EDR), Incident Response, PKI/Cryptography, Identity & Access Management (IAM), Privileged Access Management (PAM), and cloud technologies.
- Lead small projects and initiatives within the Information Security Department to maintain technical currency or implement new cybersecurity capabilities.
- Plan, configure, and support information security technologies that protect MBLL business-critical networks and servers, including firewalls, Virtual Private Networks (VPN), secure remote access, secure authentication, and file system monitoring.
- Work closely with ITS technical teams to ensure cybersecurity controls, best practices, and mitigation strategies are effectively implemented and maintained.
- Respond to and resolve support requests (ITSM tickets, phone calls, e-mails, etc.) for the Information Security Department promptly.
- Communicate discovered vulnerabilities and provide recommendations on mitigation to appropriate staff and management.
- Design, develop, and deliver information security awareness training and education to all employees.
- Perform periodic reviews and audits of information systems to ensure security controls, policies, standards, and regulatory compliance are in place.
- Assist, train, and mentor other cybersecurity and ITS team members in the use of security tools, application of security standards, and resolution of security issues.
- Develop insightful analysis and reporting of information security metrics, such as network traffic anomalies, phishing attempts, and vulnerability exposure.
- Develop, maintain, and enforce security operations policies, standards, and processes (run books), seeking continuous improvement.
- Conduct file integrity monitoring and reporting of gaming systems and retail operations.
- Participate in an on-call rotation, providing after-hours support for urgent security issues.
- Analyze logs and events from critical information systems for suspicious or abnormal activity.
- Scan incoming emails for phishing attempts and other malicious content.
- Implement web content filtering, anti-virus, and anti-spyware technology to protect against non-business appropriate and malicious websites.
- Provide secure storage of system passwords and sensitive documents.
- Conduct network monitoring for malicious and suspicious activity.
- Perform vulnerability and risk assessments on new and existing information systems, developing reports for management review.
- Manage information security incidents following the incident response plan, including detection, identification, analysis, investigation, response, and recovery.
- Assist in the development of the information security incident response plan.
- Conduct investigations as requested by senior management or Corporate Security.
Project and Administrative Duties
- Represent the Information Security Department on business project teams as a senior technical resource and act as a risk advisor. Conduct risk analysis and advise project teams on cyber security risk and related mitigations and best practices in alignment with MBLL’s risk assessments and third-party risk management practices.
- Perform ad-hoc cyber security risk assessments on technology systems and business solutions and create reports for senior management.
- Participates in information security architecture and system design development, ensuring that all activities adhere to MBLL’s information security principles, standards, and processes.
- Develop and maintain Key Performance Indicators (KPIs) to report on important information security program health and risk indicators.
- Participate in the development of information security policies that support the security strategy and corporate business objectives.
- Provide information required for the budgeting process, monitor spending, and use technical knowledge to ensure that resources required for projects and systems maintenance are utilized efficiently and responsibly.
- Assist, train, and mentor ITS team members in the use of security tools, application of security standards, and resolution of security issues, while actively promoting and modeling good information security practices through participating and facilitating cross-training opportunities, information security campaigns and delivering presentations to strengthen a strong cyber security culture.
- Champion Corporate Responsibility (CR) by leading corporate CR strategic initiatives and ensuring corporate responsibility (consumer, environmental and community) and corporate reputation risks and opportunities are considered in business decisions and integrated into products, plans and corporate culture.
- As a Subject Matter Expert (SME), work with other MBLL staff and project teams to research, design, and implement information security solutions.
Cyber Security Incident Response
- Lead technical investigations of information security incidents by following information security incident response plans and playbooks for detection, identification, analysis, investigation, response, and recovery.
- Coordinates eradication and mitigation activities with business and IT partners for security incident recovery related to IT or business application / infrastructure security incident.
- Perform threat, vulnerability, and forensics analysis. Continuously monitor and evaluate security events, vulnerabilities, and exploits. Implement decisive actions to safeguard organizational assets against identified threats, minimizing potential business disruptions.
- Actively monitor information security technologies used by MBLL and respond to detected malicious or suspicious events.
- Contribute to and assist leading the development of incident response plans and playbooks and participate in validation activities with table-top exercises and simulations.
- Other related duties as assigned.
Primary Qualifications
- Completion of a recognized degree or a two-year college diploma in Computer Science or similar discipline, or an equivalent combination of education, certification, and experience.
- A minimum of five years of Information Technology (IT) experience with a minimum of three years experience performing information security functions.
- One or more professional information security certifications, in good standing, such as CISSP, CISM, CRISC, OSCP, SANS GIAC, etc.
- Strong communication and interpersonal skills.
- Experience and proficiency in Microsoft 365 (Word, Excel, PowerPoint, Teams and Outlook)
- Demonstrated initiative, and ability to prioritize, and achieve results in a timely manner.
- Working knowledge of general enterprise IT concepts including but not limited to operating systems, applications, databases, network technologies.
- Working knowledge of information security concepts such as Security Information Event Management (SIEM) systems, Security Orchestration & Automated Response (SOAR), Intrusion Detection and Prevention Systems (IDS/IPS), endpoint protection, Cloud security controls and M365, vulnerability management practices, Cloud Access Security Brokers (CASB), web application security scanning and monitoring, encryption technologies, patch management, Firewalls/VPNs, Identity and Access Management (IAM), Privileged Access Management (PAM).
- Have and maintain a valid Manitoba Class 5 Drivers License and access to a reliable vehicle.
- The core competencies for this position include achieving quality results, adaptability/managing change, communication, customer service, decision making and problem solving, integrity and building trust, teamwork and cooperation and valuing diversity. Leadership competencies include, building strategic performance, coaching and developing, influencing and leading.
These competencies are deemed important for the success of the position and organization.
Secondary Qualifications
- Knowledge of PCI and gaming-industry regulatory requirements and their potential impact on the organization from an information security perspective.
- Experience in scripting languages such as PowerShell or Python.
- Demonstrated record of continuing cyber security education and certifications. Committed to continuous education and recertification to maintain professional certifications and keep current with evolving cyber security technologies, trends, and threats.
- Possess an understanding of cyber security concepts, controls, frameworks, and standards including NIST and ISO.
- Ongoing professional development and recertification are required to maintain certifications and keep up to date in information technology.
***Testing may form part of the screening/selection process. Employment Equity will be a factor in the recruitment process. Circumstances may arise where the bulletin may need to be withdrawn or the number of positions may need to be increased depending on the Collective Agreement.
We thank all interested applicants, however, only those selected for interviews will be contacted.
A Great Place to Work! Enjoy fantastic benefits with our Total Rewards package
Work/Life Balance and Wellness
- Discretionary Time: Up to 10 paid discretionary leave days per year, depending on bargaining unit. Employees can carry forward discretionary leave days each year for a total of up to 50 days.
- Hybrid Work Model for Eligible Positions: Remote/Office work for eligible positions.
- Flex Time: Flexible shifts and work hours for eligible positions.
- Maternity and Parental Leave: Top-up of E.I. maternity leave benefits to 93% of employee’s basic earnings for 17 weeks.
- Fitness Allowance Reimbursement, depending on bargaining unit: Up to $250 per year that can be used to cover gym memberships, fitness equipment, and more.
- Computer Purchase /Fitness Purchase Program: Interest free loans for employees purchasing computer equipment to increase computer literacy, learning, and professional growth, or to purchase fitness equipment for personal health and wellness.
- Diversity and Inclusion: Our Diversity, Equity and Inclusion Committee is made up of employees from across the organization who are passionate about bringing diversity and inclusion to life.
- The Together Project: At Liquor & Lotteries, Caring is part of our corporate culture - we care for each other, our partners, and our community The Together Project represents the charitable efforts of the corporation and its employees working together to enrich the lives of Manitobans. Employee charitable activities are eligible for reward benefits.
Vacation
- Accrue up to 10 paid vacation days per year during the first 2 years of employment.
- Accrue 15 paid vacation days per year after 3 years of employment.
- Accrue 20 paid vacation days per year after 5 years of employment.
- Accrue 25 paid vacation days per year after 9 years of employment.
- Accrue 30 paid vacation days per year after 19 years of employment.
Retirement Savings Plan
- Defined Benefit Pension Plan: Guaranteed lifelong monthly payment at retirement provides great security for employee’s long-term strategy.
- Voluntary Group Registered Retirement Savings Plan
Health Insurance and Benefits
- Customize your Plan: Choose from a variety of options to best fit your needs. Includes coverage for prescription drugs, vision, dental, ambulance, extended health options and more for you and your eligible dependents. Health Spending Account: Depending on the option you choose, you may receive up to $1,750 towards eligible medical or dental expenses.
Flex Credit: Depending on the bargaining unit and status, you may be provided with a Flex Credit amount to purchase some or all of Group Life Insurance, Accidental Death and Disablement Insurance & Dependent Life Insurance.
World-wide Travel Health Benefits
Employee & Family Assistance Program (EFAP): Free qualified wellness support for employees and their immediate family member
Training and Development
- Educational Assistance: Tuition reimbursement for eligible employees.
- Training: Variety of courses and programs to support skill and professional development.
- Career progression: Internal job posting system that provides opportunities for a variety of career paths.
- Apprenticeship and skilled trade training: Programs offered in partnership with educational institutions such as RRC Polytech, the University of Winnipeg, and the University of Manitoba.
Discounts and Rewards
- Employee Rewards & Recognition Program: Points-based program recognizing employees for earned and nominated achievements such as long-service, going above and beyond, and community volunteer work.
- Discounts: Employees receive exclusive discounts from a variety of retailers, entertainment venues, and service providers.
📌 Senior Information Security Specialist (Canada)
🏢 Manitoba Liquor & Lotteries
📍 Canada