11 Sep
|
The Manitoba Public Insurance
|
Winnipeg
11 Sep
The Manitoba Public Insurance
Winnipeg
As a Cybersecurity and IT Risk and Compliance Analyst you are responsible for working with the Information Security and IT Risk Management leaders to develop and maintain Cybersecurity and IT Risk and Compliance Management governance, frameworks, policies and processes.
You will work with operational teams to provide risk and compliance management advisory, coordination, facilitation and oversight services to enable IT and business leaders to effectively and efficiently manage operational risks and meet compliance requirements within the domain or business units.
Assiststhe
Businessand
Information
Technology(IT)leadersinconductingbusinessimpactanalysisandmaintainingamapofbusinessprocessestoinformationtechnology.
WorkswithITleaderstodevelopandmaintainITRisk
Taxonomies.
WorkswithITleaderstoperform
Riskand
Control
Assessments(RCAs)andresponseplanningforcybersecurityandITcontrols.
AssistsbusinessandITleadersinconducting
Change
Risk
AssessmentsformaterialchangesintheITenvironment.
WorkswithbusinessandITleaderstoconductriskscenarioanalysisandidentifyemergingcybersecurityandtechnologyrisks.
AssistsITleaderstoidentifyandactioninternalandexternalrisklossevents.
DevelopsandmaintainstheITRisk
Register.
ConductsperiodicreportingofthecybersecurityandITRisk
ProfiletobusinessandITleaders.
Provides objective and independent assessment of first Line Risk Management activities
WorkswithbusinessandITleaderstodevelopandmaintainaninventoryofexternalrequirementsandtheannualITCompliance
Plan.
WorkswithITleaderstodesignandimplementITcontrolsandconductperiodiccontrolself-assessmentsandITthird-partyserviceprovidercontrolassessments.
Logs,monitorsandreportscontrolissues,actionsandexceptions.
Performsindependentcomplianceassessments.
Developsandmaintainstheinventoryofinternalcontrols.
Coordinatesandsupportsthethird-partyauditfunction(internal/external)fortheregulatorytestcycle.
Coordinatesandpreparesmanagementresponsestoauditfindingsandrecommendations.
FacilitatesITprocessgovernance,managementandimprovement.
Developsandmaintainsthe
Risk
Managementprocessandtools,includingthird-partyriskmanagement.
Coordinatestheintegrationofriskswith
Enterprise
Risk
Management.
WorkswithITleaderstodevelopandmaintainthe
CybersecurityandITRiskand
Compliance
Managementframework,policies,standards,processes,toolsandbestpractices.
Education and Experience
University degree in Computer Science or a related discipline from a recognized university or college.
Five years of experience in Information Technology and/or Cybersecurity.ORA two-year diploma in a relevant field from an accredited institution.
Seven years of experience in Information Technology and/or Cybersecurity
In addition to:A professional certification or equivalent from a recognized education institution or company relevant to audit or risk, including: Certified in Risk and Information Systems Control (CRISC)Certified Information Security Manager (CISM)Certified Information Systems Auditor (CISA)Certified in Governance of Enterprise IT (CGEIT)Technical Knowledge & Skills: Knowledge of industry risk and compliance policies, procedures and best practices.
Ability to relate to others with all levels of technical competency.
Knowledge of IT process and control frameworks such as COBIT, NIST CSF, ISO 27002, ITIL, PMI, etc.
Health benefits
We offer a comprehensive health benefits program that includes:flexible health, dental and vision planshealth spending accounttravel health coverageother extended health benefits such as ambulance, massage and physiotherapy
Financial security
In an effort to support financial security, we offer:registered pension plangroup, dependent, and optional life insurance coveragesick leave to cover short-term disabilitylong-term disability
Wellness
We offer programs that focus on how to better achieve a balance between work and personal commitments, as well as maintain a healthy workplace culture.
This includes:vacation entitlementmaternity, parental and adoptive leavesbereavement and family responsibility leavesemployee and family assistance programmental-health programmingonsite employee gym facility (Cityplace)discounted gym membershipswellness account
Diversity and inclusion
Manitoba Public Insurance believes that diversity and inclusion strengthens us.
We consider ourselves to be a barrier-free organization where individual values, beliefs and practices are respected and appreciated for the diversity they bring to our work life.
Employee recognition
It's important to recognize our employees for their contributions.
Not only do we recognize employees as they achieve milestone years in their careers, we also have several outlets for leaders and peers to reward each other for work well done.
Career development
We want our employees to grow, which is why we offer support in keeping their skills up to date.
We offer in-house training, professional development and an educational assistance program.
Safety and health
In an effort to encourage a safe and healthy work environment, we offer various safety, health and workplace policies and programs along with technical expertise and assistance to support employee activities in safety and health.
📌 Cybersecurity & IT Risk and Compliance Analyst (Winnipeg)
🏢 The Manitoba Public Insurance
📍 Winnipeg