Cybersecurity & IT Risk and Compliance Analyst (Manitoba)

Cybersecurity & IT Risk and Compliance Analyst (Manitoba)

11 Sep
|
Manitoba Public Insurance
|
Manitoba

11 Sep

Manitoba Public Insurance

Manitoba

Overview As a Cybersecurity and IT Risk and Compliance Analyst you are responsible for working with the Information Security and IT Risk Management leaders to develop and maintain Cybersecurity and IT Risk and Compliance Management governance, frameworks, policies and processes. You will work with operational teams to provide risk and compliance management advisory, coordination, facilitation and oversight services to enable IT and business leaders to effectively and efficiently manage operational risks and meet compliance requirements within the domain or business units.
Responsibilities AssiststheBusinessandInformationTechnology(IT)leadersinconductingbusinessimpactanalysisandmaintainingamapofbusinessprocessestoinformationtechnology.
WorkswithITleaderstodevelopandmaintainITRiskTaxonomies.
WorkswithITleaderstoperformRiskandControlAssessments(RCAs)andresponseplanningforcybersecurityandITcontrols.
AssistsbusinessandITleadersinconductingChangeRiskAssessmentsformaterialchangesintheITenvironment.
WorkswithbusinessandITleaderstoconductriskscenarioanalysisandidentifyemergingcybersecurityandtechnologyrisks.
AssistsITleaderstoidentifyandactioninternalandexternalrisklossevents.
DevelopsandmaintainstheITRiskRegister.
ConductsperiodicreportingofthecybersecurityandITRiskProfiletobusinessandITleaders.
Provides objective and independent assessment of first Line Risk Management activities
WorkswithbusinessandITleaderstodevelopandmaintainaninventoryofexternalrequirementsandtheannualITCompliancePlan.
WorkswithITleaderstodesignandimplementITcontrolsandconductperiodiccontrolself-assessmentsandITthird-partyserviceprovidercontrolassessments.
Logs,monitorsandreportscontrolissues,actionsandexceptions.
Performsindependentcomplianceassessments.
Developsandmaintainstheinventoryofinternalcontrols.
Coordinatesandsupportsthethird-partyauditfunction(internal/external)fortheregulatorytestcycle.




Coordinatesandpreparesmanagementresponsestoauditfindingsandrecommendations.
FacilitatesITprocessgovernance,managementandimprovement.
DevelopsandmaintainstheRiskManagementprocessandtools,includingthird-partyriskmanagement.
CoordinatestheintegrationofriskswithEnterpriseRiskManagement.
WorkswithITleaderstodevelopandmaintaintheCybersecurityandITRiskandComplianceManagementframework,policies,standards,processes,toolsandbestpractices.
Qualifications Education and Experience
University degree in Computer Science or a related discipline from a recognized university or college.
Five years of experience in Information Technology and/or Cybersecurity.
OR
A two-year diploma in a relevant field from an accredited institution.
Seven years of experience in Information Technology and/or Cybersecurity
In addition to:
A professional certification or equivalent from a recognized education institution or company relevant to audit or risk, including: Certified in Risk and Information Systems Control (CRISC)
Certified Information Security Manager (CISM)
Certified Information Systems Auditor (CISA)
Certified in Governance of Enterprise IT (CGEIT)

Technical Knowledge & Skills:
Knowledge of industry risk and compliance policies, procedures and best practices.
Ability to relate to others with all levels of technical competency.
Knowledge of IT process and control frameworks such as COBIT, NIST CSF, ISO 27002, ITIL, PMI, etc.
Employee Benefits Health benefits
We offer a comprehensive health advantages program that includes:
flexible health, dental and vision plans




health spending account
travel health coverage
other extended health benefits such as ambulance, massage and physiotherapy
Financial security
In an effort to support financial security, we offer:
registered pension plan
group, dependent, and optional life insurance coverage
sick leave to cover short-term disability
long-term disability
Wellness
We offer programs that focus on how to better achieve a balance between work and personal commitments, as well as maintain a healthy workplace culture. This includes:
vacation entitlement
maternity, parental and adoptive leaves
bereavement and family responsibility leaves
employee and family assistance program
mental-health programming
onsite employee gym facility (Cityplace)
discounted gym memberships
wellness account
Diversity and inclusion
Manitoba Public Insurance believes that diversity and inclusion strengthens us. We consider ourselves to be a barrier-free organization where individual values, beliefs and practices are respected and appreciated for the diversity they bring to our work life.
Employee recognition
It’s important to recognize our employees for their contributions. Not only do we recognize employees as they achieve milestone years in their careers, we also have several outlets for leaders and peers to reward each other for work well done.
Professional development
We want our employees to grow, which is why we offer support in keeping their skills up to date. We offer in-house training, professional development and an educational assistance program.
Safety and health
In an effort to encourage a safe and healthy work environment, we offer various safety, health and workplace policies and programs along with technical expertise and assistance to support employee activities in safety and health.

#J-18808-Ljbffr

📌 Cybersecurity & IT Risk and Compliance Analyst (Manitoba)
🏢 Manitoba Public Insurance
📍 Manitoba

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: cybersecurity & it risk and compliance analyst (manitoba) / manitoba

Subscribe to this job alert:

Get the latest job offers by email for: cybersecurity & it risk and compliance analyst (manitoba) / manitoba