Cenovus Energy

Contract CyberSecurity GRC Analyst

Contract CyberSecurity GRC Analyst
Notice info
LocationCalgary, AB
Job Typecontract, full time
On-site
Oil and Gas

About This Job

We’re a Canadian-based integrated energy company headquartered in Calgary. We’re committed to maximizing value by developing our assets in a safe, responsible and cost-efficient manner, integrating sustainability considerations into our business plans.

We operate in Canada, the United States and the Asia Pacific region. Our operations include oil sands projects in northern Alberta, thermal and conventional crude oil and natural gas projects across Western Canada, crude oil production offshore Newfoundland and Labrador and natural gas and liquids production offshore China and Indonesia. Cenovus’s downstream operations include upgrading, refining and marketing operations in Canada and the United States.

Our shares trade under the symbol CVE and are listed on the Toronto and New York stock exchanges.


Cenovus is seeking a Cybersecurity Governance, Risk, and Compliance (GRC) Analyst to support core administrative security and system hygiene activities within the System Controls and Monitoring Team. This role is primarily focused on the execution and maintenance of foundational cyber controls, including recurring access reviews, system and account monitoring, control evidence collection, and validation of compliance with established standards and policies.

The position involves routine, detail-oriented, and audit-like work essential to maintaining a secure and well-governed IT environment. Success in this role depends on consistency, accuracy, and the ability to follow defined procedures across large enterprise systems. The work is structured, process-driven, and operational in nature rather than investigative or threat-hunting focused.

The successful candidate will work closely with IT service owners, identity and access management teams, and compliance stakeholders to ensure controls are executed as designed and deficiencies are identified, tracked, and remediated. This role is well suited to individuals who take satisfaction in keeping systems clean, compliant, and predictable, and who are comfortable performing repetitive control activities that underpin enterprise cybersecurity assurance.

Key Responsibilities:

- Execute recurring access reviews (including SOX, privileged, and standard user access) in accordance with documented procedures, ensuring continued alignment with approved access models, security policies, and regulatory requirements.

- Perform ongoing monitoring and maintenance of directory and domain hygiene, including user account lifecycle activities, group membership validation, and identification of stale, orphaned, or non-compliant accounts.

- Administer established cybersecurity governance and compliance processes, ensuring controls are performed consistently, evidence is complete, and deviations from policy are identified and escalated.

- Conduct routine control-based risk assessments focused on identifying control gaps, misconfigurations, or process breakdowns rather than theoretical threat modeling.

- Monitor, validate, and evidence the operation of technical and administrative security controls, ensuring controls are functioning as designed and producing auditable results.

- Work with IT service owners and business stakeholders to resolve access discrepancies, hygiene issues, and control deficiencies, particularly those arising from operational processes or third-party dependencies.

- Maintain detailed documentation, logs, and reports for governance, risk, and compliance activities to support audits, management review, and regulatory scrutiny.

- Participate in internal and external audits by preparing evidence, responding to auditor inquiries, and supporting remediation of identified findings.


- Working knowledge of identity and access management, account monitoring, and domain hygiene within large enterprise environments.

- Practical familiarity with control frameworks and compliance standards (e.g., NIST, ISO 27001, COBIT, SOX), with emphasis on control execution rather than framework design.

- Solid hands-on understanding of enterprise IT environments, including directories, infrastructure platforms, and business applications.

- Exposure to cloud platforms (e.g., Azure, AWS) from a governance, access control, or compliance perspective.

- Bachelor’s degree in Information Technology, Cybersecurity, or a related discipline, or equivalent practical experience in IT controls, audit, or compliance functions.

- Strong process discipline, with the ability to follow documented procedures, maintain accurate records, and produce repeatable, auditable outcomes.

- Clear and professional written and verbal communication skills, particularly for documenting findings, explaining access issues, and supporting audits.


Preferred Skills:

- Prior experience in oil and gas or other highly regulated industries, with exposure to formal governance, audit, or compliance expectations.

- Practical familiarity with Active Directory governance, including its role in access control, segregation of duties, and enterprise IT control environments.

- Exposure to IT audit, control testing, or risk management activities, such as evidence preparation, issue tracking, and remediation support.

Similar Jobs

company-logo

Contract CyberSecurity GRC Analyst

Cenovus Energy
Job Typecontract, full time
 
Calgary, AB
5 days ago
company-logo

Cybersecurity Senior GRC Analyst

UGI Utilities, Inc.
Job Typefull time
 
Lancaster County, PA
4 days ago
company-logo

Cybersecurity Senior GRC Analyst

UGI
 
Denver, PA
5 days ago
company-logo

Principal Cyber Security GRC Analyst

Strategic Storage Partners
Job Typefull time
 
New Orleans, LA
6 days ago
company-logo

Cyber GRC Analyst II

CLECO
Job Typefull time
 
Pineville, LA
3 months ago
company-logo

Cyber GRC Analyst II

Cleco
Job Typefull time
 
Pineville, LA
3 months ago
company-logo

Cybersecurity Analyst

Par Pacific Holdings, Inc.
Job Typefull time
 
Houston, TX
7 days ago
company-logo

CyberSecurity Analyst

NiSource
Job Typefull time
Salary
$82200 - $123200
Columbus, OH
about 1 month ago
company-logo

Cybersecurity Analyst

ProEnergy Services
 
Houston, TX
about 1 month ago
company-logo

Cybersecurity Analyst

Southern Company
Job Typefull time
 
Birmingham, AL
2 months ago
company-logo

Global Cybersecurity GRC Manager

UGI Corporation
Job Typefull time
 
Greater Philadelphia, PA
4 days ago
company-logo

Global Cybersecurity GRC Manager

UGI Corporation
Job Typefull time
 
Greater Philadelphia, PA
3 months ago
company-logo

Cyber Security Analyst

American Water
Job Typefull time
Salary
$102290 - $118100
Camden, NJ
about 1 month ago
company-logo

Cyber Security Analyst

American Water
Job Typefull time
Salary
$102290 - $118100
Camden, NJ
3 months ago
company-logo

Cybersecurity Operations Analyst I

ENMAX
Job Typefull time
 
Calgary, AB
6 days ago
company-logo

Senior Cybersecurity Analyst

Precision Drilling
Job Typefull time
 
Calgary, AB
6 days ago
company-logo

Cybersecurity Analyst I

Minnkota Power Cooperative
Job Typefull time
 
Grand Forks, ND
2 months ago
E

Senior Cybersecurity Analyst

Evrecruit.io
Job Typefull time
 
Columbus, OH
3 months ago
company-logo

Cybersecurity Analyst II

ENGIE North America Inc.
Job Typefull time
Salary
$74900 - $114770
Houston, TX
3 months ago
company-logo

Senior Cybersecurity Analyst

Precision Drilling
Job Typefull time
 
Calgary, AB
3 months ago

Trending Jobs

company-logo

Industrial Craft Electricians for 2026 Start– Kennecott Copper

Rio Tinto
Job Typefull time
 
Salt Lake City, UT
3 months ago
company-logo

Deckhand 3

Marathon Petroleum Corporation
Job Typefull time
 
Catlettsburg, KY
2 months ago
company-logo

Title Landman

Norwood Land Services, LLC
Job Typecontract
 
00
3 months ago
HE

Accounting Clerk II - Oahu

Hawaiian Electric Company, Inc.
Salary
$47840 - $47840
Honolulu, HI
3 months ago
company-logo

STOREKEEPER

Manitoba Hydro
 
Winnipeg, MB
2 months ago
PR

Executive Coordinator

Perpetua Resources
Job Typefull time
Salary
$55000 - $75000
Boise, ID
3 months ago
company-logo

Landman

Aaron Resources, LLC
Job Typefull time
 
00
3 months ago
company-logo

Armed Nuclear Security Officer

Ontario Power Generation
Job Typefull time
 
Pickering, ON
2 months ago
company-logo

First Year Apprentice Lineman

GVEC
Job Typefull time
 
Gonzales, TX
2 months ago
company-logo

Chemical Engineering Student - May and September 2026

Suncor
Job Typetemporary
 
Fort McMurray, AB
3 months ago
company-logo

Senior Engineer Nuclear Development

SRP
Job Typefull time
 
Tempe, AZ
2 months ago
company-logo

Business Line Manager

Nikkiso Clean Energy & Industrial Gases
Job Typefull time
Salary
$107614 - $158003
Seal Beach, CA
3 months ago
company-logo

Nuclear Operations Technician I or Nuclear Operations Technician II - Harris Nuclear Plant

Duke Energy Corporation
Job Typefull time
 
New Hill, NC
about 1 month ago
company-logo

Intern - High School - Des Moines, IA

Berkshire Hathaway Energy
Job Typeinternship
 
Des Moines, IA
3 months ago
company-logo

Power Line Technician - Fort St. John

BC Hydro
Job Typefull time
 
Fort St. John, BC
3 months ago
company-logo

Field Landman

RWT Land Services, LLC
Job TypeContract
Salary
$75000 - $110000
White Oak, Texas
1 day ago
company-logo

Title Landman

Perpetual Resource Partners LLC
Job Typefull time
 
Dallas, TX
2 months ago
company-logo

Welder/Fitter

Unique Metal Fabrications, Inc.
Job Typecontract
Salary
$39520 - $47840
Pittsburg, KS
3 months ago
company-logo

Executive Protection Advisor

Enbridge
Job Typefull time
 
Waltham, MA
3 months ago
company-logo

Cortez - Safety & Health Superintendent

Barrick Gold Investments
Job Typefull time
 
Crescent Valley, NV
2 months ago