A workplace powered by you
At BC Hydro, we’re working towards creating a cleaner and more sustainable future for all British Columbians and need
people like you to help us. A career at BC Hydro is meaningful and provides you the opportunity to be part of a talented,
inclusive, and diverse team. We offer a healthy work-life balance, competitive wages, a comprehensive benefits package,
and training opportunities to support you in your career growth. We're proud to be ranked as one of B.C.'s Top Employers
and one of Canada's Best Diversity Employers.
We invite you to join us as we build an even cleaner B.C. We welcome applications from all qualified job seekers. If you’re a
person with a disability, please let us know by emailing RecruitmentHelp@bchydro.com, as adjustments can be made to
help support you in your application process.
IT Advisor (Cybersecurity Audit and OT Risk)
Number of positions: 1 Job Location: Dunsmuir 08
Employment type: Permanent Region: Lower Mainland
Hours of work: Full-time (37.5 hrs/wk) Flexible Work Role: Hybrid
Annual salary: $ 107,000.00 - 135,300.00
What you'll do
•Perform security and compliance impact assessments for technology or corporate initiatives, including documenting
threats, identifying risks, and recommending controls.
•Maintain knowledge of current cyber threats and conduct security analyses of internal and external measures to identify
risks, weaknesses, and vulnerabilities.
•Ensure that risk assessments, vulnerability assessments and threat analyses are conducted periodically and consistently
to identify cybersecurity risk to the organization’s information.
•Provide direction and education to business areas and maintain expertise. In addition, help develop and maintain
knowledge of BC Hydro’s program’s methodologies, policies, and published practices.
•Conduct vulnerability assessment reviews and perform vulnerability scans as required.
•Lead and coordinate the 3rd party vendor risk assessment by evaluating their security posture and ensuring compliance
with security and regulatory standards through SOC 2 Type 2 or similar reports and attestation forms.
•Monitor existing risk to ensure that changes are identified and managed appropriately.
•Analyze to assess the security controls when reviewing Privacy Impact Assessments (PIAs).
•Improve regulatory compliance by consulting with appropriate regulatory SMEs when required.
•Participate as Technology security SME on projects or initiatives to improve BC Hydro’s cybersecurity posture, especially
focused on the cybersecurity risk management, etc.
•Participate or coordinate response to various internal and external cybersecurity audits when required.
What you bring
•A university degree or equivalent combination of education and experience, with a minimum of 7 years in IT/OT
technology, cybersecurity, risk management, or audit-related work.
•Experience in system, application, and network security, risk management, IT security monitoring, and knowledge of
industry standards (ISO 270001/2, NIST, COBIT5) and NERC CIP standards is preferred.
•Experience on developing, managing or supporting Cyber Security Information Technology (IT) or Operational Technology
(OT) programs (for example, patching programs, password controls or threat assessment) would be considered an asset.
•Preference given to candidates with demonstrated knowledge and understanding of Cyber Security related to both IT and
OT assets as well as a strong knowledge of Protection and Control concepts. However, transferable experience may be
considered.
•Understanding of audit requirements, including the ability to analyze compliance quality, accuracy and adequacy.
•Ability to obtain security clearance for a Security Sensitive Position, translate technical risks into actionable business
language, and negotiate effectively.
•Excellent presentation, interpersonal, and documentation skills, with the ability to communicate technical matters to non-
technical audiences.
•Work experience in various domains, including system security, application security, network security, risk management,
and IT security monitoring.
•Experience on project management and task coordination.
•Experience on internal control process improvement.
•A team player with strong time-management and organizational skills, capable of working autonomously in a dynamic
environment and adjusting quickly to multiple demands, shifting priorities, and rapid change.
What we offer
•A comprehensive benefits package
•A minimum of 15 paid vacation days
•Flexible work model, depending on your role type
•Training and development courses
For more information on the benefits we offer, visit bchydro.com/benefits.
Location: Vancouver, BC, V6B 5R3 Canada
What else you should know
•Please note this is a hybrid position with the expectations to work in our office in Vancouver, BC for a minimum of 2 days
per week.
Don't forget to update your Candidate Profile with your current resume and copies of your certifications. If applicable,
include your Trades Qualification. This will ensure we have all the necessary information to assess your application without
any delays.
Date Posted: 2025-07-15 Closing Date: 2025-07-31
For internal use 52204234