Cybersecurity & Compliance Senior Analyst
6 Month Contract to Hire
5 Days onsite Calgary
145-165K
About the Role
As Cybersecurity & Compliance Senior Analyst, you will be a hands-on practitioner at the center of how we protect the software the E&P industry depends on. You will partner with engineering, IT, and product teams to make our clients software genuinely more secure, carrying real accountability across a broad scope of technical and compliance work.
The E&P industry relies on our clients software to make high-stakes decisions around reservoir modeling, well planning, and production optimization. Our customers - major oil and gas operators worldwide - hold us to a high bar on security and compliance, whether they run our software in their own data centers or subscribe to it as a SaaS platform. You will be the person who keeps that bar high: evaluating controls, analyzing risks, closing gaps, supporting audits, and ensuring that security is embedded in how we build and deliver software rather than added after the fact.
What You Will Do
Cybersecurity Operations and Risk Management
- Perform ongoing risk assessments, vulnerability reviews, and security control evaluations across applications, infrastructure, and cloud environments
- Review findings from SAST, DAST, SCA, and IaC scans; assess real-world risk; and recommend actionable mitigations
- Analyze identified security issues, recommend mitigation strategies, and track remediation efforts through to closure
- Support incident response by providing compliance guidance, maintaining documentation, and contributing to post-incident review and improvement
- Track emerging threats and evolving security trends in commercial software and the energy sector, and translate them into practical recommendations
Governance, Compliance, and Audit Support
- Own day-to-day maintenance of cybersecurity policies, standards, and procedures - keeping them accurate, current, and written in a way teams can use
- Support alignment with key regulatory and industry frameworks including ISO 27001, SOC 2, and NIST CSF
- Collect and prepare evidence for external audits, certifications, and internal control reviews
- Execute control testing, document results, and drive corrective action plans to closure
- Manage governance exceptions through the Governance process
- Participate in vendor and partner security reviews
Security Awareness and Training
- Develop and deliver security awareness programs suited to a software engineering and product environment
- Serve as a practical resource for engineering, product, and business teams, offering clear guidance on secure development practices, compliance requirements, and how to reduce risk in everyday work
Collaboration, Tooling, and Process Improvement
- Work directly with engineering, IT, product, and business stakeholders to weave security and compliance requirements into projects, processes, and the software development lifecycle
- Manage security and compliance projects and assist in evaluating new security technologies
- Build and maintain metrics, dashboards, and reports that give leadership an honest view of risk posture and compliance status
- Handle customer security questionnaires and contract security reviews with accuracy and technical credibility
What You Will Bring
Required:
- Bachelor’s degree in Computer Science, Information Security, Information Technology, or a related field, or equivalent experience that demonstrates the same depth
- 5+ years in cybersecurity, GRC, IT audit, or risk management, with real accountability for outcomes
- Solid working knowledge of security controls, vulnerability management, identity and access management, and cloud security
- Experience with at least one major compliance framework - ISO 27001, SOC 2, NIST, or equivalent - including conducting assessments, gathering evidence, and seeing findings through to resolution
- Clear written and verbal communication skills, with the ability to write a policy, analyze a finding, and explain the risk to someone who is not a security professional
Preferred:
- Industry certifications such as CISSP, CISA, CISM, Security+, CCSK, or equivalent
- Hands-on experience with cloud platforms such as Azure or AWS and their native security services
- Familiarity with secure SDLC, DevSecOps, and CI/CD pipeline tools and practices
- Background in a regulated industry - energy, oil and gas, finance, healthcare, or similar environments where security obligations are genuinely high-stakes
- Experience securing commercial software, including SaaS platforms, on-premises enterprise products, or both
- Experience with continuous compliance or compliance automation platforms such as Drata, Vanta, Secureframe, Hyperproof, or equivalent is highly desirable, including configuring controls, integrations, automated evidence collection, and continuous monitoring
- Ability to automate compliance and reporting workflows using APIs, scripting, or agentic AI
- Familiarity with software supply chain security practices, including software composition analysis, SBOMs, third-party dependency risk, and CI/CD security controls
Pay: 145-165K
Vacancy: New Vacancy (New Role)
We may use artificial intelligence tools to assist with the screening, assessment, or selection of potential applicants for this position.