Powerex Corp., the wholly owned energy marketing subsidiary of BC Hydro, is responsible for marketing clean electricity across North America. Cybersecurity is fundamental to maintaining the reliability, integrity, and availability of the systems that support our business.
Our Cybersecurity team is building a dedicated Governance, Risk & Compliance (GRC) function to strengthen oversight, accountability, and risk visibility across the organization. We are looking for an experienced Cybersecurity GRC Analyst to take ownership of this function and work directly with the Director of Cybersecurity to mature our GRC practices.
This role is well-suited to a cybersecurity GRC professional who brings hands-on experience in risk management, policy, compliance, and vendor risk, and who is ready to make a tangible impact - from shaping how we track and communicate risk to driving our cybersecurity awareness and compliance programs.
\n
Why Join Powerex?
- Take ownership of a new GRC function at the heart of Powerex’s cybersecurity program, with direct influence on how cybersecurity risk is managed and communicated.
- Work closely with the Director of Cybersecurity and shape the maturity of our governance, risk, and compliance practices.
- Develop broad impact across governance, policy, risk, compliance, vendor management, and cybersecurity awareness.
- Influence how Powerex communicates its cybersecurity posture to executive leadership and the board.
- Flexible hybrid model (as little as 2 days in the office), comprehensive compensation, pension, and benefits package.
Key Responsibilities
Governance & Reporting
- Prepare quarterly cybersecurity reports for IT governance committees and the board, and coordinate the quarterly IT Cybersecurity Governance meetings - including agendas, action tracking, and follow-up.
- Maintain a clear overview of the cybersecurity program and budget, act as the liaison between the cybersecurity team and the PMO, and coordinate recurring annual cybersecurity activities such as tabletop exercises, penetration tests, and policy reviews.
Policy & Standards
- Maintain the policy register and own the end-to-end policy lifecycle - from drafting and scheduled reviews to exception management and sign-off - ensuring all policies are current, documented, and accessible in Confluence.
- Coordinate policy communication and sign-off campaigns with HR and business stakeholders, and work with the CS director and IT leaders to identify gaps and drive the creation of new policies where needed.
Risk Management
- Own the cybersecurity risk register: ensure risks are logged with clear ownership and ratings, facilitate monthly risk reviews with the team, and prepare quarterly risk summaries - including risk themes and mitigation status - for governance and board-level reporting.
- Drive the formal risk acceptance process, ensuring risks without planned mitigations are documented and approved by an accountable owner, and that the risk register remains a reliable, up-to-date source of truth.
Third-Party Risk Management (TPRM)
- Manage the vendor register and own the end-to-end TPRM lifecycle: coordinate onboarding assessments using standardized questionnaires, administer Third-Party Access Policy acknowledgements, and drive annual re-assessments and collection of security certifications.
- Maintain vendor offboarding checklists and confirm that access revocation and data handling steps are completed, ensuring Powerex’s third-party risk exposure is well-documented and continuously managed.
Compliance & Audit
- Track all audit findings in the risk register with named owners and remediation timelines, prepare compliance status updates for quarterly governance reporting, and coordinate internal self-assessments against the cybersecurity standard and NIST CSF.
- Monitor relevant external requirements - including PIPA, cybersecurity insurance expectations, and external audit requirements - to ensure the necessary controls are in place and documented.
Cybersecurity Awareness
- Design and deliver the annual cybersecurity awareness program, organize Powerex’s participation in Cybersecurity Awareness Month, and track engagement metrics for reporting to the CS director and quarterly governance meetings.
- Produce quarterly awareness summaries - covering participation rates, simulation click rates, and trends - and coordinate targeted follow-up with managers or HR for staff who repeatedly fail simulations or have not completed awareness activities.
Key Qualifications
Required
- Bachelor’s degree in Information Security, Computer Science, Engineering, or a related technical field (or equivalent practical experience).
- 3+ years of hands-on experience in cybersecurity GRC - including risk management, compliance, policy management, audit support, or vendor risk - within a cybersecurity context.
- Demonstrated experience supporting assessments, audits, control testing, compliance activities, and evidence collection, with a solid understanding of frameworks such as NIST CSF, ISO 27001, or SOC 2.
- Experience tracking risks, issues, remediation plans, and compliance evidence using tools such as Jira, Confluence, SharePoint or more specialized products
- Strong written and verbal communication skills - able to distill complex risk and compliance topics into clear, concise summaries for executive and non-technical audiences.
- Able to work independently, manage multiple workstreams, and build relationships across IT, business, and leadership teams.
Preferred
- Relevant certifications such as CISA, CISM, CRISC, CompTIA Security+, or equivalent.
- Hands-on experience with cybersecurity or GRC tooling - such as GRC platforms, SIEM (e.g., Microsoft Sentinel, Google SecOps, Splunk), risk register tools, or vulnerability management tools.
- Familiarity with Canadian privacy legislation (PIPA) or cybersecurity insurance requirements.
- Experience in regulated or business-critical environments such as energy, financial services, or utilities.
Work Arrangements & Other Requirements
- Full-time position.
- Must be located in the Vancouver/Lower Mainland area.
- Must be legally authorized to work in Canada.
- A background check and references will be required for the position.
What We Offer
- Compensation: The expected salary range for this role is $90k-$110k
- Comprehensive benefits package including extended health, dental, vision, and pension.
- Opportunity to take ownership of a new GRC function and leave a lasting mark on Powerex’s cybersecurity posture.
- A collaborative, innovation-driven IT culture that is actively embracing AI and modern cybersecurity practices.
- Professional development support, including funding for certifications and training.
About PowerexPowerex Corp. is a market leader in the trading and marketing of clean and renewable wholesale electricity and associated environmental products. We are at the forefront of the clean energy transition, helping our wholesale customers throughout Western North America meet their increasingly ambitious environmental goals. Our customers include electricity and natural gas utilities, global energy companies, large financial institutions, and global technology companies. We are an established, entrepreneurial, and consistently successful company that is a wholly owned subsidiary of BC Hydro. Powerex’s financial success directly benefits the citizens of British Columbia as Powerex’s income helps lower BC Hydro’s electricity rates.
Fast paced, dynamic, and empowering are words that describe a career with Powerex. We pride ourselves on having a supportive and fun culture, and a strong commitment to the development and wellbeing of our employees. With an average tenure of 15+ years on our trade floor, Powerex stands out as an employer of choice in Vancouver. Ask any Powerex employee what they love about their job, and their first comment will likely be “the people I work with every day.”
At Powerex we believe that a diverse team is a strong team, and our dedication to equity and inclusion is intertwined with our performance-based culture. We strive for excellence in everything we do, and we recognize that diverse perspectives and backgrounds fuel innovation and drive superior performance.
\n