Cybersecurity Consultant - Policies and Standards
- Contract Length: 6 Months
- Location: Vancouver, British Columbia
Raise is currently hiring a Cybersecurity Consultant - Policies and Standards on behalf of our client. They’re expanding their team to meet growing needs, making this a unique opportunity to work with an industry leader. Our Client, is one of the largest electrical energy suppliers in Canada.
Note: The primary pay rate is based on T4 classification; however, we will also consider applications from candidates interested in an INC classification, where applicable.
Description
The Cybersecurity Consultant - Policies and Standards to join our clients Cybersecurity Governance and Performance team. In this role, you will help protect critical information infrastructure by developing, reviewing, and refining cybersecurity policies and standards for both enterprise IT and Operational Technology (OT) environments. You will work collaboratively across business groups to identify control gaps, recommend prioritized remediation actions, and act as a trusted advisor on cybersecurity governance. Your contributions will directly reduce security risks, ensure regulatory compliance, and strengthen ’s overall security posture.
Responsibilities
- Policy Development & Review: Develop, tune, and maintain comprehensive cybersecurity policies, standards, guidelines, and procedures by working closely with internal stakeholders and subject matter experts.
- Risk & Gap Analysis: Identify control gaps relative to established frameworks and policies, making data-driven recommendations on prioritized actions to tailor an appropriate set of security standards for .
- Advisory & Collaboration: Act as a trusted advisor to business groups and project managers, addressing stakeholder concerns regarding policy interpretation, implementation, and cybersecurity best practices.
- Framework Alignment: Apply deep knowledge of recognized standards (NIST CSF, 800-53r5, RMF, AI RMF, COBIT, ISO 27001/2, Cloud Security, and AI Risk) to govern enterprise IT and OT infrastructure.
- Compliance & Program Support: Support broader cybersecurity and compliance initiatives, including NERC CIP compliance, security impact assessments, and general operational support tasks.
- Incident & Risk Mitigation Support: Assist in defining security requirements, reviewing baseline configurations, and supporting incident response documentation or security operations workflows as required.
Qualifications
- A minimum of five (5) years of working experience in Information Technology.
- At least three (3) years of focused experience in cybersecurity or equivalent roles (7+ years total IT/cyber experience preferred).
- At least two (2) years of dedicated working experience in cybersecurity policy development and review.
- Technical & Domain Knowledge
- Frameworks & Standards: NIST CSF, NIST SP 800-53r5, NIST RMF, NIST AI RMF, COBIT, ISO 27001/2, BC FIPPA, and NERC CIP.
- Specialized Domains: Operational Technology (OT) security, cloud security architectures, and emerging AI risk management.
- Core Technical Concepts: Identity and Access Management (IAM), Public Key Infrastructure (PKI), vulnerability management, encryption, network architecture, and continuous monitoring.
- Soft Skills & Competencies
- Excellent written and spoken communication skills tailored for a professional utility environment, capable of translating complex technical controls into clear, digestible policies.
- Stakeholder Engagement: Exceptional interpersonal skills with the ability to build consensus, manage change, and collaborate effectively across technical and non-technical teams.
- Strong problem-solving abilities to evaluate control effectiveness, interpret audit or test results, and formulate practical governance solutions.
- Education and Certifications
- Bachelor’s degree or technical diploma in Computer Science, Information Security, or a related discipline
- Must be able to obtain and maintain a security clearance for a Security Sensitive Position classification
- Professional Certifications (Assets / Preferred)
- Certified Information Systems Security Professional (CISSP)
- Certified Information Security Manager (CISM)
- Certified Information Systems Auditor (CISA)
- Certified Cloud Security Professional (CCSP)
- Certified in Risk Information Systems Control (CRISC) or GIAC certifications (GCIH, GPEN)
Additional Information
- Every contractor must supply their own Windows 11 Laptop computer for the duration of the assignment.
- Every contractor must supply their own “Smart Phone”. This is needed to gain access to the Organizations network.