- Pay Rate: $84.87/hour, depending on experience
- Contract Length: 2 Months
- Location: Calgary, Alberta
Raise is currently hiring
Two (2) Governance, Risk, and Compliance Analysts on behalf of our client. They’re expanding their team to meet growing needs, making this a unique opportunity to work with an industry leader. Our Client, is a major Canadian airline.
Note: The primary pay rate is based on T4 classification; however, we will also consider applications from candidates interested in an INC classification, where applicable.
Description
The Governance, Risk, and Compliance Analysts in this role will support our clients team in creating a comprehensive package of evidence for the federal government. This package will demonstrate compliance with the Critical Cyber Systems Protection Act (CCSPA) (formerly Bill C-8). Additionally, this role will play a vital part in performing deep analysis of our Operational Technology (OT) security environment to identify risks, evaluate controls, and fortify our critical infrastructure.
Responsibilities
- OT Environment Analysis: Conduct in-depth analysis of OT environments supporting airline operations, including maintenance and operational support systems.
- Asset & Risk Discovery: Identify and document OT assets, data flows, system dependencies, and associated cyber risks.
- Control Evaluation: Evaluate the effectiveness of existing security controls against industry frameworks and regulatory requirements.
- Stakeholder Engagement: Facilitate risk workshops and interviews with key business, operational, and technology stakeholders.
- Assessments & Reporting: Develop risk assessments, gap analyses, and actionable remediation recommendations.
- Governance Support: Support the creation of OT security governance standards, policies, and procedures.
- Executive Communication: Produce executive-ready reports summarizing findings, risks, and recommended actions to leadership and stakeholders.
Qualifications
- 5+ years of professional experience specializing in cybersecurity risk assessment, Governance, Risk, and Compliance (GRC), or audit engagement
- Demonstrated hands-on background working within Operational Technology (OT), Industrial Control Systems (ICS), or critical infrastructure sectors (aviation, transportation, energy, or telecommunications preferred).
- Proven working knowledge and practical application of major cybersecurity frameworks such as NIST CSF, CIS Controls, or ISO 27001.
- Familiarity with federal cybersecurity mandates, compliance frameworks, or security legislation (such as Canada's CCSPA / Bill C-8 principles) to help build defensible evidence packages for regulators
- Demonstrated history of identifying, documenting, and mapping complex OT assets, data flows, system dependencies, and network architectures - specifically within environments supporting mission-critical operations or maintenance systems.
- Risk Assessments & Gap Analysis Execution - Track record of conducting formal security control evaluations, vulnerability assessments, and comprehensive gap analyses. Remediation Planning: Ability to translate technical findings into actionable remediation recommendations and risk mitigation strategies aligned with industry standards
- Strong cross-functional facilitation skills demonstrated through leading risk workshops and technical interviews with diverse stakeholders, ranging from business operators and hangar technicians to IT/OT engineers.
- Experience producing polished, executive-level reports, summaries, and documentation that translate dense technical risks into clear language for leadership.
- Background in drafting or contributing to OT security governance standards, internal policies, and standard operating procedures (SOPs).
- Education and Certifications
- bachelor’s degree in Computer Science, Cybersecurity, Information Technology, Information Systems, Engineering (Electrical/Computer/Software), or a related discipline
- Nice to have Certifications GICSP (GIAC Global Industrial Cyber Security Professional), ISA/IEC 62443 Cybersecurity Specialist / Expert, CSSA (Certified SCADA Security Architect), CISA (Certified Information Systems Auditor), CISA (Certified Information Systems Auditor), CISM (Certified Information Security Manager) or CISSP (Certified Information Systems Professional
Additional Requirement
- Our client asks that candidates provide 2 Endorsements/References at the time of application: ( this could be a colleague/manager that worked with you on Recent Projects that relate to this role Ask them to provide a Quick Endorsement - testimonial in point form of your accomplishment / value added) to highlight your skills for this role
Looking for meaningful work? We can help!
Raise is an established hiring firm with over 65 years of experience. We believe strongly in making the world a better place through work, which is why we’re a certified B Corporation and donate 10% of our profits to charity.
We strive to build teams that reflect the diversity of the communities we work in. We encourage all qualified applicants to apply, including people from traditionally underrepresented groups such as women, visible minorities, Indigenous peoples, people identifying as LGBTQ2SI, veterans, and people with visible/nonvisible disabilities.
We have a dedicated webpage for accommodations where you can learn more about what we offer and request accommodation: https://raise.jobs/accommodations/
In order to submit candidates for roles, our clients will sometimes require personal information to confirm the identity of applicants and their legal status to work. Raise will never ask you for personal or banking information unless you have been selected for a job. If you are ever unsure about the legitimacy of this or any other Raise job posting (or have any other questions), please contact us at +1 800-567-9675 or hello@raiserecruiting.com.
#WES