411 Cybersecurity Professionals jobs in Canada
Cybersecurity Intern
Posted today
Job Viewed
Job Description
Location:
Remote (Global)
Duration:
3–6 months (Part-time/Full-time options)
Type:
Internship (Unpaid, with potential transition to paid role or full-time hire)
Company
Kspace Technologies is a forward-looking tech company operating at the intersection of
software, space technologies, and cybersecurity
. As we continue to expand globally, we are committed to building secure, resilient systems while aligning with international cybersecurity standards such as
SOC 2, ISO 27001, and NIST CSF
.
We are excited to launch our
Cybersecurity Internship Program
, giving students and early-career professionals an opportunity to gain real-world experience in governance, risk, and compliance (GRC), while contributing directly to Kspace's security readiness.
What You'll Do
As a Cybersecurity Intern, you'll:
- Draft and improve
cybersecurity policies
(Incident Response, Access Control, Data Retention, Vendor Risk, etc.). - Conduct
risk assessments
and maintain Kspace's
Risk Register
. - Perform
vulnerability scanning and penetration testing
(OWASP ZAP, OpenVAS). - Assist in setting up and monitoring
SIEM tools
(Wazuh, Snort). - Support
SOC 2 / ISO 27001 compliance mapping
and evidence collection. - Help prepare
audit documentation
and contribute to Kspace's compliance roadmap.
What You'll Gain
Hands-on experience with
global cybersecurity frameworks
(SOC 2, ISO 27001, NIST).
Training in
governance, risk, and compliance (GRC)
.
Exposure to
open-source security tools
and secure remote work practices.
Real contributions to
audit readiness and security documentation
.
Mentorship from Kspace's leadership team.
A chance to transition into
long-term opportunities
at Kspace Technologies.
Who Should Apply
We are looking for
motivated, detail-oriented individuals
who are:
- Pursuing or recently completed a degree/diploma in
Cybersecurity, Computer Science, IT, or related fields
. - Familiar with (or eager to learn)
compliance frameworks
like SOC 2, ISO 27001, and NIST. - Interested in penetration testing, risk management, and security operations.
- Strong communicators, proactive learners, and team players.
Bonus if you've worked with GitHub, cloud platforms, or open-source security tools.
How to Apply
Send your
resume + a short cover letter
to:
-
Subject:
"Cybersecurity Internship Application – (Your Name)"
Join Us
At Kspace, you won't just be "an intern." You'll be
part of a mission
to strengthen the foundations of secure technology for the future. This is your chance to
grow, learn, and make an impact
in a company preparing for global compliance certifications.
cybersecurity analyst
Posted today
Job Viewed
Job Description
Join a diverse and talented team
For years now, we've been designing lingerie and swimwear for everyday living. Why do we do what we do? Because we want women around the world to look and feel their best Join our dynamic team to start a stimulating professional career in a committed and constantly evolving environment.
We're a proudly local company with more than 4,600 employees and more than 287 stores across Canada and in 19 countries around the globe (100 stores).
Purpose of the job
Under the supervision of the Manager of IT Systems Administration, the Cyber Security Analyst is responsible for the overall management of information security risks. He/she ensures the integration of appropriate defensive measures from the beginning of the implementation of any new system. The incumbent implements preventive security and monitoring tools to reduce the risk of intrusion, whether malicious or unauthorized. He/she also ensures their maintenance and continuous improvement, in accordance with the company's standards and policies.
Key Responsibilities
- Plan and monitor the implementation of robust security measures in all aspects of physical, virtual and cloud infrastructure;
- Manage vulnerabilities by applying security patches and updates to the computer park, including cloud and physical infrastructures;
- Ensure controls over authentication, authorization and access control processes by applying the principles of least right of access (JIT, JPO);
- Ensure the optimizations of automated threat detection and prevention (EDR) systems according to company policies;
- Ensure threat management and support of intrusion detection system alerts, unusual and unauthorized activities with information and event tools (SIEM);
- Participate in the process of reviewing access and corporate policies;
- Collaborate with architecture, development, and operations teams;
- Participate in the documentation of systems, processes, configurations, operational safety and emergency procedures of the various environments.
Your profile
- Technical expertise: You are proficient in cybersecurity in physical, virtual and cloud environments, and know how to implement robust and compliant measures;
- Analytical mind: You detect vulnerabilities, manage risks and propose concrete solutions to strengthen security;
- Overview: You understand interconnected systems and contribute to a secure and sustainable IT architecture;
- Responsiveness: You act quickly in the event of an incident while remaining proactive in prevention;
Requirements
- Minimum 5 years of experience as a cybersecurity specialist or other relevant experience;
- Bachelor's degree in computer science and/or a related field or equivalent work experience;
- Spoken and written bilingualism (The person will have to speak with users outside Quebec;
- Expertise in security of cloud, hybrid networks and stores;
- Proficiency in unified monitoring tools (SIEM, XDR);
- Proficiency in vulnerability management tools;
- Excellent knowledge of intrusion tools and firewall protection;
- Excellent problem-solving skills, with the ability to analyze and address complex security issues in diverse environments;
- Ability to raise awareness of cybersecurity best practices in the various business units;
- Manage priorities and communicate the progress of security projects;
- Manage multiple technology vendors;
- CISSP and/or AZ-500 certifications (or in the process of being obtained);
- Available to offer technical support outside of business hours;
- Good stress management and ease in a fast-paced company;
- Be on the lookout for advancements and new technologies.
Permanent, Full time
TIThe information on this site is for information purposes only and is not intended to have legal consequences. La Vie en Rose is committed to employment equity. La Vie en Rose has put in place an adaptation process that provides accommodation for selected candidates for an interview.
Cybersecurity Architect
Posted today
Job Viewed
Job Description
29 Aug 2025
- Work Location- 335 King Street East, Toronto, ON
- Employee Type - Regular Employee FT Salaried
- Hybrid Work - This position currently offers a hybrid work schedule. Subject to change. The in-office requirement is a minimum of three days per week (Tuesday, Wednesday & Thursday), with the flexibility to work from home on the remaining days.
- Initial Posting Close Date - Septemeber 15, 2025
About This Opportunity
We are seeking an experienced Cybersecurity Architect to join our Cybersecurity team. The Cybersecurity Architect will lead the design and maintenance of secure architectures across Information Technology (IT), Operational Technology (OT), and cloud environments.
This is an exciting opportunity to leverage your expertise in cybersecurity frameworks, risk assessment, industrial control systems, cloud infrastructure, and identity security—grounded in 7+ years of experience in cybersecurity, including at least 3 years focused on OT/ICS security and 3+ years in cloud security—to design, implement, and oversee the organization's security infrastructure.
Responsibilities
Architecture & Strategy
- Develop and maintain enterprise-wide security architecture for IT, OT, and Cloud.
- Design secure network, cloud (AWS, Azure, GCP), and hybrid environments.
- Create security reference models, segmentation strategies, and governance frameworks.
- Implement controls for ICS, SCADA, and critical infrastructure.
Risk Management
- Conduct risk assessments, threat modeling, and compliance gap analysis.
- Assess vulnerabilities in IT, OT, and cloud systems, including third-party risks.
- Develop mitigation strategies for operational and cloud-specific risks.
Standards & Compliance
- Align security programs with NIST, ISO 27001, IEC 62443, NERC CIP, and other cloud security frameworks.
- Ensure compliance with SOC 2, FedRAMP, GDPR, and industry-specific regulations.
- Establish and enforce security policies, procedures, and baselines.
Technology & Implementation
- Deploy network and cloud security tools (CASB, CSPM, CWPP, IAM, encryption).
- Implement secure architectures for LAN, WAN, DMZ, data centers, and OT networks.
- Integrate monitoring, DevSecOps, and automated response capabilities.
Collaboration & Leadership
- Partner with IT, OT, cloud, and engineering teams to implement controls.
- Work with vendors, regulators, and leadership on security posture and best practices.
- Mentor team members and support security awareness efforts.
Incident Response & Recovery
- Develop IR playbooks and disaster recovery plans for IT, OT, and cloud.
- Support forensic investigations and root cause analysis.
- Establish backup and recovery procedures for critical systems.
Continuous Improvement
- Monitor emerging threats and industry trends.
- Conduct architecture reviews and recommend enhancements.
- Evaluate new technologies for adoption.
Qualifications
- Bachelor's degree in Computer Science, Cybersecurity, Information Technology, Engineering, or a related field.
- A minimum of one advanced certification (e.g., CISSP, ISSAP, SABSA) is required.
- Cloud security certifications such as CCSP or platform-specific credentials (AWS, Azure, GCP) are preferred.
- OT/ICS certifications such as GICSP or GRID are preferred.
- Minimum 7 years of cybersecurity experience, including 3+ years in OT/ICS security and 3+ years in cloud security.
- Strong background in cloud and network security technologies, including TCP/IP, firewalls, IDS/IPS, VPNs, and cloud-native security tools (CASB, CSPM, CWPP).
- Experience with security assessment tools, SIEM, identity management, DevSecOps practices, industrial control systems (SCADA, DCS, PLC) and OT protocols (Modbus, DNP3, EtherNet/IP).
- Familiarity with compliance frameworks (NIST, IEC 62443, NERC CIP, GDPR) and regulated industries (utilities, manufacturing, chemical).
About Us: Proudly Canadian and Independently Owned, We are Coke Canada
Coca-Cola Canada Bottling Limited is Canada's premier bottling company. We are an independently owned business encompassing over 5,800 associates, more than 50 sales and distribution centers, and 5 production facilities nationwide. For more information about Coke Canada Bottling, please visit
Important
All offers of employment at Coca-Cola Canada Bottling Limited ("Coke Canada Bottling") are conditional upon a successful background clearance obtained through our contracted third-party vendor. The standard clearance requirements depend on the position and may include some or all of the following: criminal clearance, employment verification, education verification and drivers abstract review. Please advise the Talent Acquisition team if you have any questions or concerns in regards to this once you are contacted for further consideration.
Coke Canada Bottling is committed to creating a diverse and inclusive workforce with several programs, policies and resources in place to support our people. For individuals requiring accommodations or support throughout the recruitment process please contact our Talent Acquisition Services team by calling or email
Cybersecurity Specialist
Posted 9 days ago
Job Viewed
Job Description
**Responsibilities-**
+ Secure API development - Design and develop RESTful APIs and integrations with strong authentication, authorization, and data protection measures.
+ Work with PostgreSQL and other RDBMS to query, optimize, and secure data structures against injection attacks, data leakage, and unauthorized access.
+ Contribute to system architecture with Security by Design, including threat modeling and secure design reviews at the planning stage.
+ Write scripts to automate security scans, compliance checks, and reduce manual effort in security monitoring and deployment workflows.
+ Proficiency in Python, JavaScript, Java, or Go with a focus on secure coding standards (e.g., OWASP Top 10 mitigation).
+ Implement CI/CD pipelines with integrated SAST, DAST, dependency scanning, and secrets management for secure deployments.
+ Deep application of secure coding frameworks, vulnerability prevention, and industry best practices (OWASP, SANS).
+ Strong problem-solving and debugging skills for both functional and security-related issues in dev, test, and prod environments.
+ Collaborate closely with developers, operations, and security teams to embed a culture of security across all cross-functional work.
**Primary Skills:**
+ Secure coding (OWASP Top 10, SANS CWE)
+ API security (OAuth2, JWT, input validation)
+ CI/CD security integration (SAST, DAST, dependency scanning)
+ Programming in Python, JavaScript, Java, or Go
+ PostgreSQL database security
+ Threat modeling & secure architecture reviews
+ Security automation scripting
**Good to Have:**
+ Cloud security (AWS/GCP/Azure)
+ Container security (Docker/K8s, image scanning)
+ IaC security (Terraform, Ansible)
+ Security compliance (SOC 2, ISO 27001)
Ideal Experience Range
+ 6-9 years total experience in software development and DevOps, with at least 2 - 3 years hands-on security exposure (secure coding, pipeline security, API security, threat modeling)
#LIPT1
Cognizant is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to sex, gender identity, sexual orientation, race, color, religion, national origin, disability, protected Veteran status, age, or any other characteristic protected by law.
Senior Engineer, Cybersecurity (Network Security)
Posted today
Job Viewed
Job Description
Job Description
Company Description
At NIQ, we believe in turning ideas into action, collaborating as one team, and delivering results that matter. We are looking for a Senior Cybersecurity Network Engineer who embodies these principles — someone passionate about building secure, scalable infrastructure and committed to protecting the systems that power our clients’ insights.
In this role, you will lead the design and implementation of security solutions that support NIQ’s mission to deliver trusted insights. You will work cross-functionally — and often across lines of business — to solve complex challenges, mentor others, and drive innovation with urgency and accountability. If you are client-obsessed, integrity-driven, and motivated to win as part of a high-performing team, we invite you to bring your expertise to NIQ and help advance how we secure the technologies that drive our clients’ success.
Job DescriptionLead the design and implementation of secure, scalable infrastructure solutions that align with NIQ’s security and compliance objectives.
Serve as a trusted subject matter expert, driving initiatives that strengthen NIQ’s security posture and advance our engineering maturity across diverse lines of business and technologies.
Demonstrated senior-level expertise, with a proven ability to lead the resolution of complex technical issues, provide strategic support across diverse environments, and guide teams through advanced troubleshooting and incident response scenarios.
Collaborate with cross-functional teams across multiple lines of business to deliver security solutions that enable our growth while managing risk effectively.
Champion automation, observability, and engineering best practices to improve the reliability, scalability, and efficiency of NIQ’s security infrastructure.
Mentor and uplift junior engineers, fostering a culture of curiosity, continuous learning, and pride in our collective capabilities.
Translate security requirements into actionable technical strategies, balancing security, usability, and operational efficiency.
Proactively identify and mitigate risks, lead root cause analyses, and drive long-term improvements that reflect NIQ’s commitment to quality and accountability.
Influence strategic planning and decision-making, contributing to the evolution of enterprise security architecture.
Proven track record of designing, implementing, and supporting secure infrastructure solutions in complex enterprise environments.
Expertise in Networking and Network Security Cybersecurity domains.
Hands-on experience with network analysis and security tools such as packet capture, NGFW, IDS/IPS, web proxy/SWG, routing/switching, DNS, application layer networking, transport layer security (encryption/decryption), certificate handling and wireless technologies.
A strong command of spoken and written English, to facilitate communications with our global workforce.
Strong communication and collaboration skills, with the ability to influence and engage stakeholders across technical and business teams.
Demonstrated leadership in coaching and mentoring junior engineers.
Working knowledge of the CIS framework and risk management practices.
Bachelor’s degree or College Diploma in Computer Science, Cybersecurity, or Information Systems (or equivalent practical experience).
A minimum of 5–8 years of experience in Cybersecurity and/or Information Technology (IT), demonstrating expertise in securing systems, managing risk, and supporting enterprise IT environments, is required.
Relevant industry certifications (e.g., ISC2, GIAC) are a plus.
Additional Information
NielsenIQ is a global measurement and data analytics company that provides the most complete and trusted view available of consumers and markets worldwide. We provide consumer packaged goods manufacturers/fast-moving consumer goods and retailers with accurate, actionable information and insights and a complete picture of the complex and changing marketplace that companies need to innovate and grow. Our approach marries proprietary NielsenIQ data with other data sources to help clients around the world understand what’s happening now, what’s happening next, and how to best act on this knowledge. We like to be in the middle of the action. That’s why you can find us at work in over 90 countries, covering more than 90% of the world’s population. For more information, visit
NielsenIQ is committed to hiring and retaining a diverse workforce. We are proud to be an Equal Opportunity/Affirmative Action-Employer, making decisions without regard to race, color, religion, gender, gender identity or expression, sexual orientation, national origin, genetics, disability status, age, marital status, protected veteran status or any other protected class.
Our Benefits
- Flexible working environment
- Volunteer time off
- LinkedIn Learning
- Employee-Assistance-Program (EAP)
About NIQ
NIQ is the world’s leading consumer intelligence company, delivering the most complete understanding of consumer buying behavior and revealing new pathways to growth. In 2023, NIQ combined with GfK, bringing together the two industry leaders with unparalleled global reach. With a holistic retail read and the most comprehensive consumer insights—delivered with advanced analytics through state-of-the-art platforms—NIQ delivers the Full View™. NIQ is an Advent International portfolio company with operations in 100+ markets, covering more than 90% of the world’s population.
For more information, visit NIQ.com
Want to keep up with our latest updates?
Follow us on: LinkedIn | Instagram | Twitter | Facebook
Our commitment to Diversity, Equity, and Inclusion
At NIQ, we are steadfast in our commitment to fostering an inclusive workplace that mirrors the rich diversity of the communities and markets we serve. We believe that embracing a wide range of perspectives drives innovation and excellence. All employment decisions at NIQ are made without regard to race, color, religion, sex (including pregnancy, sexual orientation, or gender identity), national origin, age, disability, genetic information, marital status, veteran status, or any other characteristic protected by applicable laws. We invite individuals who share our dedication to inclusivity and equity to join us in making a meaningful impact. To learn more about our ongoing efforts in diversity and inclusion, please visit the -center/diversity-inclusion
Cybersecurity Systems Engineering
Posted today
Job Viewed
Job Description
At General Dynamics Mission Systems–Canada, our focus extends beyond engineering technology solutions—we are dedicated to cultivating careers. If you seek a purpose-driven career solving some of the world's most critical problems, alongside some of the brightest engineering minds, your application is welcome. Join a community where your unique perspective propels innovation.
Why Join Us?
- Flexible Work Environment: We have On-site and Hybrid positions, this is often dependent on the nature of your role. We offer a variety of options for your work schedule which includes compressed work week options, flexible start times and shut down periods.
- Professional Development: We offer a number of resources and support to help develop your professional toolkit You should anticipate regular progress reviews as well as access to educational assistance, professional designations and certification support, training and more
- Total Rewards: Consider it covered—health, dental, and beyond. Early access to a pension plan with various perks to acknowledge your contributions to the organization.
Job Description
General Dynamics Mission Systems–Canada has an opportunity for a Cybersecurity Analyst to join our Sonar Systems team within the Air & Naval division. In this role you will develop security strategies, design secure systems, and implement cybersecurity solutions to ensure that General Dynamics Mission Systems–Canada (GDMS-C) systems and products are designed and developed based on sound security principles.
Responsibilities include:
- Support stakeholder engagement by identifying regulatory requirements, the Security Assessment and Accreditation (SA&A) process to be applied, and obtains concurrence from SA&A authorities on the identified information protection needs
- Evaluate, select, and establish the system security architecture and develop cybersecurity controls
- Conduct threat modeling and vulnerability assessments, applying threat intelligence to refine system defenses and enhance resilience
- Ensure cybersecurity frameworks adhere to military and industry standards such as NIST, RMF (Risk Management Framework), ITSG-33, and ISO 27001
- Establish security policies, procedures, and protocols to comply with Defense Information Systems Agency (DISA) Security Technical Implementation Guides (STIGs) and Federal Information Processing Standards (FIPS).
- Conducting Threat Risk Analysis, impact analysis, and vulnerability testing
- Supporting the implementation of software development environments by ensuring appropriate security controls have been identified and are implemented based on desired assurance level
- Ensuring the system tests verify and validate System Security Requirements and support the proof of assurance; author and run Security Test Procedures
- Support internal and external audits by authoring and maintaining reproducible security artifacts and SA&A documentation (e.g., System Security Plans, Risk Assessments, Security Artifacts in System Design Document, Security Test Reports)
Qualifications
- The successful candidate for this position will have a Bachelor's Degree in Engineering or equivalent with a minimum of 5 years of experience
- Experience supporting the engineering development of secure systems, ideally in airborne or naval military environments
- Strong understanding of container security (Docker/Podman), vulnerability scanning, and artifact management
- Familiarity with DISA STIGs, SCAP tools (OpenSCAP, oscap), and frameworks like ITSG‑33 or NIST RMF
- Experience supporting vulnerability management workflows, including CVE/CWE tracking and remediation
- Familiarity generating and maintaining SBOMs (SPDX or CycloneDX format) with CVE mapping
- Effective communicator, strong interpersonal skills, positive attitude, and ability to motivate others through collaborative leadership
- Excellent time management skills, whether working as a self-motivated individual or part of a team
- Up-to-date with cybersecurity trends, emerging threats, and advanced technologies
Assets
- Certifications such as CISSP, GICSP, GIAC DevSecOps, or Kubernetes Security Specialist
- Proficiency with GitLab CI/CD, SonarQube, Parasoft, and scripting languages (Python, Bash); proficiency with C++
It is a requirement that General Dynamics Mission Systems-Canada be registered with the Canadian Controlled Goods program and that all of its workforce be security assessed. Successful applicants must meet all applicable security requirements, including but not limited to the ability to obtain and maintain a Canadian government security clearance. Applicants may be required to meet additional security requirements in order to gain access to technical data, classified areas or information that is subject to international regulations. You must be eligible to work in Canada.
Additional Information
We believe the unique contributions of each of our colleagues are key in our ability to drive innovation. By fostering a culture of belonging, encouraging idea sharing at all levels, and reinforcing the very real impact of what we do, we offer an environment where everyone can take pride in their work. We respect diverse opinions, and value the lived experiences each and every one of us bring to our workplace. If you require accommodation during any stage of the application process, please contact Human Resources via -
Senior Associate/Cybersecurity
Posted today
Job Viewed
Job Description
About Charles River Associates
CRA is a leading global consulting firm that provides independent economic and financial analysis behind litigation matters, guides businesses through critical strategy and operational issues to become more profitable, and advises governments on the economic impact of policies and regulations. Our two main services – economic and management consulting – are delivered by practice groups that focus on specific areas of expertise or industries. Click here to learn how CRA can help you launch your career.
Position Overview
CRA's Forensic Services practice supports companies' commitment to integrity by assisting them and their counsel in independently responding to allegations of fraud, waste, abuse, misconduct, and non-compliance. We are noted for deploying cross-trained teams of forensic professionals to assist our clients in gaining deeper insights and greater value more quickly. We provide accounting and forensic services as well as cybercrime investigation services.
The opportunities to contribute to the team in this Senior Associate role may include (but are not limited to):
- Executing security and privacy investigations for CRA clients, in preparation of, and in response to, data security matters, which may include ongoing breach detection, threat analysis, incident response and malware analysis;
- Performing forensic analysis of digital information using standard computer forensics and evidence handling techniques and computer forensics tools;
- Improving the ability of the incident response team to react to incidents by evaluating and implementing new tools and processes;
- Contributing to the creation and maintenance of effective relationships with local, state and federal law enforcement agencies to assist in criminal matters;
- Preparing client communications for project milestones and senior leadership;
- Managing risk by implementing quality control measures and documentation;
- Participating in team recruiting and retention efforts and managing team morale. Manage the growth and professional development of junior staff members;
- Providing management support to engagement teams led by senior personnel;
- Supporting engagement planning and management. Participating in project team execution, analysis, and work product. Managing and supervising teams as appropriate;
- Providing technical assessment/audit and guidance to clients on the adequacy of cyber security controls in accordance with cybersecurity frameworks that are included in one or more of the following - NIST CSF 2.0, HIPAA, ISO 27001 and 27002, SOC2, NERC-CIP,
- Interfacing with client personnel;
- Assisting in business development efforts by drafting proposals and coordinating with other practice areas within the firm.
Desired Qualifications
- Bachelor's or Master's degree in a related field required;
- 5-7 years' experience in cyber intrusion investigation or incident response analysis;
- Ability to effectively prioritize multiple projects and meet timely deadlines;
- Experience in a hands-on technical role functioning as an incident responder, network forensic analyst or malware analyst;
- Experience with data analytics engagements and contributing to the execution of technology-based best practices;
- Working knowledge of computer hardware components, operating systems, file systems, computer networks, e-mail systems, mobile devices, IT security or incident response;
- Deep knowledge of networking (TCP/IP, design, traffic flow, protocols, sessions), operating systems (Windows / *nix) and web technologies.
To Apply
To be considered for a
position in Canada
, we require the following:
- Resume – please include current address, personal email and telephone number;
If you are interested in applying for one of our
international locations
, please visit our Careers site to view and apply for available jobs.
Career Growth And Benefits
- CRA's robust skills development programs, including a commitment to offering 100 hours of training annually through formal and informal programs, encourage you to thrive as an individual and team member. Beginning with research and analysis skill building, training continues with technical training, presentation skills, internal seminars, and career mentoring and performance coaching from an assigned senior colleague. Additional leadership and collaboration opportunities exist through internal firm development activities.
- We offer a comprehensive total rewards program including a superior benefits package, wellness programming to support physical, mental, emotional and financial well-being, and in-house immigration support for foreign nationals and international business travelers.
Work Location Flexibility
CRA creates a work environment that enables our colleagues to benefit from being together in the office to best deliver on our promise of career growth, mentorship and inclusivity. At the same time, we recognize that individuals realize a range of benefits when working from home periodically. We currently expect that individuals spend at least 3 to 4 days a week working in the office (which may include traveling to another CRA office or to client meetings), with specific days determined in coordination with your practice or team.
Our Commitment to Equal Employment Opportunity
Charles River Associates is an equal opportunity employer (EOE). All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, age, disability, status as a protected veteran, or any other protected characteristic under applicable law.
Be The First To Know
About the latest Cybersecurity professionals Jobs in Canada !
ICS Cybersecurity Analyst
Posted today
Job Viewed
Job Description
Type of position: Regular
Your future role on our team
At BBA, we strive to offer effective, reliable, secure and resilient control systems to our industrial clients. Our ICS Cybersecurity team specializes in regulatory compliance and critical infrastructure protection, with a strong focus on helping utilities and industrial operators meet NERC CIP and ARS CIP requirements. We design and implement practical and innovative solutions that not only meet client needs but also satisfy mandatory compliance obligations.
You'll work hands-on as part of multidisciplinary teams whose members have complementary expertise in digital technologies, network and telecommunication infrastructures, programming and integration of automation systems, instrumentation and controls, and digital power systems.
With us, you'll get the opportunity to:
- Lead and support NERC CIP and ARS CIP compliance activities across standards such as CIP-002 through CIP-014, including drafting and revising policies, procedures, RSAWs, audit evidence, diagrams, and supporting documentation.
- Perform compliance gap assessments, readiness reviews, and mock audits to help clients prepare for regulatory oversight and mitigate risk of violations.
- Assess ICS/OT cybersecurity and physical security controls to identify vulnerabilities, recommend compliance-driven remediation, and assist clients in implementing technical and procedural controls.
- Advise clients on regulatory obligations and provide clear interpretation of NERC/ARS CIP requirements, ensuring deliverables align with both compliance and operational needs.
- Objectively evaluate and recommend compliance-aligned technological solutions available on the market, such as access control systems, monitoring solutions, network segmentation technologies, and secure remote access tools.
- Build strong relationships with clients by guiding them in decision-making to mature their compliance posture, cybersecurity governance, and overall risk resilience.
- Contribute to the development of compliance methodologies, playbooks, and internal best practices in BBA's in-house labs (industrial cybersecurity, automation, networking, power systems).
Do your qualities and values match our corporate culture?
- Autonomous
- Show an aptitude for self-development
- Result Oriented
- Excellent communication and interpersonal skill
- Attention to detail
- Strong organizational skills
- Thirst to learn and excel
- Caring mindset that puts people first
Certifications and job requirements:
- Undergraduate degree in cybersecurity, electrical engineering, computer engineering, or a related field.
- Minimum 3–6 years of direct experience with NERC CIP or ARS CIP compliance programs in the electric utility, energy, or industrial sector.
- Strong knowledge of NERC/ARS CIP standards (CIP-002 to CIP-014), including proven experience with audits, self-certifications, evidence gathering, RSAW development, and compliance program management.
- Excellent communication skills, both spoken and written (English required; French an asset).
- Experience with ICS/OT environments such as programmable logic controllers, distributed control systems, intelligent electronic devices (IEDs), and SCADA systems.
Familiarity with industrial network architectures and communication protocols (Ethernet/IP, Modbus, DNP3, ICCP, etc.). - Preferred but not essential assets
- Experience working with utilities, Independent System Operators (ISO/RTOs), or regulatory agencies in North America.
- Exposure to compliance-driven security controls such as patch management, vulnerability assessments, change management, and access management (aligned to CIP-005, CIP-007, CIP-010, CIP-011).
- Experience with IP network devices (switches, routers, firewalls) and security tools for monitoring and compliance reporting.
- Knowledge of cybersecurity technologies and best practices beyond compliance (ISA/IEC 62443, NIST CSF, NIST SP
- Involvement in SOC operations, incident response, recovery planning (CIP-008, CIP-009), and business continuity planning.
- Certifications such as NERC Certified CIP Professional (C3P), GCIP, CISSP, CISM, GICSP, or equivalent.
An overview of BBA's Total Rewards:
- Annual base salary
- Annual premium program for regular employees
- Access to a time bank
- Onsite mobility premium
- Cellphone Program
- Group insurance plan starting day one including short-term and long-term disability insurance for regular employees and telemedicine program
- Retirement saving plan for regular employees
- Vacation and sick leave
- Premium offered through the Employee Referral program
At BBA, you get many benefits:
- Access to a leadership program
- Opportunity to mentor our next generation: we invest in our people and help them develop
- A corporate culture that values expertise
- An inclusive culture that values diversity, respect and openness
- Pension, insurance plan and other benefits
- On site and at the office: Health, safety and the environment are a priority
- A caring environment where everyone's ideas are listened to and there is no perception of hierarchy
- Friendly, eco-mindful and high-tech workspaces
- Committees involved in important causes: diversity, social commitment, etc
- Growing business with many opportunities
About BBA
BBA is one of Canada's leading private consulting engineering firms, with over 45 years of experience serving the energy and natural resources industry.
Our people are the foundation of our success. Their passion and excellence have earned us recognition as one of Canada's Best Employers and Best Managed Companies, and we're committed to fostering a workplace where everyone feels empowered to grow, lead and be themselves.
Our teams bring together engineering, environmental and commissioning expertise to deliver practical, innovative and sustainable solutions—from strategy to execution. With 20 offices across Canada, the U.S. and Latin America, we combine local presence with international reach, offering clients close collaboration and field-ready support.
Learn more about our culture and projects on LinkedIn or connect with our talent team.
Cybersecurity Business Analyst
Posted 1 day ago
Job Viewed
Job Description
Calgary's leading energy companies on a contract, full-time basis. This is a fully remote role. The ideal candidate will support a portfolio of cybersecurity initiatives and start during the definition phase of project scoping and documentation. This resource would be expected to assist with projects through execution in the following year. The team consists of PMs, BAs, solutions architects and SMEs with a focus on both IT and OT environments, including industrial systems (ICS and SCADA).
Responsibilities Include:
-Gather and analyze business and technical requirements through stakeholder engagement.
-Translate requirements into clear technical specifications and user stories.
-Collaborate with development and project teams to design and deliver IT solutions.
-Support full project lifecycle including QA, UAT, training, and deployment.
-Assist in evaluating solution options and contribute to proposal activities.
We are a company committed to creating diverse and inclusive environments where people can bring their full, authentic selves to work every day. We are an equal opportunity/affirmative action employer that believes everyone matters. Qualified candidates will receive consideration for employment regardless of their race, color, ethnicity, religion, sex (including pregnancy), sexual orientation, gender identity and expression, marital status, national origin, ancestry, genetic factors, age, disability, protected veteran status, military or uniformed service member status, or any other status or characteristic protected by applicable laws, regulations, and ordinances. If you need assistance and/or a reasonable accommodation due to a disability during the application or recruiting process, please send a request to learn more about how we collect, keep, and process your private information, please review Insight Global's Workforce Privacy Policy: and Requirements
- 10+ years of hands on BA experience in cybersecurity projects
- Skilled at coordination with multiple SMEs in complex environment
- Strong interpersonal and soft skills - Identity and Access Management (IAM / IDAM) project experience
- Multi-Factor Authentication (MFA) project experience
- Governance, Risk and Compliance (GRC) project experience
- Experience working on projects in ICS/SCADA environments
- CBAP
- CISSP
- Oil/gas experience
Cybersecurity Project Manager
Posted 1 day ago
Job Viewed
Job Description
Insight Global is seeking a Cybersecurity Project Manager to join one of Calgary's leading energy companies on a contract, full-time basis. This is a fully remote role. The ideal candidate will support a portfolio of cybersecurity initiatives and start during the definition phase of project scoping and documentation. This resource would be expected to manage projects through execution in the following year. The team consists of PMs, BAs, solutions architects and SMEs with a focus on both IT and OT environments.
Responsibilities:
-Define project scope, objectives, and success criteria; develop project charters and governance plans.
-Lead day-to-day execution, monitor progress, manage risks, and ensure on-time delivery.
-Oversee budgets, forecasts, and vendor coordination.
-Facilitate team collaboration and adapt delivery artifacts to project methodology.
-Serve as primary stakeholder contact; manage communications and incorporate feedback.
-Implement and control change management processes across scope, schedule, and budget.
We are a company committed to creating diverse and inclusive environments where people can bring their full, authentic selves to work every day. We are an equal opportunity/affirmative action employer that believes everyone matters. Qualified candidates will receive consideration for employment regardless of their race, color, ethnicity, religion, sex (including pregnancy), sexual orientation, gender identity and expression, marital status, national origin, ancestry, genetic factors, age, disability, protected veteran status, military or uniformed service member status, or any other status or characteristic protected by applicable laws, regulations, and ordinances. If you need assistance and/or a reasonable accommodation due to a disability during the application or recruiting process, please send a request to learn more about how we collect, keep, and process your private information, please review Insight Global's Workforce Privacy Policy: and Requirements
- 10+ years of hands on experience managing cybersecurity projects
- Experience working with security architects to identify vulnerabilities and define mitigation strategies
- Experience conducting impact assessments and managing risk registers
- Strong interpersonal and soft skills - Identity and Access Management (IAM / IDAM) project experience
- Multi-Factor Authentication (MFA) project experience
- Governance, Risk and Compliance (GRC) project experience
- Experience managing projects in ICS/SCADA environments
-PMP
-CISSP
-Oil/gas experience