Share this Job

Senior Cybersecurity Advisor - Governance & Risk

Date: May 4, 2022

Location: Toronto, ON, CA

Company: Hydro One Networks Inc

44006 - Toronto - Regular - Ongoing 

Safety Comes First is a core value at Hydro One, and we remain committed to taking every reasonable precaution to ensure a respectful, safe and healthy working environment. Further to this commitment, we have adopted a COVID-19 Vaccination Policy to protect the health of our employees from the hazard of COVID-19. Employees will be required to either be fully vaccinated or undergo regular rapid antigen testing in order to access a Hydro One worksite.

Hydro One is proud to be the largest electricity transmission and distribution provider in Ontario, serving nearly  1.4 million customers. We have a long history in the industry with our roots dating back over 110 years to 1906. Since then, we have worked to grow and evolve to meet the changing needs of our customers and communities across Ontario. Today, we’re focused on providing exceptional customer service and ensuring we are building safe communities where we live, work and play.

It’s an exciting time to join the team at Hydro One!


As Senior Cybersecurity Advisor at Hydro One, you will:

  • Join a diverse team of experienced Cybersecurity practitioners, and act as a subject matter expert for Information Security with the Lines of Business (LOB)
  • Focus on security operations and information security governance as it relates to Information Technology (IT) and Operations Technology (OT) systems
  • Translate technical cyber & information security requirements into business actions. Preserve and apply the security governance framework (based on NIST) for the LOBs.
  • Work with different, potentially conflicting requirements (legal, regulatory, industry standards, security strategy) to distil realistic security requirements supporting the business strategy
  • Conduct research to maintain and expand knowledge on the latest cyber security technologies and standards, as well as the threat and vulnerability landscape for Industrial Control Systems (ICS) in general, and the Electrical sector in Ontario


You are an experienced Cyber Risk management professional with extensive knowledge and experience in architecture of the following domains and their application to IT (and preferably OT) environments:

  • Identity and Access Management
  • Threat, Risk and Compliance
  • Vulnerability Management
  • Security Operations
  • Infrastructure Security
  • Security Governance and Policies
  • Security Architecture


Specific Accountabilities may include:

  • Represent the Cyber Security Governance, Risk and Architecture team as an advisor and expert Cyber Security SME to support overall security program
  • Seek industry trends and organization knowledge to understand and implement effective risk management practices.
  • Provide recommendations for security architecture for all technology projects, new platforms – on premise or cloud based and ensure alignment of technology solutions to established frameworks and security standards.
  • Provide consultation to operational teams as a risk-focused senior cyber security advisor on security-related initiatives, solution selection, security architecture and security assessments
  • Provide risk management insights through an ongoing process of gathering, analyzing and prioritizing actionable risk messages; develop content to support communication of the messages and enable technology teams to consume and apply the messages to their respective areas.
  • Establish practices and communications to foster a culture of issue self-identification and support partners in the Risk Issue management processes to carry out their roles effectively and consistently.
  • Continuously improve quality of the issue management process and data.
  • Manage various stakeholders across levels (including executives) and engage in resolution of risk issues.
  • Build and manage effective relationships with key stakeholders, team members, and other business, functional and support groups. Collaborate with senior leaders to ensure alignment of Cyber Security initiatives.
  • Support responses to various regulatory requests and audits


Requisite Experience and Skills:

  • Extensive experience of strategic development of standards, Cyber Security Risk Identification and Mitigation techniques
  • Demonstrable experience in an advisor/consultant capacity representing Information Security
  • 10+ years of information security experience in risk management and information security
  • Strong knowledge of NIST SP800-53 and NIST Cyber Security Framework
  • Sound understanding of the Ontario Cyber Security Framework
  • Familiarity with Risk Management Frameworks (ISO 27005, NIST 800-30/39 or ISF IRAM2 )
  • Familiarity with scenario-based risk analysis using common threat modelling techniques
  • Knowledge of current trends in the cyber security industry
  • Knowledge of unique threats to the energy sector and its role within Canadian critical infrastructure
  • Excellent interpersonal, communication, and presentation skills applicable to a wide audience including senior and executive management
  • Excellent organization/project planning, time and organizational change skills across multiple functional groups and departments
  • Knowledge of metrics programs and security dashboard creation
  • Post-secondary education in Computer Science or related field, or equivalent work experience
  • One or more of CISSP, CRISC, CISM or other relevant certifications would be an asset


Internal Job Title: Sr. IT Security Specialist 

At Hydro One we understand that the success and strength of our business rests with our people. When we develop their skills, we are investing in both their success and ours. To secure the best talent, we seek to create a workforce that reflects the diverse populations of the communities where we live and work and to create a culture based on safety, innovation and inclusiveness.


We are honoured to be recognized by Forbes in its list of Canada’s Best Employers for 2021.


Thank you for considering a career with Hydro One, we welcome applications from all qualified candidates. If you are having difficulty using our online application system and you need an accommodation due to a disability, please email careers@hydroone.com. Hydro One will provide reasonable accommodation for qualified individuals with disabilities in the job application process.


Please note this email is only for accommodation requests. Resumes sent to this email address will not be considered.


Deadline: June 7, 2022



In the event you are experiencing difficulties applying to this job please consult our help page here.

Job Segment: Risk Management, Electrical, Law, Cyber Security, Computer Science, Finance, Engineering, Legal, Security, Technology