IT Advisor - Technology Cybersecurity
The IT Advisor conducts cybersecurity risk, threat, and vulnerability assessments to support risk-informed business decisions. They are responsible for maintaining cybersecurity governance, coordinating penetration testing, and managing third-party security risk assessments.
- Hybrid
- Vancouver, BC
- Posted Jul 31, 2026
- Apply by Aug 30, 2026
- 1 position
Job summary
Job Location: Vancouver, BC Employment type: Permanent Hours of work: Full-time (37.5 hrs/week) Annual Salary: $109,700.00 - 138,700.00 No. of positions: 1 Closing date: 2026-08-12 What you’ll do - * Reporting to the Technology Cybersecurity Manager, the IT Advisor will conduct cybersecurity security reviews, risk, and compliance activities within the Technology KBU. * Conduct cybersecurity risk, threat, vulnerability, and security impact assessments for technology and corporate initiatives. Identify risks, assess control effectiveness, recommend improvements, and support risk-informed business decisions. * Determine, document, and monitor risk treatment plans and risk acceptance decisions in accordance with organizational risk management processes. * Support cybersecurity governance activities through the development, maintenance, and application of cybersecurity policies, standards, procedures, and control frameworks. * Maintain knowledge of emerging cyber threats, industry standards, regulatory requirements, and internal policies and procedures. * Lead and coordinate third party penetration testing activities and track remediation of identified findings. * Conduct internal penetration testing, vulnerability assessments, and security reviews using approved tools and methodologies. * Lead and coordinate third party cybersecurity risk assessments, including evaluating vendor security posture, assurance reports (e.g., SOC 2 Type II), and compliance with security and regulatory requirements. * Review Privacy Impact Assessments (PIAs) and assess the adequacy of security controls and privacy safeguards. * Participate as a cybersecurity risk and governance SME on projects and initiatives to improve BC Hydro's cybersecurity posture. * Develop cybersecurity risk reporting, communicate risk findings and recommendations to stakeholders, and support responses to internal and external audits, assessments, and compliance reviews. What you bring – * University degree or experience in relevant discipline or equivalent combination of education and experience. * Ability to obtain security clearance for a Security Sensitive Position classification. * Minimum of 7 years of progressively responsible experience in cybersecurity, information security, governance, risk, compliance, audit, or security assurance. * Experience across cybersecurity governance, risk management, security reviews, vulnerability management, third party risk, compliance, or control assessments. * Knowledge of cybersecurity frameworks, standards, policies, and regulatory requirements, such as NIST, ISO 27001/27002, COBIT, and NERC CIP. * Ability to communicate cybersecurity risks, controls, vulnerabilities, and recommendations clearly to technical and non-technical stakeholders. * Strong relationship-building, influencing, presentation, documentation, facilitation, and prioritization skills. * Cybersecurity certification (e.g. CISSP, GSEC, GCIA, GCWN, CISA, CISM, CCNA, GPEN) would be considered an asset. * Experience in Industrial Control Systems (ICS) including SCADA and other Operational Technology (OT) used in the Energy sector would be considered an asset. What we offer – - A comprehensive benefits package - A minimum of 15 paid vacation days - A lifetime pension - Flexible work model, depending on your role type - Training and development courses For more information on the benefits we offer, visit bchydro.com/benefits. What else you should know – Don't forget to update your Candidate Profile with your current resume and copies of your certifications. This will ensure we have all the necessary information to assess your application without any delays. How to apply – Interested candidates should submit their applications online at https://app.bchydro.com/careers/current_opp.html or click ‘Apply’ You must use a supported browser, such as Firefox, Internet Explorer, Google Chrome or Safari. Your pop up blocker will also need to be disabled for the BC Hydro Careers site. On the BC Hydro Careers site, click on the Apply button in order to complete the steps to apply for this job. Please be sure to update your Candidate Profile with your current resume and include copies of your certifications, if applicable.
What you’ll do
The IT Advisor conducts cybersecurity risk, threat, and vulnerability assessments to support risk-informed business decisions. They are responsible for maintaining cybersecurity governance, coordinating penetration testing, and managing third-party security risk assessments.
Requirements
Requires a university degree and at least 7 years of experience in cybersecurity, governance, risk, and compliance. Knowledge of frameworks like NIST and ISO 27001 is required, while certifications and ICS/OT experience are considered assets.
Benefits
• Comprehensive Benefits Package • Paid Vacation Days • Lifetime Pension • Training And Development Courses
Other relevant skills
Identified from the job description. Confirm important requirements above.
- Cybersecurity Risk Assessment
- Governance Risk And Compliance
- Vulnerability Management
- Penetration Testing
- Third Party Risk Management
- Security Impact Assessments
- Privacy Impact Assessments
- Security Control Frameworks
- Stakeholder Communication
- Audit Support
- NIST
- ISO 27001/27002
- COBIT
- NERC CIP
- ICS/SCADA
- Operational Technology
Job areas
- Technology
- Security & Safety
- Energy
- Consulting
- Government & Public Sector
Additional details
- Minimum education
- Professional degree
- Minimum experience
- 5+ years
- Apply by
- Aug 30, 2026
- Posting language
- English
- Working hours
- 38 hours per week
- Seniority
- Associate
