Req ID: 20601
Education Level: Bachelor's degree in information technology or other related fields including computer science, or engineering (electrical, IT, Cyber Security and Networking).
Job Overview
Ontario Power Generation Inc. (OPG) is looking for one (1) results-oriented professional to join our team in a full-time, permanent role of IT/OT Governance Risk Compliance (GRC) Analyst - Regulatory Analyst in our Toronto location.
The Regulatory Analyst is responsible for policy development, interpretation, implementation, monitoring, training and awareness, and compliance assessment/assurance related to OPG's cyber security program for its operational technology (OT) assets within the North American Electric Reliability Corporation Critical Infrastructure Protection (NERC CIP) cyber security compliance framework. This framework ensures the continuing reliability of the North American-wide critical interconnected electrical grid.
Reporting position: The Regulatory Analyst position is within OPG's Regulatory Affairs Department, who along with the CIO and Cyber Security lines of business, also report to OPG's CIP Senior Manager.
Key Accountabilities
- Lead the company-wide NERC CIP cyber security compliance program by developing and implementing effective policies related to protected OT assets.
- Maintain in-depth knowledge of regulatory cyber security requirements by participating in industry committees, working groups, and conferences, and develop communication plans to keep internal stakeholders informed of new and/or modified requirements.
- Provide interpretation and analysis of regulatory cyber security requirements, including NERC CIP, to internal stakeholders.
- Monitor, track, and trend OPG's NERC CIP compliance posture using assessments, processes, and software tools as required. Track and trend actions and timelines associated with outcomes of issues.
- Assess and make programmatic recommendations to management to ensure OT activities, processes, and procedures within other company departments meet defined internal policies and NERC CIP standards.
- Work with the CIO in assessing computer and OT hardware, software, and networking systems and make recommendations to the CIO and operations staff for compliance with NERC CIP standards.
- Develop strategies and material (including coordinating and facilitating working group meetings) to address awareness and training of OPG's NERC CIP cyber security program for all internal stakeholders.
- Coordinate and facilitate security assessments and audits with Internal Audit, outside consultants, and regulatory enforcement agencies. Track all related audits including scope of audits and timelines, and assist with preparation and submission of evidence and other related audit documentation. Work with auditors as appropriate to keep audit focus in scope, maintain excellent relationships and provide guidance, evaluation and advocacy on audit responses. Keep management and appropriate lines of business aware of proceedings throughout the audit.
Education
- Bachelor's degree in information technology or other related fields including computer science, or engineering (electrical, IT, Cyber Security and Networking).
- Information security related training or certifications such as CISSP or CRISC is considered an asset
Qualifications
- 6+ years of advanced IT/OT skills with high level of cyber security experience and expertise.
- Knowledge of IT/OT security risk management frameworks and compliance practices.
- Knowledge of securing network technologies, including client and server operating systems, and industrial process control equipment/systems.
- Understanding of regulations relating to NERC CIP standards.
- Excellent interpersonal, communication, and presentation skills, including formal report writing experience.
- Must have a strong customer service mindset and the ability to project that attitude to internal stakeholders within other lines of business.
- Ability to develop cyber security policies and guidelines based on regulatory requirements, best practices and industry standards.
- Experience or Familiarity with cyber security auditing processes
Ontario Power Generation
700 University Ave
Toronto
Ontario Canada
www.opg.com


