Aug 28, 2025
Electric Energy Jobs

Cyber Security Specialist

Organization:
Ontario Power Generation
Region:
Canada, Ontario, Pickering
End of contest:
October 30, 2023
  This job posting has expired
Type:
Full time
Category:
Information technology (it)
Description
Req ID:  44311

Status: Regular Full Time

Working Conditions: Hybrid Working Environment     

Education Level: 4 years of Bachelor/University degree in Engineering, Computer Science, Information Technology or related field.

Location: Pickering, ON

Travel: Yes- 10%

Deadline to Apply: October 30, 2023

Electrify your career and help build a brighter tomorrow.

 Every generation has a challenge that defines them. At OPG, we are calling on all innovators, disruptors, thought leaders and change-makers. Join us to electrify life in one generation and build a sustainable future powered by our electricity, our ideas, and our people. Join OPG and make history.

Whether you work in the skilled trades or are a business professional, a career at OPG is an opportunity to electrify your life on -- and off -- the job.

NEW CAMPUS: In late 2024, OPG is establishing our new campus at 1908 Colonel Sam Drive, Oshawa, Ontario. The new campus will provide a cutting-edge work environment that fosters collaboration and innovation.

BE THE GENERATION to help build a brighter tomorrow.

JOB OVERVIEW

Ontario Power Generation (OPG) is looking for dynamic, strategic and results-driven professionals to join our team in the role of Cyber Security Specialist in our Nuclear Cyber Security team.

Reporting to the Section Head, Nuclear Cyber Security, this position is responsible to tracking and investigating security threats and driving remediation strategies, that includes creating reports, authoring playbooks and maintaining compliance to cybersecurity policies. Be required to keep abreast of up-to-date developments and trends in cybersecurity management information systems, networks and computer applications.

This is an exciting opportunity to work in an environment where you will contribute to OPG's public outreach, engagement and education efforts as part of the company's commitment to growing its social license.

KEY ACCOUNTABILITIES 

  • Working with internal/external teams and system owners to drive remediation and arrive at solutions that maintain business continuity.
  • Drive remediation of vulnerabilities by working with internal/external teams and system owners to mitigate based on a risk-based approach, that could require the business to take action. Provide system owners with accurate action plans and follow up on implementation.
  • Perform internal assessments of Nuclear Cyber Security Program effectiveness.
  • Perform external benchmarking of Nuclear Cyber Security Program against industry standards
  • Create reports for key metrics and deliverables for Cyber Security and present to senior management, as assigned. Identify opportunities for improvement and work with stakeholders on implementation.
  • Maintain an in depth understanding of Threat Assessments, Risk Management and Incident Response.
  • Develop and participate in Incident Response activities and drills.
  • Assist, as required, during Incident Response and Recovery activities.
  • Identify and support the development of processes and procedures to improve monitoring, detection, and response to threats.
  • Provide input to and maintain compliance to policies, standards and procedures. Work with other team members to provide up to date information to stakeholders, acting as a local compliance technical resource and ensure compliance with current standards.
  • Support Cyber Security in audits and compliance reporting. Such involves performing procedures for critical controls in collaboration with system owners to ensure regulatory compliance.
  • As assigned, represent OPG Cyber in sessions for internal policy/projects and/or general updates for Security e.g. interface committee to explain the need for changes, based on feedback provided by users.
  • Collaborate with and provide advice to Cyber Security team on best practices and assist with awareness of Cyber Security from a regulatory and industry perspective. Attend workshops with industry peers and exchange information on emerging technologies and controls.
  • Perform patch management, prepare annual Firewall assessments, in addition to supporting audits and inspections on the Nuclear Cyber Security Program
  • Participate in cyber vulnerability assessments, participate in audits and assessments and provide support, as required.
  • Provide support to related lines of business, including Nuclear Projects and CIO Projects.
  • Other Duties as Required

EDUCATION

  • 4 years of Bachelor/University degree in Engineering, Computer Science, Information Technology or related field.
  • Designation in the Cyber Security field or equivalent experience
  • Requires an advanced knowledge of engineering and/or computer sciences and cybersecurity, including in-depth understanding of security best practices, risks and technologies, and the solutions to address those risks within the operational technology (OT) environment as work will be performed to support the Industrial Control Systems (ICS) within the Nuclear sites.
  • Requires knowledge gained through security and other training organizations, such as Information Systems Security Certification Consortium (ISC2), SysAdmin Audit Network and Security (SANS), or Information Systems Audit & Control Association (ISACA), to investigate threats to corporate information technology systems applications, and networks, and assess, evaluate and recommend additions, modifications or replacement. Requires a good knowledge of communications, both oral and written, prepare procedures and playbooks and communicate effectively with others. 
  • Requires a good communications skill, both oral and written, to prepare reports and communicate effectively with others.

QUALIFICATIONS

  • 6+ years of practical cybersecurity experience, preferably related to instrumentation and control (I&C),
  • 6+ years of practical engineering experience preferably with ICS.
  • Completed or working towards at least one cyber security certification for Industrial Control Systems (ICS) (i.e., SANS ICS, ICS-CERT, US-CERT, ISA, CybatiWorks, or other relevant certifications) considered an asset
  • Knowledge of CSA N290.7-14, Cyber Security for Nuclear Power Plants and Small Reactor Facilities or CSA N290.7-21, Cyber Security for Nuclear Facilities would be an asset
  • Requires experience to have gained an understanding of various vulnerability assessments, threat vectors, methodologies and social engineering techniques to ensure events are categorized correctly and remediated in a timely manner.
  • Ability to work effectively and efficiently in a flexible hybrid office environment.

Read the full posting.

Contact

Ontario Power Generation

700 University Ave

Toronto

Ontario Canada

www.opg.com