Cyber Security Risk Specialist

British Columbia Lottery Corporation
British Columbia
CAD 60,000 - 80,000
Job description

BCLC exists to generate win-wins for the greater good.

For our people, our players, our communities, our industry, and our planet.

Lottery | Casino | Sports

Being a social purpose company, we are not only able to better align our business decisions with our purpose, but more importantly, we are committing to doing our part in creating a better world.

We bring our purpose to life by ensuring all our actions, behaviours and decisions create benefits for communities and the planet.

Motivated and guided by our social purpose, everything we do must benefit the greater good. And we encourage our employees, partners, players, industry and communities to engage with us on this ambition.

We want you to be where you feel you can do your best work. Most of our jobs can be done remotely providing you reside in BC.

This is a Permanent, Full Time opportunity

Expected Salary Range: $84,981.00-$106,227.00-$132,784.00

JOB SUMMARY

The Cyber Security Specialist 3 role supports BCLC’s Cyber Security program and supports projects and business operations by taking a lead role in identifying information security risks in high-complexity systems, recommending appropriate controls, and assisting with technical mitigation strategies with security operations and/or technology. The aim of the role is to sustain and improve BCLC’s information security posture and thereby protect BCLC’s information assets. The role conducts senior-level security assessments and incident investigations. Additionally, the role brings deep technical capabilities to support the Cyber Security program.

KEY ACCOUNTABILITIES

  1. Provides high-level recommendations to management for day-to-day activities associated with BCLC’s procedures & systems for the Cyber Security program; working closely with internal stakeholders and external vendors to ensure alignment. Leads the development and continuous improvement of standards, policies, procedures, and methodologies, and identifies gaps and provides creative solutions to enhance departmental processes. Ensures compliance with corporate and industry standards and best practices.
  2. Serves as an expert on emerging information security trends and industry best practices and standards. Masters domain knowledge to reinforce an understanding of BCLC’s key business systems and processes, identifying information security risks and leading the response to information security incidents. Develops and maintains field-specific information security strategies for consideration and input into overall Cyber Security program.
  3. Enhances and evolves the day-to-day monitoring of the integrity of systems and infrastructure components.
  4. Leads high-complexity information security compliance and risk assessments of processes, infrastructure and solutions, and shapes and recommends appropriate controls and assisting with technical mitigation strategies.
  5. Leads the Cyber Security team’s investigation of and response to field incidents, ensuring that issues are dealt with in a timely manner. Makes tactical and strategic decisions to ensure an appropriate response to protect the security of BCLC systems and information, while working within defined policies, standards, and procedures. Conducts thorough forensic reviews of platforms, systems, and devices during and post incident, ensuring that data is properly handled, and chain of custody is preserved for potential presentation in court.
  6. Leads security testing activities such as penetration testing, application security testing, etc. Where instructed by management, leads enterprise vulnerability management function.
  7. Provides information on system configurations, accounts and information security practices to auditors and regulators as directed by the Cyber Security management team.
  8. Leads large/high-complexity projects as directed by the Cyber Security program, working collaboratively in a team environment analyzing solutions, processes, and infrastructure, and recommending appropriate information security controls. Develops recommendations for secure solutions, coordinating closely with enterprise architecture teams, enhancing the security architecture repository, and developing secure design patterns & principles. Leads the development and delivery of information security training programs.
  9. Develops strategic relationships with internal stakeholders, external vendors, industry partners, and auditors to promote collaborative and positive team environments. Develops strategic relationships with other industry peers to facilitate information exchange and partnering. Provides technical expertise and support to BCLC’s privacy and compliance functions as appropriate.
  10. Provides instruction, training, and occasional work delegation to Cyber Security 1 and 2 roles and leads information security governance throughout the organization. Provides Subject Matter Expert (SME) coaching, mentoring and seasoned leadership on information security matters with domain owners from an enterprise perspective, evangelizing cyber security, and ‘selling’ the value of good information security risk management to the organization.
  11. Acts as a delegate for their leader as required.

QUALIFICATIONS

A combination of education, experience, and demonstrated skills may be considered.

EDUCATION & EXPERIENCE

  1. University / Bachelor’s degree in a relevant discipline such as computing or information security;
  2. 4 to 6 years relevant and progressive experience in a relevant field such as computing or information security;
  3. Experience assessing and remediating information security issues in areas such as identity & access management, risk analysis/management, endpoint security, architecture, network security/penetration testing, application security testing, compliance testing or security operations;
  4. At least one information security certification, such as CISSP, CISM or GSEC, is required;
  5. Experience assessing the security of web, cloud computing, SaaS, and mobile applications;
  6. Experience producing information security metrics and reporting;
  7. Extensive experience with security tools, such as SIEM, file integrity monitoring and database monitoring;

KNOWLEDGE & TECHNICAL SKILLS

  1. Expert knowledge of networking fundamentals (e.g. TCP/IP, SSL/TLS, firewalls, IDS/IPS, etc.), information security frameworks, and security standards & regulations related to data privacy and security;
  2. Expert knowledge of and experience with Windows and/or Linux, especially in an enterprise environment (e.g. Active Directory, Group Policy, Red Hat Satellite, etc.);
  3. Proficient working with security tools, such as SIEM, file integrity monitoring, and database monitoring;
  4. Deep understanding of information security risk management, controls, and compliance;
  5. Advanced technical security skills (Application and OS hardening, vulnerability assessments, security audits, networking, IDS, firewalls, etc.);
  6. Enhanced technical writing skills; able to confidently and competently author complex, multi-faceted and strategic documentation for technical, management and executive audiences;
  7. Proficient user of Microsoft Office Suite: Word, Excel, Outlook, PowerPoint, etc.

COMPETENCIES

  1. Exceptional attention to detail and accuracy;
  2. Advanced business acumen;
  3. Advanced problem-solving skills spanning multiple technologies, with ability to think analytically and innovate accordingly;
  4. Advanced interpersonal and relationship-building skills;
  5. Advanced written and verbal communication and presentation skills, with ability to effectively convey technical and business concepts to technical, management and executive audiences, and facilitate clear collaboration within cross-functional teams;
  6. Advanced time management, organizational, and multi-tasking skills to manage multiple concurrent objectives, projects, groups, and activities, and support team leadership/management and enterprise-wide initiatives;
  7. Able to deal with highly sensitive matters with a high degree of tact and diplomacy.

BCLC has organizational Values that reflect the culture we strive to maintain. All employees are expected to ensure their actions, decisions, and interactions consistently align with BCLC’s Values, Respect, Integrity, and Community.

  1. Building Trust;
  2. Customer Focus;
  3. Welcome change and adapt quickly;
  4. Hold oneself and others accountable for their behaviours.

Preference may be given to individuals who have the following:

  1. Experience with Python, Powershell, or another scripting language would be an asset;
  2. Experience with information security systems such as SOAR, EDR, DLP, is desirable;
  3. Technology administration certifications, such as MCSE, CCIE, RHCE (Network Security Engineer), CCNP, AWS Certified Advanced Networking, VCP-NV 2019, are an asset;
  4. EnCase Certified Examiner (EnCE) and GIAC GCFE and/or GCFA forensic certifications (DFIR Engineer) are an asset;
  5. Experience in security controls and integrations related to Microsoft 365 or AWS implementations are an asset;
  6. Understanding of Agile methodology or experience working with a similar cross-functional team environment would be an asset;
  7. Understanding of B.C. gaming industry would be an asset.

WORKING CONDITIONS (IF APPLICABLE)

  1. Infrequent travel may be required for conferences, internal stakeholder and external vendor interactions, training, meetings with industry partners and/or auditors, on-site assessments/inspections, etc.

What’s in it for you

  1. Defined benefit pension plan which provides a recurring income you can depend on for life throughout retirement
  2. We pride ourselves on our flexible working model which supports work-life integration and our 37.5 hour work week
  3. Professional development including education/certification sponsorship, in house leadership cohorts, LinkedIn Learning

However you identify, or whatever your path in life, if you see something here that makes you excited to get to work every day, please apply. We hire people for skills, capabilities and potential, not just education and experience.

We value Respect, Integrity and Community, and we provide an inclusive environment where everyone can feel like they belong.

Our social purpose is much more than returning 100% of net income to the province in the form of healthcare & education programs, and community gaming grants. Check it out!

Did you know BCLC is an industry leader in player health and safe & responsible gambling? Find out more!

If you require accommodation so you can be at your best in the interview, please let us know: recruitment@bclc.com.

All candidates must be at least 19 years of age and legally eligible to work in Canada.

Get a free, confidential resume review.
Select file or drag and drop it
Avatar
Free online coaching
Improve your chances of getting that interview invitation!
Be the first to explore new Cyber Security Risk Specialist jobs in British Columbia