3d ago
New

Cybersecurity GRC Analyst

CanadaCanada·VancouverFull Time Regularmid
Grc AnalystCybersecurity
1 views0 saves0 applied

Quick Summary

Overview

Powerex Corp., the wholly owned energy marketing subsidiary of BC Hydro, is responsible for marketing clean electricity across North America.

Technical Tools
Grc AnalystCybersecurity

Powerex Corp., the wholly owned energy marketing subsidiary of BC Hydro, is responsible for marketing clean electricity across North America. Cybersecurity is fundamental to maintaining the reliability, integrity, and availability of the systems that support our business.

Our Cybersecurity team is building a dedicated Governance, Risk & Compliance (GRC) function to strengthen oversight, accountability, and risk visibility across the organization. We are looking for an experienced Cybersecurity GRC Analyst to take ownership of this function and work directly with the Director of Cybersecurity to mature our GRC practices.

This role is well-suited to a cybersecurity GRC professional who brings hands-on experience in risk management, policy, compliance, and vendor risk, and who is ready to make a tangible impact — from shaping how we track and communicate risk to driving our cybersecurity awareness and compliance programs.

  • Take ownership of a new GRC function at the heart of Powerex’s cybersecurity program, with direct influence on how cybersecurity risk is managed and communicated.
  • Work closely with the Director of Cybersecurity and shape the maturity of our governance, risk, and compliance practices.
  • Develop broad impact across governance, policy, risk, compliance, vendor management, and cybersecurity awareness.
  • Influence how Powerex communicates its cybersecurity posture to executive leadership and the board.
  • Flexible hybrid model (as little as 2 days in the office), comprehensive compensation, pension, and benefits package.
  • Prepare quarterly cybersecurity reports for IT governance committees and the board, and coordinate the quarterly IT Cybersecurity Governance meetings — including agendas, action tracking, and follow-up.
  • Maintain a clear overview of the cybersecurity program and budget, act as the liaison between the cybersecurity team and the PMO, and coordinate recurring annual cybersecurity activities such as tabletop exercises, penetration tests, and policy reviews.
  • Maintain the policy register and own the end-to-end policy lifecycle — from drafting and scheduled reviews to exception management and sign-off — ensuring all policies are current, documented, and accessible in Confluence.
  • Coordinate policy communication and sign-off campaigns with HR and business stakeholders, and work with the CS director and IT leaders to identify gaps and drive the creation of new policies where needed.
  • Own the cybersecurity risk register: ensure risks are logged with clear ownership and ratings, facilitate monthly risk reviews with the team, and prepare quarterly risk summaries — including risk themes and mitigation status — for governance and board-level reporting.
  • Drive the formal risk acceptance process, ensuring risks without planned mitigations are documented and approved by an accountable owner, and that the risk register remains a reliable, up-to-date source of truth.
  • Manage the vendor register and own the end-to-end TPRM lifecycle: coordinate onboarding assessments using standardized questionnaires, administer Third-Party Access Policy acknowledgements, and drive annual re-assessments and collection of security certifications.
  • Maintain vendor offboarding checklists and confirm that access revocation and data handling steps are completed, ensuring Powerex’s third-party risk exposure is well-documented and continuously managed.
  • Track all audit findings in the risk register with named owners and remediation timelines, prepare compliance status updates for quarterly governance reporting, and coordinate internal self-assessments against the cybersecurity standard and NIST CSF.
  • Monitor relevant external requirements — including PIPA, cybersecurity insurance expectations, and external audit requirements — to ensure the necessary controls are in place and documented.
  • Design and deliver the annual cybersecurity awareness program, organize Powerex’s participation in Cybersecurity Awareness Month, and track engagement metrics for reporting to the CS director and quarterly governance meetings.
  • Produce quarterly awareness summaries — covering participation rates, simulation click rates, and trends — and coordinate targeted follow-up with managers or HR for staff who repeatedly fail simulations or have not completed awareness activities.
  • Bachelor’s degree in Information Security, Computer Science, Engineering, or a related technical field (or equivalent practical experience).
  • 3+ years of hands-on experience in cybersecurity GRC — including risk management, compliance, policy management, audit support, or vendor risk — within a cybersecurity context.
  • Demonstrated experience supporting assessments, audits, control testing, compliance activities, and evidence collection, with a solid understanding of frameworks such as NIST CSF, ISO 27001, or SOC 2.
  • Experience tracking risks, issues, remediation plans, and compliance evidence using tools such as Jira, Confluence, SharePoint or more specialized products
  • Strong written and verbal communication skills — able to distill complex risk and compliance topics into clear, concise summaries for executive and non-technical audiences.
  • Able to work independently, manage multiple workstreams, and build relationships across IT, business, and leadership teams.
  • Nice to Have

    ~2 min read
  • Relevant certifications such as CISA, CISM, CRISC, CompTIA Security+, or equivalent.
  • Hands-on experience with cybersecurity or GRC tooling — such as GRC platforms, SIEM (e.g., Microsoft Sentinel, Google SecOps, Splunk), risk register tools, or vulnerability management tools.
  • Familiarity with Canadian privacy legislation (PIPA) or cybersecurity insurance requirements.
  • Experience in regulated or business-critical environments such as energy, financial services, or utilities.
  • Full-time position.
  • Must be located in the Vancouver/Lower Mainland area.
  • Must be legally authorized to work in Canada.
  • A background check and references will be required for the position.
  • Compensation: The expected salary range for this role is $90k-$110k
  • Comprehensive benefits package including extended health, dental, vision, and pension.
  • Opportunity to take ownership of a new GRC function and leave a lasting mark on Powerex’s cybersecurity posture.
  • A collaborative, innovation-driven IT culture that is actively embracing AI and modern cybersecurity practices.
  • Professional development support, including funding for certifications and training.
  • Powerex Corp. is a market leader in the trading and marketing of clean and renewable wholesale electricity and associated environmental products. We are at the forefront of the clean energy transition, helping our wholesale customers throughout Western North America meet their increasingly ambitious environmental goals. Our customers include electricity and natural gas utilities, global energy companies, large financial institutions, and global technology companies. We are an established, entrepreneurial, and consistently successful company that is a wholly owned subsidiary of BC Hydro. Powerex’s financial success directly benefits the citizens of British Columbia as Powerex’s income helps lower BC Hydro’s electricity rates.

    Fast paced, dynamic, and empowering are words that describe a career with Powerex. We pride ourselves on having a supportive and fun culture, and a strong commitment to the development and wellbeing of our employees. With an average tenure of 15+ years on our trade floor, Powerex stands out as an employer of choice in Vancouver. Ask any Powerex employee what they love about their job, and their first comment will likely be “the people I work with every day.”

    At Powerex we believe that a diverse team is a strong team, and our dedication to equity and inclusion is intertwined with our performance-based culture. We strive for excellence in everything we do, and we recognize that diverse perspectives and backgrounds fuel innovation and drive superior performance.

    Location & Eligibility

    Where is the job
    Vancouver, Canada
    Hybrid — some on-site time required
    Who can apply
    CA

    Listing Details

    Posted
    September 30, 2026
    First seen
    October 2, 2026
    Last seen
    October 3, 2026

    Posting Health

    Days active
    0
    Repost count
    0
    Trust Level
    62%
    Scored at
    October 3, 2026

    Signal breakdown

    freshnesssource trustcontent trustemployer trust
    Newsletter

    Stay ahead of the market

    Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.

    A
    B
    C
    D
    Join 12,000+ marketers

    No spam. Unsubscribe at any time.

    Cybersecurity GRC Analyst