Analyst, Security Policy & Audit

Engineering / Technical Edmonton, Alberta


Description

Highlights of the job

We are hiring a Full-Time Permanent Analyst, Security & Policy position working out of Edmonton, AB. This position is open to internal and external applicants.

 

As the Security Policy & Audit Analyst, you will collaborate with specialized cross-functional teams to support EPCOR Distribution & Transmission Inc. (EDTI)’s Alberta Reliability Standard (ARS) compliance program. Your responsibilities include implementing and executing technical administrative processes for regular compliance reviews, documentation updates, and end-user education. Leveraging your strong organizational and data analysis skills, you will review and maintain compliance evidence and audit documentation.

 

The Analyst collaborates with the Security Policy & Audit Specialist and the OT Security Specialist to maintain EDTI’s cybersecurity and Critical Infrastructure Protection (CIP) documentation. You will serve as the primary contact for EDTI staff regarding the company’s cybersecurity and CIP program. Additionally, the Analyst will work with the System Operations team to ensure compliance with ARS and ISO rules and standards.

 

This position may be eligible for EPCOR’s hybrid work program. The Security Policy & Audit Analyst reports to and works closely with the Senior Manager, OT Systems & Security.

What you’d be responsible for

  • Assisting EDTI in maintaining EPCOR’s ARS CIP processes, and procedures, including but not limited to change management, access management, and patch management.  This includes compiling, reviewing and preparing data used to sustain these processes and for audit evidence.
  • Assisting EDTI System Control & Engineering personnel with recurring compliance evidence collection, regular process and documentation reviews related to Alberta Reliability Standards, ISO Rules, and the maintenance of System Control & Engineering training records.
  • Aiding in the sustainment and continuous improvement of EPCOR’s ARS compliance program, including the completion of annual ARS self-certifications, utilizing data analysis and organizational skillsets to improve reporting and existing processes.
  • Collecting, organizing, and formatting evidence for regulatory and policy audits, interpreting technical evidence, and drafting business language explanations for AESO regulatory compliance audit worksheets.
  • Completing and maintaining quarterly and annual CIP access reviews for managerial signoff and supporting periodic reviews conducted by other teams.
  • Organizing and tracking the completion of annual CIP training and assisting with periodic personnel risk assessment (PRA) renewals.
  • Providing technical and business analysis, aiding in the development of business cases and project proposals, and participating in regulatory filings related to cybersecurity and operational technology initiatives.
  • Assisting in the writing, formatting, and upkeep of various security policy and technology roadmaps.
  • Providing input to the planning and direction of the OT Systems & Security and System Control & Engineering teams, while maintaining effective relationships with other roles as needed.
  • Collaborating with other EDTI staff to stay informed about emerging utility industry compliance issues through participation in various forums and industry groups.

What’s required to be successful

  • A diploma in Business, Data Analysis/Intelligence or related field is required. Related education (Information Technology) is considered an asset
    • A degree in Business, Data Analysis/Intelligence or related field is considered an asset
  • 1+ years of equivalent experience in a business analyst or audit role, and/or 1+ years of experience working at a utility in a regulatory or compliance support role
  • Experience with ARS / NERC CIP regulatory requirements is considered an asset
  • Proficiency in business writing for the preparation of reports and presentations is required
  • Effective communication and presentation skills, suitable for senior management levels, are required
  • Strong organizational ability with attention to detail is required.
  • Demonstrated reporting and data analysis skillsets using Excel & PowerBI
  • Strong computer skillsets especially with MS Office and SharePoint
  • Experience with business and process analysis

 

As the successful Analyst, you proactively solve problems, stay organized, and achieve goals without needing to be prompted. You are a team player and relationship builder, demonstrated by your active listening skills and open communication style. With excellence as your standard, you use sound judgment to complete tasks and consistently meet or exceed the expectations of both internal and external customers. You effectively and clearly communicate technical information, both verbally and in writing, to team members, management, executives, and other stakeholders. You take pride in the quality of your work.

Other important facts about this job

Jurisdiction: CSU52

Class: T1

Wage: Starting at $39.23 per hour. Final Wage and Step will be determined at the time of selection and is subject to change based on the ratification of the new Collective Agreement.

Hours of work: 80 hours biweekly

 

This position may be eligible for a $500 employee referral reward! Ensure you enter “Referral” as the source when you are applying.

 

Application deadline: January 5, 2025

 

EPCOR Employees: Please ensure that you are using your “@epcor.com” email address.

 

Learn more about Working at EPCOR!

Follow us on LinkedIn, Twitter, Glassdoor or Facebook!

 

#LI-TA2

 

Please note the following information:

 

  • A requirement of working for EPCOR is that you are at least 18 years of age, successfully attained a high school diploma (GED, or equivalent level of secondary education) and legally entitled to work in Canada. (A copy of a valid work permit may be required.)
  • If you are considered for the position, clearance on all applicable background checks (which may include criminal, identity, educational, and/or credit) and professional reference checks is required. Some EPCOR positions require an enhanced level of background assessment, which is dictated by law. These positions require advanced criminal record checks that must also be conducted from time to time after commencement of employment.
  • A technical/practical assessment may be administered during the selection process and this exercise will be used as a part of the selection criterion.
  • To meet the physical demands required of some positions, candidates must be in good physical condition and willing to work in all weather conditions. Clearance on pre-placement medical and drug and alcohol testing may be required.
  • Prior infractions for unsafe driving behaviours will be evaluated and considered for non-selection regardless of current demerits on file.