Cybersecurity & IT Risk Analyst

WCB Manitoba

Winnipeg, CAonsitePosted Jul 23, 2026
Posting intelligenceActively listedReposted 4×, possible evergreen/ghost posting

Skills

azure

About the role

Job Summary (external):

The Cybersecurity & IT Risk Analyst is responsible for assessing, analyzing and resolving cybersecurity risks and vulnerabilities in the IT operating environment. This role works closely with the IT team and key stakeholders to ensure compliance with cybersecurity best practices and to execute day-to-day operational tasks.

Job Duties:

Conducts IT risk assessments to identify, classify, monitor and resolve cybersecurity threats.

Monitors and reports on the effectiveness of cybersecurity controls, risk management strategies, emerging cybersecurity threats and industry trends. Proactively addresses potential risks and exposures.

Develops and implements cybersecurity policies and procedures to protect the organization's IT assets and operating environment.

Manages the patch management policy, reviews and assesses vendor published patches and identifies prerequisites/side effects before they are applied into the operating environment.

Develops and manages the organization's patch schedule, monitors effectiveness, and prioritizes corrective steps required to address vulnerabilities and issues.

Manages vulnerability scanning process and tools. Monitors health of scanner engine and agent presence on assets.

Monitors vulnerability scan results and patch success. Reports and communicates results with IT teams and business stakeholders.

Reviews firewall rules and validates requirements based on system and business needs.

Produces monthly and quarterly Key Performance Indicator (KPI) reports pertaining to the health and security of technology and cloud assets, infrastructure, and configuration status.

Manages the security awareness training campaigns and platform, ensuring regular staff education and integration of training in the on-boarding process.

Designs, implements and reports on simulated phishing email campaigns. Recommends additional training (if required) based on results.

Identifies, investigates and classifies security incidents. Determines root cause, and provides advice/recommendations on mitigation strategies and resolution.

Reviews network security architectures design. Provides guidance and support to IT staff on cybersecurity best practices and protocols aligned with IT Security policies.

Advises IT leadership regarding cybersecurity risks and initiatives, progress and gaps.

Assists with preparation and presentation of the cybersecurity risk management reports as well as cybersecurity maturity assessments.

Performs other related duties as assigned.

Qualifications:

Completion of a recognized degree or diploma program in an IT related discipline

Minimum five (5) years Information Technology experience, including minimum three (3) years in the area of Cybersecurity and IT risk management, executing multiple cybersecurity programs

Knowledge of cybersecurity frameworks, concepts and standards such as National Institute of Standards and Technology (NIST), Center for Internet Security (CIS) and cloud security, vulnerability and access management with the ability to apply knowledge and best practices

Working knowledge of cloud computing technologies and platforms such as Microsoft Azure, network infrastructure, Active Directory, firewalls, Azure security solutions, anti-virus, Endpoint Detection and Response (EDR) and Security Information and Event Management (SIEM) tools

Familiarity with attack vectors, vulnerabilities, and how they are used/initiated by malicious actors

Working knowledge and experience with vulnerability management tools such as Qualys or Tenable

Ability to independently plan and organize workload and meet tight deadlines

Ability to develop professional documents in accordance with standard operating procedures and processes

Ability to communicate effectively, both verbally and in writing, including excellent presentation skills

Ability to facilitate meetings, stakeholder workshops and vendor presentations

Ability to foster positive working relationships with partners and stakeholders, including managed service providers and external vendors

The ability to communicate proficiently in both official languages (English & French) is an asset, but is not required

The following are considered assets:

Possession of certificates or education related to information technology, IT infrastructure, Azure cloud services, or system administration including the following:

Certified Information Systems Security Professional (CISSP), or Certified Information Security Manager (CISM)

Certified in Governance of Enterprise IT (CGEIT)

Certified Risk and Information Systems Control (CRISC)

Certified Information Systems Security Officer (CISSO)

Certified Cloud Security Professional (CCSP)

Certified Ethical Hacker (CEH)

IT Infrastructure Library (ITIL) Foundations certification

Competencies (internal only):

Essential:

Analysis/Problem Assessment

Technical/Professional Knowledge

Quality Orientation/Attention to Detail

Interpersonal Communication

Very Important:

Planning, Organizing & Follow-up

Organizational Awareness

Teamwork/Collaboration

Decision-Making (Judgement/problem Solving

Adaptability

Important:

Impact

Additional Information (internal):

The WCB recognizes that individuals may face barriers that hinder their full and equal participation in the workplace, and is committed to providing reasonable accommodation to all employees and candidates who are or may be disabled by one or more barriers in the workplace. Accommodations are available on request for candidates taking part in all aspects of the selection process.

MVA Applicable

You may be asked to demonstrate your ability through competency based interviewing and/or testing.

Screening decisions are based on information outlined in your resumé and cover letter. Your work performance must be satisfactory for your application to be considered. If applying for a term position or out of a term position, please note that article 10.09d of the Collective Agreement may apply.

The work from home suitability for this position is rated as High.

Additional Information (external):

Up to 2 permanent positions

Ability to communicate proficiently in both official languages (English & French) is an asset.

A satisfactory criminal record check and verification of education will be required for the successful candidate.

The WCB is committed to building a skilled, diverse workforce with equitable representation of Indigenous persons, visible minorities, persons with disabilities, women, 2SLGBTQ+ persons and members of other equity-seeking groups. Applicants are encouraged to indicate in their covering letter or resumé if they are a member of these groups.

The WCB recognizes that individuals may face barriers that hinder their full and equal participation in the workplace, and is committed to providing reasonable accommodation to all employees and candidates who are or may be disabled by one or more barriers in the workplace. Accommodations are available on request for candidates taking part in all aspects of the selection process.

The Workers Compensation Board promotes safety and health in Manitoba workplaces and aims to help prevent and reduce the occurrence of workplace injuries and disease. Working with its partners, the WCB promotes safe and healthy workplaces, facilitates recovery and return to work, provides compassionate and supportive compensation services for workers and employers, and ensures responsible financial stewardship.

WCBdoes encompasses what it means to work at the WCB. The WCB is proud to have employee benefits and programs that support financial and personal security, foster health and well-being, encourage involvement and support growth as an individual and member of the WCB community. The four categories of WCBdoes include: Security, Wellness, Engagement and Growth.

Job Summary (internal):

The Cybersecurity & IT Risk Analyst is responsible for assessing, analyzing and resolving cybersecurity risks and vulnerabilities in the IT operating environment. This role works closely with the IT team and key stakeholders to ensure compliance with cybersecurity best practices and to execute day-to-day operational tasks.

Questions about this role

Click "Apply with AI Applyd" above. We auto-fill the application from your resume and answer screening questions in seconds. No copy and paste, no juggling tabs.

Compensation for Risk Analyst roles in Canada varies widely by seniority, employer size, and remote vs onsite arrangement. Check the salary range on this listing when published, or browse our Risk Analyst hub for Canada medians across recent openings.

Most applications complete in under 90 seconds. You can track the status in your dashboard and watch the screenshot proof land the moment the application submits.

AI Applyd supports Greenhouse, Lever, Ashby, Workday, iCIMS, SmartRecruiters, Personio, Teamtailor and other major ATS platforms. If we can submit through the platform, we do.

Want AI Applyd to auto-apply to roles like this?

We tailor your resume per posting, fill the forms, and track replies for you.