Cybersecurity & IT Risk Analyst
Skills
About the role
Position ID:
J0726-0354
Competition No.:
26-60
Job Title:
Cybersecurity & IT Risk Analyst
Job Type:
Permanent, Full-time
Open Positions:
2
Job Location:
Winnipeg, Manitoba, Canada
Work From Home Eligible:
Yes
Workplace Type:
Hybrid
Date Posted:
July 23, 2026
Closing Date:
August 6, 2026
About the Workers Compensation Board of Manitoba
The Workers Compensation Board of Manitoba (WCB) serves workers and employers through a no-fault insurance system integral to the Manitoba economy. With approximately 600 employees, the WCB is dedicated to ensuring and supporting safe and healthy workplaces.
We put workers and employers at the centre of everything we do, providing services for injury prevention, compensation and facilitating return to health and work. Through SAFE Work Manitoba, a division of the WCB, we collaborate with our partners to build a strong culture of workplace safety and health by preventing injuries and illnesses before they occur.
If you're passionate about making a meaningful difference in people's lives, we invite you to join our dedicated team and contribute to a safer Manitoba.
Why work for us?
If you’re looking to make a real difference in your community, grow your career and work in a supportive, inclusive environment, the WCB is the place for you. We offer:
competitive wages
compressed work week and flexible start times
defined benefit pension plan
100% employer-paid benefits
work from home program
paid professional development
health and wellness spending accounts
paid mental health and wellness days
staff appreciation and recognition events
respectful, diverse and inclusive workplace culture
Apply today and see why we’re one of Manitoba's Top Employers.
Job Summary
The Cybersecurity & IT Risk Analyst is responsible for assessing, analyzing and resolving cybersecurity risks and vulnerabilities in the IT operating environment. This role works closely with the IT team and key stakeholders to ensure compliance with cybersecurity best practices and to execute day-to-day operational tasks.
Job Duties:
Conducts IT risk assessments to identify, classify, monitor and resolve cybersecurity threats.
Monitors and reports on the effectiveness of cybersecurity controls, risk management strategies, emerging cybersecurity threats and industry trends. Proactively addresses potential risks and exposures.
Develops and implements cybersecurity policies and procedures to protect the organization's IT assets and operating environment.
Manages the patch management policy, reviews and assesses vendor published patches and identifies prerequisites/side effects before they are applied into the operating environment.
Develops and manages the organization's patch schedule, monitors effectiveness, and prioritizes corrective steps required to address vulnerabilities and issues.
Manages vulnerability scanning process and tools. Monitors health of scanner engine and agent presence on assets.
Monitors vulnerability scan results and patch success. Reports and communicates results with IT teams and business stakeholders.
Reviews firewall rules and validates requirements based on system and business needs.
Produces monthly and quarterly Key Performance Indicator (KPI) reports pertaining to the health and security of technology and cloud assets, infrastructure, and configuration status.
Manages the security awareness training campaigns and platform, ensuring regular staff education and integration of training in the on-boarding process.
Designs, implements and reports on simulated phishing email campaigns. Recommends additional training (if required) based on results.
Identifies, investigates and classifies security incidents. Determines root cause, and provides advice/recommendations on mitigation strategies and resolution.
Reviews network security architectures design. Provides guidance and support to IT staff on cybersecurity best practices and protocols aligned with IT Security policies.
Advises IT leadership regarding cybersecurity risks and initiatives, progress and gaps.
Assists with preparation and presentation of the cybersecurity risk management reports as well as cybersecurity maturity assessments.
Performs other related duties as assigned.
Qualifications:
Completion of a recognized degree or diploma program in an IT related discipline
Minimum five (5) years Information Technology experience, including minimum three (3) years in the area of Cybersecurity and IT risk management, executing multiple cybersecurity programs
Knowledge of cybersecurity frameworks, concepts and standards such as National Institute of Standards and Technology (NIST), Center for Internet Security (CIS) and cloud security, vulnerability and access management with the ability to apply knowledge and best practices
Working knowledge of cloud computing technologies and platforms such as Microsoft Azure, network infrastructure, Active Directory, firewalls, Azure security solutions, anti-virus, Endpoint Detection and Response (EDR) and Security Information and Event Management (SIEM) tools
Familiarity with attack vectors, vulnerabilities, and how they are used/initiated by malicious actors
Working knowledge and experience with vulnerability management tools such as Qualys or Tenable
Ability to independently plan and organize workload and meet tight deadlines
Ability to develop professional documents in accordance with standard operating procedures and processes
Ability to communicate effectively, both verbally and in writing, including excellent presentation skills
Ability to facilitate meetings, stakeholder workshops and vendor presentations
Ability to foster positive working relationships with partners and stakeholders, including managed service providers and external vendors
The ability to communicate proficiently in both official languages (English & French) is an asset, but is not required
The following are considered assets:
Possession of certificates or education related to information technology, IT infrastructure, Azure cloud services, or system administration including the following:
Certified Information Systems Security Professional (CISSP), or Certified Information Security Manager (CISM)
Certified in Governance of Enterprise IT (CGEIT)
Certified Risk and Information Systems Control (CRISC)
Certified Information Systems Security Officer (CISSO)
Certified Cloud Security Professional (CCSP)
Certified Ethical Hacker (CEH)
IT Infrastructure Library (ITIL) Foundations certification
Additional Information
Up to 2 permanent positions
Ability to communicate proficiently in both official languages (English & French) is an asset.
A satisfactory criminal record check and verification of education will be required for the successful candidate.
The WCB is committed to building a skilled, diverse workforce with equitable representation of Indigenous persons, visible minorities, persons with disabilities, women, 2SLGBTQ+ persons and members of other equity-seeking groups. Applicants are encouraged to indicate in their covering letter or resumé if they are a member of these groups.
The WCB recognizes that individuals may face barriers that hinder their full and equal participation in the workplace, and is committed to providing reasonable accommodation to all employees and candidates who are or may be disabled by one or more barriers in the workplace. Accommodations are available on request for candidates taking part in all aspects of the selection process.
The Workers Compensation Board promotes safety and health in Manitoba workplaces and aims to help prevent and reduce the occurrence of workplace injuries and disease. Working with its partners, the WCB promotes safe and healthy workplaces, facilitates recovery and return to work, provides compassionate and supportive compensation services for workers and employers, and ensures responsible financial stewardship.
WCBdoes encompasses what it means to work at the WCB. The WCB is proud to have employee benefits and programs that support financial and personal security, foster health and well-being, encourage involvement and support growth as an individual and member of the WCB community. The four categories of WCBdoes include: Security, Wellness, Engagement and Growth.
Are you interested in this job?
Questions about this role
Want AI Applyd to auto-apply to roles like this?
We tailor your resume per posting, fill the forms, and track replies for you.