Cyber Security Advisor - Exposure Management
- Calgary, AB
- Hybrid
- Posted Sep 19, 2026
- 1 position
$51–$68 / hour
Opens an external site
- Employment type
- Full-time
- Experience level
- Senior · 8+ years
- Minimum education
- Professional degree
- Apply by
- Oct 16, 2026
- Posting language
- English
- Working hours
- 40 hours per week
- Seniority
- Mid-Senior level
Job summary
The advisor will drive the City's cyber security exposure management program by identifying and prioritizing vulnerabilities and misconfigurations for treatment. They will provide strategic advisory services and coordinate remediation efforts across diverse business units and technology teams.
Job details
If you are committed to public service, enjoy collaborating with others, share our values and have a desire to learn and grow, join The City of Calgary. City employees deliver the services, run the programs and operate the facilities which make a difference in our community. We support work-life balance, promote physical and psychological safety, and offer competitive wages, pensions, and benefits. Together we make Calgary a great place to make a living, a great place to make a life. The City is committed to fostering a respectful, inclusive and equitable workplace which is representative of the community we serve. We welcome those who have demonstrated a commitment to upholding the values of equity, diversity, inclusion, anti-racism and reconciliation. Applications are encouraged from members of groups that are historically disadvantaged and underrepresented. Accommodations are available during the hiring process, upon request. The City of Calgary's Cyber Security Business Unit safeguards the information, technology, and operational systems that enable the delivery of services to Calgarians. As the Cyber Security Advisor, you will be responsible for authoritative and strategic advisory services pertaining to cyber security exposures affecting enterprise assets including data, information, processes and technology systems. Specifically, you will drive the City's cyber security exposure management program, ensuring vulnerabilities, weaknesses, misconfigurations, and other exposures are identified and prioritized for appropriate treatment plans, while contributing more broadly to the City's Cyber Security mandate and roadmap. Primary duties include: Serve as Cyber Security's point of contact for security vulnerability and exposure management activities, including scanning and testing readiness, environment and asset coverage, and platform administration. Provide authoritative advisory guidance to Cyber Security's governance channels and business leadership regarding opportunities, objectives, and performance within the exposure management program. Develop and apply prioritization criteria for exposures, incorporating enterprise context and asset criticality, threat intelligence, exploitability, and compensating controls. In collaboration with Cyber Security colleagues and City partners, maintain and execute a robust exposure management program documentation plan, including remediation tracking, standards, procedures, compliance and assurance evidence, performance measures and other metrics. Coordinate resources and efforts from diverse City business units, technology teams, and external parties through the exposure management lifecycle from discovery and validation through remediation, exception management, and verification. Qualifications A diploma in Computer Science, Information Technology, Cyber Security, Business Administration, or a related field and at least 8 years of experience in cyber security, vulnerability or risk management, cyber security architecture, software engineering, system administration or a related function; OR A degree in Computer Science, Information Technology, Cyber Security, Business Administration, or a related field and at least 5 years of experience in cyber security, vulnerability or risk management, cyber security architecture, software engineering, system administration, or a related function. One or more recognized, current cybersecurity or risk management certifications such as Certified Information Systems Security Professional (CISSP), Certified Cloud Security Professional (CCSP), Certified Information Security Manager (CISM), or Certified in Risk and Information Systems Control (CRISC) are required. Demonstrated experience at a senior level in a minimum of two cyber security domains (for example: cyber security risk management, cyber security architecture, data security, cyber security operations, industrial control systems security, application security, vulnerability management, continuous threat exposure management, penetration testing) is required. Proven experience in continuous monitoring, automated logging, and cloud-native environments in complex, public sector, or highly regulated environments would be considered an asset. Demonstrated Project Management skills will also be an asset. Success in this position requires empathy, highly developed communication and relationship building skills, a well-developed ability to influence without authority and build a shared vision for security outcomes. Working Conditions: Occasional coordination with vendors, project teams, or other interested parties outside of regular business hours may be required to support assessments, deadlines, or time-sensitive advisory activities. Pre-employment Requirements A security clearance will be conducted. Successful applicants must provide proof of qualifications. Workstyle This position may be eligible to work from home for at least part of the time as one of several flexible work options available to City employees. These arrangements depend on the operational requirements of the role, employee suitability, and are subject to change based on operational needs and corporate direction.
What you’ll do
The advisor will drive the City's cyber security exposure management program by identifying and prioritizing vulnerabilities and misconfigurations for treatment. They will provide strategic advisory services and coordinate remediation efforts across diverse business units and technology teams.
Requirements
Requires a diploma with 8 years of experience or a degree with 5 years of experience in cyber security or a related field. Must hold at least one recognized certification such as CISSP, CCSP, CISM, or CRISC and demonstrate senior-level experience in at least two cyber security domains.
Benefits
• Work-life balance • Competitive wages • Pensions • Benefits
Listed skills
- Risk Management · Preferred
- Project management · Preferred
- Relationship Building · Preferred
Other relevant skills
Identified from the job description. Confirm important requirements above.
- Cyber Security Exposure Management
- Vulnerability Management
- Risk Management
- Cyber Security Architecture
- Threat Intelligence
- Compliance and Assurance
- Project Management
- Cloud-native Environments
- Continuous Monitoring
- Automated Logging
- Relationship Building
- Stakeholder Influence
Job areas
- Security & Safety
- Technology
- Government & Public Sector
- Management & Leadership
- Consulting
More jobs you can apply to directly
Similar opportunities posted by employers hiring on Jobs.ca, with no external application form.
Desjardins
Analyste d'affaires système(BSA) Guidewire
Direct employerEasy Apply- Hybrid
- Lévis, QC
- Posted Sep 21, 2026
Desjardins
Administrateur ou administratrice de plateforme TI - Senior
Direct employerEasy Apply- Hybrid
- Montréal, QC
- Posted Sep 17, 2026
Canadian Pork Council
Senior Software Developer
SponsoredDirect employerEasy Apply- Hybrid
- Posted Sep 11, 2026