Back to job search
Manitoba Public Insurance logo
Manitoba Public InsuranceVerified Job Source

Cybersecurity & IT Risk and Compliance Analyst

  • Winnipeg, MB
  • Hybrid
  • Posted Sep 8, 2026
  • 1 position

Opens an external site

Employment type
Full-time
Experience level
Senior · 5+ years
Minimum education
Professional degree
Apply by
Oct 8, 2026
Posting language
English
Working hours
40 hours per week
Seniority
Mid-Senior level

Job summary

Develop and maintain cybersecurity and IT risk and compliance governance frameworks, policies, and processes. Provide advisory and oversight services to help business and IT leaders manage operational risks and meet compliance requirements.

Job details

Overview As a Cybersecurity and IT Risk and Compliance Analyst you are responsible for working with the Information Security and IT Risk Management leaders to develop and maintain Cybersecurity and IT Risk and Compliance Management governance, frameworks, policies and processes. You will work with operational teams to provide risk and compliance management advisory, coordination, facilitation and oversight services to enable IT and business leaders to effectively and efficiently manage operational risks and meet compliance requirements within the domain or business units. Responsibilities Assists the Business and Information Technology (IT) leaders in conducting business impact analysis and maintaining a map of business processes to information technology. Works with IT leaders to develop and maintain IT Risk Taxonomies. Works with IT leaders to perform Risk and Control Assessments (RCAs) and response planning for cybersecurity and IT controls. Assists business and IT leaders in conducting Change Risk Assessments for material changes in the IT environment. Works with business and IT leaders to conduct risk scenario analysis and identify emerging cybersecurity and technology risks. Assists IT leaders to identify and action internal and external risk loss events. Develops and maintains the IT Risk Register. Conducts periodic reporting of the cybersecurity and IT Risk Profile to business and IT leaders. Provides objective and independent assessment of first Line Risk Management activities. Works with business and IT leaders to develop and maintain an inventory of external requirements and the annual IT Compliance Plan. Works with IT leaders to design and implement IT controls and conduct periodic control self-assessments and IT third-party service provider control assessments. Logs, monitors and reports control issues, actions and exceptions. Performs independent compliance assessments. Develops and maintains the inventory of internal controls. Coordinates and supports the third-party audit function (internal/external) for the regulatory test cycle. Coordinates and prepares management responses to audit findings and recommendations. Facilitates IT process governance, management and improvement. Develops and maintains the Risk Management process and tools, including third-party risk management. Coordinates the integration of risks with Enterprise Risk Management. Works with IT leaders to develop and maintain the Cybersecurity and IT Risk and Compliance Management framework, policies, standards, processes, tools and best practices. Qualifications University degree or four-year college diploma in Computer Science or a related discipline from a recognized university or college. Five years of experience in Information Technology and/or Cybersecurity. OR A two-year diploma in a relevant field from an accredited institution. Seven years of experience in Information Technology and/or Cybersecurity In addition to: A professional certification or equivalent from a recognized education institution or company relevant to audit or risk, including: Certified in Risk and Information Systems Control (CRISC) Certified Information Security Manager (CISM) Certified Information Systems Auditor (CISA) Certified in Governance of Enterprise IT (CGEIT) Technical Knowledge & Skills: Knowledge of industry risk and compliance policies, procedures and best practices. Ability to relate to others with all levels of technical competency. Knowledge of IT process and control frameworks such as COBIT, NIST CSF, ISO 27002, ITIL, PMI, etc. Employee Benefits Health benefits We offer a comprehensive health benefits program that includes: flexible health, dental and vision plans health spending account travel health coverage other extended health benefits such as ambulance, massage and physiotherapy Financial security In an effort to support financial security, we offer: registered pension plan group, dependent, and optional life insurance coverage critical illness insurance sick leave to cover short-term disability long-term disability Wellness We offer programs that focus on how to better achieve a balance between work and personal commitments, as well as maintain a healthy workplace culture. This includes: vacation entitlement flexible work arrangement for eligible positions maternity, parental and adoptive leaves bereavement and family responsibility leaves employee and family assistance program mental-health programming lunch-and-learn offerings discounted gym memberships and wellness account Diversity and inclusion Manitoba Public Insurance believes that diversity and inclusion strengthens us. We consider ourselves to be a barrier-free organization where individual values, beliefs and practices are respected and appreciated for the diversity they bring to our work life. Employee recognition It’s important to recognize our employees for their contributions. Not only do we recognize employees as they achieve milestone years in their careers, we also have several outlets for leaders and peers to reward each other for work well done. Professional development We want our employees to grow, which is why we offer support in keeping their skills up-to-date. We offer in-house training, professional development and an educational assistance program. Safety and health In an effort to encourage a safe and healthy work environment, we offer various safety, health and workplace policies and programs along with technical expertise and assistance to support employee activities in safety and health.

What you’ll do

Develop and maintain cybersecurity and IT risk and compliance governance frameworks, policies, and processes. Provide advisory and oversight services to help business and IT leaders manage operational risks and meet compliance requirements.

Requirements

Requires a university degree or diploma in Computer Science or a related field with 5 to 7 years of experience in IT or Cybersecurity. Professional certification such as CRISC, CISM, CISA, or CGEIT is also required.

Benefits

  • Health Benefits
  • Dental Plan
  • Vision Plan
  • Health Spending Account
  • Travel Health Coverage
  • Massage And Physiotherapy
  • Registered Pension Plan
  • Life Insurance
  • Critical Illness Insurance
  • Sick Leave
  • Long-term Disability
  • Vacation Entitlement
  • Flexible Work Arrangement
  • Maternity, Parental And Adoptive Leaves
  • Bereavement And Family Responsibility Leaves
  • Employee And Family Assistance Program
  • Mental-health Programming
  • Lunch-and-learn Offerings
  • Discounted Gym Memberships
  • Wellness Account
  • Professional Development
  • Educational Assistance Program

Listed skills

  • Control · Preferred
  • Technical · Preferred
  • analysis · Preferred
  • Health · Preferred
  • Compliance · Preferred
  • Risk Management · Preferred
  • safety · Preferred
  • management · Preferred
  • Process · Preferred
  • Development · Preferred
  • Audit · Preferred
  • Flexible · Preferred

Other relevant skills

Identified from the job description. Confirm important requirements above.

  • Cybersecurity Governance
  • IT Risk Management
  • Compliance Management
  • Business Impact Analysis
  • Risk And Control Assessments
  • Risk Scenario Analysis
  • IT Risk Register
  • Third-party Risk Management
  • Control Self-assessments
  • Audit Coordination
  • COBIT
  • NIST CSF
  • ISO 27002
  • ITIL
  • PMI

Job areas

  • Security & Safety
  • Technology
  • Management & Leadership
  • Government & Public Sector
  • Finance & Accounting