Sr Cybersecurity & Operations Specialist
- Calgary, AB
- On-site
- Posted Sep 21, 2026
- 1 position
Opens an external site
- Employment type
- Full-time
- Experience level
- Senior · 5+ years
- Minimum education
- Professional degree
- Apply by
- Sep 27, 2026
- Posting language
- English
- Working hours
- 40 hours per week
Job summary
The Senior Cybersecurity & Operations Specialist will lead complex incident response investigations and oversee security platforms across global information systems. They will also manage security vendors, coordinate awareness programs, and drive continuous improvement in cloud and on-premises security controls.
Job details
Meet Vermilion We responsibly produce essential energy to support local and global needs while delivering long-term value to our people, shareholders, customers, partners and communities. Our people are fundamental to our success. As a global organization, Excellence, Trust, Respect and Responsibility are at the core of our vision and central to how we do business. Together, these core values create the foundation for our strong and collaborative culture. We prioritize health and safety, the environment, and profitability, in that order. Nothing is more important to us than the safety of the public and those who work with us, and the protection of our natural surroundings. The Opportunity Are you an experienced Cyber Security professional who can combine technical depth with strong business communication? Do you have experience leading investigations, digital forensics, security monitoring, penetration testing and security awareness programs across on-premises and cloud environments? We are hiring a Senior Cybersecurity & Operations Specialist for our Calgary head office. You will help protect Vermilion's global information systems by leading complex incident response and investigations, overseeing key security platforms and service providers, and translating cyber risk into clear actions for the business. You will also coordinate the security awareness program, manage security vendors, and drive continuous improvement across security operations, cloud security and defensive controls. What you will do Lead the investigation, response and documentation of complex cyber security incidents, working with internal teams, external security providers, vendors and business stakeholders. Conduct digital forensic investigations and analyze security alerts, logs, threat intelligence and other evidence to determine the nature, scope and impact of security events. Manage and continuously improve security monitoring and detection capabilities across SIEM, endpoint, identity, network and cloud security technologies. Oversee SOC, MxDR and other cyber security service providers, including escalations, service delivery reviews and corrective actions. Lead threat hunting, vulnerability management, penetration testing and security assessments, partnering with accountable teams to prioritize and remediate identified risks. Assess and strengthen security controls across on-premises infrastructure, Microsoft Azure, networks, endpoints, identity platforms and cloud services. Plan and deliver the corporate cyber security awareness program, including employee training, phishing simulations, targeted communications and follow-up activities. Translate cyber security risks, incidents and priorities into clear, practical recommendations for technical teams, business stakeholders and senior leaders. Manage cyber security vendors, contracts and initiatives, coordinating implementation activities, dependencies, risks and stakeholder communications. Develop security metrics, incident reports, risk assessments and management updates that support informed decision-making and continuous improvement. Maintain cyber security procedures, standards, policies, investigation records and operational documentation. Support cyber security governance, information protection, compliance, eDiscovery and litigation-related investigations in partnership with Legal and other stakeholders. Stay current on emerging threats, vulnerabilities, regulatory expectations and defensive technologies relevant to Vermilion’s global operations What you will bring A current and valid ISC2 Certified Information Systems Security Professional (CISSP) certification and active ISC2 membership. Proof of certification will be required. A diploma or degree in Cyber Security, Information Technology, Computer Science or a related discipline, or an equivalent combination of education and practical experience. Extensive experience in cyber security operations, including incident detection, escalation, investigation and response. Strong experience with SIEM and security operations technologies, such as Microsoft Sentinel, and with SOC, MxDR, MSSP or other third-party security providers. Hands-on experience with digital forensics, vulnerability management, security assessments, remediation tracking and formal risk documentation. Strong technical knowledge of networking, operating systems, identity, endpoints, firewalls and core security principles. Strong knowledge of on-premises and Microsoft Azure cloud infrastructure and related security controls. Hands-on experience deploying, managing and optimizing Microsoft Defender technologies, including Microsoft Defender for Cloud, across cloud and hybrid environments. Demonstrated ability to explain cyber risk clearly, influence practical action and communicate effectively with technical teams, business stakeholders and senior leaders. Strong analytical, project management, documentation and reporting skills, with sound judgment when handling sensitive incidents and information. Experience managing vendors, initiatives and multiple concurrent priorities. Additional Experience Considered an Asset Experience with cybersecurity governance, information protection, Microsoft Purview, eDiscovery or litigation investigation support. Experience with security technologies such as Zscaler, Quorum, Red Canary or Arctic Wolf. Experience conducting or supporting security assessments in operational technology environments, including industrial control systems, SCADA or other field-based technologies. Additional certifications in areas such as ethical hacking, incident handling, cloud security, threat intelligence or digital forensics. Other Key Details This is an office-based role requiring presence in Vermilion’s Calgary office five days per week. Occasional flexibility outside regular business hours may be required to support Vermilion’s global operations, including meetings or activities involving teams in other countries and time zones. Some international travel may be required. The successful candidate must be eligible to travel internationally for business purposes. What we offer Industry-competitive time off including vacation, flex days and office closures such as Friday afternoons during the summer Casual yet professional office environment with a relaxed dress code Opportunities to connect with others, including weekly company-provided breakfast Competitive short-term and long-term incentive programs aimed to recognize and reward Top-tier benefits program, including a generous flexible health spending account and savings plan program Onsite childcare available (fee-based) Company-sponsored volunteer opportunities and volunteer grants Why you’ll love working with us We care for each other, the environment and the company, and aim to enrich the communities in which we live and work We embrace new solutions across the business, allow space for creativity, and invest in innovation and technology We operate with honesty, transparency and fairness, and can be counted on to do what we say we will We invest in our employees, providing meaningful work and opportunities for training and professional development We have been focused on sustainability for more than a decade We are focused on the future: responsibly producing the oil and natural gas that is essential to energy security while exploring alternative energy options Vermilion is committed to diversity and inclusion, and aims to create a healthy, accessible and rewarding work environment that highlights our employees’ unique contributions to our company’s success. As an equal opportunity employer, we welcome all applications to help us build a diverse workforce that reflects the communities in which we live and work. Outstanding People. Outstanding Opportunities.
What you’ll do
The Senior Cybersecurity & Operations Specialist will lead complex incident response investigations and oversee security platforms across global information systems. They will also manage security vendors, coordinate awareness programs, and drive continuous improvement in cloud and on-premises security controls.
Requirements
Candidates must hold a valid CISSP certification and possess extensive experience in cybersecurity operations, incident detection, and response. A degree or diploma in a relevant field is required, along with strong technical knowledge of Microsoft Azure, networking, and security monitoring technologies.
Benefits
• Vacation • Flex days • Flexible health spending account • Savings plan program • Onsite childcare • Company-sponsored volunteer opportunities • Volunteer grants • Short-term incentive programs • Long-term incentive programs
Listed skills
- Microsoft Azure · Preferred
Other relevant skills
Identified from the job description. Confirm important requirements above.
- Cybersecurity
- Incident response
- Digital forensics
- Security monitoring
- Penetration testing
- Cloud security
- Microsoft Azure
- SIEM
- Vulnerability management
- Threat hunting
- Microsoft Defender
- Risk assessment
- Security awareness
- Vendor management
- Identity management
- Network security
- Project Management
- Incident Response
- Communication
- Management
- Operations
- Coordinating
- Information Systems
- Incident Reporting
- Training And Development
- Influencing Skills
- Influencing Without Authority
- Honesty
- Prioritization
- Decision Making
- Innovation
- Stakeholder Communications
- Continuous Improvement Process
- Firewall
- Cloud Infrastructure
- Cloud Security
- Information Technology
- Oil and Gas
- Risk Analysis
- Penetration Testing
- Vendor Management
- Creativity
- Security Controls
- Computer Science
- Cyber Security
- Vulnerability Management
- Operating Systems
- Lawsuits
- Investigation
- Cloud Services
Job areas
- Security & Safety
- Technology
- Energy
- Software
- Management & Leadership
- Cybersecurity Operations Analyst
- Scheduler / Operations Coordinator
- Stock Clerks
- Production, Planning, and Expediting Clerks
More jobs you can apply to directly
Similar opportunities posted by employers hiring on Jobs.ca, with no external application form.
Desjardins
Analyste d'affaires système(BSA) Guidewire
Direct employerEasy Apply- Hybrid
- Lévis, QC
- Posted Sep 21, 2026
Desjardins
Administrateur ou administratrice de plateforme TI - Senior
Direct employerEasy Apply- Hybrid
- Montréal, QC
- Posted Sep 17, 2026