The Manitoba Public Insurance Corporation

Cybersecurity & IT Risk and Compliance Analyst

Job Locations CA-MB-Winnipeg
Job ID
2026-7254
# of Openings
1
Category
Information Technology
Posting Close Date
9/26/2026
Type
Full-Time
Placement
Permanent
Duration
Full-Time
French Language Services Required
No
Position eligible for Flexible Work?
Hybrid
Security Clearance Required
No

Overview

As a Cybersecurity and IT Risk and Compliance Analyst you are responsible for working with the Information Security and IT Risk Management leaders to develop and maintain Cybersecurity and IT Risk and Compliance Management governance, frameworks, policies and processes.  You will work with operational teams to provide risk and compliance management advisory, coordination, facilitation and oversight services to enable IT and business leaders to effectively and efficiently manage operational risks and meet compliance requirements within the domain or business units. 

Responsibilities

  • Assists the Business and Information Technology (IT) leaders in conducting business impact analysis and maintaining a map of business processes to information technology.
  • Works with IT leaders to develop and maintain IT Risk Taxonomies.
  • Works with IT leaders to perform Risk and Control Assessments (RCAs) and response planning for cybersecurity and IT controls.
  • Assists business and IT leaders in conducting Change Risk Assessments for material changes in the IT environment.
  • Works with business and IT leaders to conduct risk scenario analysis and identify emerging cybersecurity and technology risks.
  • Assists IT leaders to identify and action internal and external risk loss events.
  • Develops and maintains the IT Risk Register.
  • Conducts periodic reporting of the cybersecurity and IT Risk Profile to business and IT leaders.
  • Provides objective and independent assessment of first Line Risk Management activities
  • Works with business and IT leaders to develop and maintain an inventory of external requirements and the annual IT Compliance Plan.
  • Works with IT leaders to design and implement IT controls and conduct periodic control self-assessments and IT third-party service provider control assessments.
  • Logs, monitors and reports control issues, actions and exceptions.
  • Performs independent compliance assessments.
  • Develops and maintains the inventory of internal controls.
  • Coordinates and supports the third-party audit function (internal/external) for the regulatory test cycle.
  • Coordinates and prepares management responses to audit findings and recommendations.
  • Facilitates IT process governance, management and improvement.
  • Develops and maintains the Risk Management process and tools, including third-party risk management.
  • Coordinates the integration of risks with Enterprise Risk Management.
  • Works with IT leaders to develop and maintain the Cybersecurity and IT Risk and Compliance Management framework, policies, standards, processes, tools and best practices.

Qualifications

Education and Experience

 

  • University degree in Computer Science or a related discipline from a recognized university or college.
  • Five years of experience in Information Technology and/or Cybersecurity.

OR

  • A two-year diploma in a relevant field from an accredited institution.
  • Seven years of experience in Information Technology and/or Cybersecurity

 In addition to:

  • A professional certification or equivalent from a recognized education institution or company relevant to audit or risk, including:
    • Certified in Risk and Information Systems Control (CRISC)
    • Certified Information Security Manager (CISM)
    • Certified Information Systems Auditor (CISA)
    • Certified in Governance of Enterprise IT (CGEIT)

Technical Knowledge & Skills:

  • Knowledge of industry risk and compliance policies, procedures and best practices.
  • Ability to relate to others with all levels of technical competency.
  • Knowledge of IT process and control frameworks such as COBIT, NIST CSF, ISO 27002, ITIL, PMI, etc.

Employee Benefits

Health benefits

We offer a comprehensive health benefits program that includes:

  • flexible health, dental and vision plans
  • health spending account
  • travel health coverage
  • other extended health benefits such as ambulance, massage and physiotherapy

Financial security

In an effort to support financial security, we offer:

  • registered pension plan
  • group, dependent, and optional life insurance coverage
  • sick leave to cover short-term disability
  • long-term disability

Wellness

We offer programs that focus on how to better achieve a balance between work and personal commitments, as well as maintain a healthy workplace culture. This includes:

  • vacation entitlement
  • maternity, parental and adoptive leaves
  • bereavement and family responsibility leaves
  • employee and family assistance program
  • mental-health programming
  • onsite employee gym facility (Cityplace)
  • discounted gym memberships
  • wellness account

Diversity and inclusion

Manitoba Public Insurance believes that diversity and inclusion strengthens us. We consider ourselves to be a barrier-free organization where individual values, beliefs and practices are respected and appreciated for the diversity they bring to our work life.

 

Employee recognition

It’s important to recognize our employees for their contributions. Not only do we recognize employees as they achieve milestone years in their careers, we also have several outlets for leaders and peers to reward each other for work well done.

 

Professional development

We want our employees to grow, which is why we offer support in keeping their skills up to date. We offer in-house training, professional development and an educational assistance program.

 

Safety and health

In an effort to encourage a safe and healthy work environment, we offer various safety, health and workplace policies and programs along with technical expertise and assistance to support employee activities in safety and health.

Options

Sorry the Share function is not working properly at this moment. Please refresh the page and try again later.
Share on your newsfeed