Monitoring and Response Lead

Manitoba Hydro

Winnipeg

On-site

CAD 101,000 - 139,000

Full time

15 hours ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Competitive salary
Benefits package
Alternate Mondays off

Job summary

Manitoba Hydro is seeking a senior leader to head the Monitoring and Response team within Cyber Security Operations. You will guide threat monitoring, detection, and rapid response across IT and OT environments in a dynamic utility setting.

Responsibilities include building a high-performing team, coordinating with vendors, and ensuring continuous improvement of security monitoring and incident handling. Winnipeg-based with a potential 24/7 standby schedule.

Qualifications

  • Bachelor's degree in Computer Science or Engineering or related discipline and 6+ years of IT/ICS experience.
  • OR a 2-year diploma and 8+ years of IT/ICS experience.
  • Certifications such as CISSP, CISM, CRISC, OSCP or similar assets.

Responsibilities

  • Lead and develop the Monitoring and Response team with clear strategic priorities.
  • Deliver enterprise IT/OT cyber threat monitoring, detection, and response.
  • Coordinate incident response across internal teams and external providers.

Skills

Cybersecurity monitoring
Leadership
Incident response
Team development
Stakeholder communication

Education

Bachelor's in CS or Eng
Security certifications asset

Tools

SIEM
SOAR
EDR/XDR

Job description

Manitoba Hydro is consistently recognized as one of Manitoba's Top Employers! We are a leader among energy companies in North America, recognized for providing highly reliable service and exceptional customer satisfaction. Join our team of Manitoba's best as we continue to build a company that champions safety, supports innovation, and delivers on our commitment to customer service - while actively fostering a diverse, equitable, and inclusive workplace reflective of the communities we serve.

  • Competitive salary and comprehensive benefits package.
  • Enjoy a work schedule that typically provides every second Monday off (subject to location and operational requirements), supporting a balanced approach to work, family life and community.
Position Overview:

Under the general direction of the Cyber Security Operations Department Manager and as a key member of the Cyber Security Operations Department leadership team, lead and develop the Monitoring and Response team, deliver corporate-wide (IT&OT) cyber threat monitoring/detection/response services, continuously tune and enhance alerts, maximize cyber monitoring services contract value, advance monitoring and response capabilities, support and enhance the SOC technology environment, and keep abreast of cybersecurity developments.

Responsibilities:
  • Lead and develop the Monitoring and Response team: Translate departmental goals into clear strategic and operational priorities. Foster an inclusive, engaged, and high-performing culture where people can thrive, grow, and contribute to shared success. Build team capability and resiliency through coaching, mentoring, hiring, and development opportunities, creating a team that attracts, develops, and retains top talent. Oversee work prioritization, delegation, service continuity, training, performance management, and continuous improvement.
  • Deliver corporate-wide (IT&OT) cyber threat monitoring, detection, and response services: Lead the delivery and continuous improvement of enterprise monitoring, detection, investigation, and incident response capabilities across IT and OT environments. Ensure cyber threats, events, and incidents are effectively identified, analyzed, contained, eradicated, and recovered from with speed and with continuously improving measures. Lead and coordinate response activities across internal teams, service providers, and stakeholders to minimize risk and business impact while maintaining monitoring and response capabilities aligned with organizational priorities. Provide leadership during critical cyber incidents and urgent operational events. May be required to participate in a rotating 24/7 standby program. Act as the primary contract manager and escalation point for external cyber monitoring service providers, fostering strong working relationships and ensuring effective collaboration, issue resolution, service performance, and continuous improvement.
  • Exercise program: Lead a cyber security exercise program that tests and improves the organization's readiness to detect, respond to, contain, eradicate, and recover from cyber incidents. Coordinate exercises, including procurement, involving internal teams, service providers, executives, and external stakeholders, ensuring lessons learned are translated into measurable improvements to plans, processes, capabilities, and response effectiveness.
  • Continuously tune and enhance alerts: Lead continuous detection effectiveness enhancement by tuning alerts, use cases, and workflows to improve fidelity, reduce false positives, increase visibility of emerging threats, and optimize analyst efficiency. Identify alert use case gaps revealed through alert and incident response activities, and work with CSO Technology Management to remediate them. Ensure CSO Technology Management is kept informed of any changes to alert use cases
  • Maximize Cyber Monitoring Services contract value: Oversee the delivery and performance of contracted monitoring services, ensuring service levels, capabilities, reporting, and outcomes align with organizational requirements. Drive continuous improvement and maximize value from security monitoring investments.
  • Support security control enhancements: Support the identification, planning, implementation, and sustainment of monitoring and response control enhancements identified through the Cyber Roadmap, enterprise assessments, audits, incidents, and industry best practices. Drive measurable improvements in detection, response, resilience, and cyber maturity.
  • Support and enhance the SOC technology environment: Provide operational leadership, requirements, and subject matter expertise to sustain, optimize, and expand the security operations technology portfolio. Work closely with Cyber Security Operations Technology Management, vendors, and stakeholders to ensure monitoring, detection, investigation, and response tools are effectively deployed, integrated, maintained, and aligned with business and security requirements and keep pace with evolving cyber threats.
  • Keep abreast of cybersecurity developments outside of MH: Develop and maintain effective relationships with industry peers, partners, and standards bodies to exchange information and stay informed of emerging threats, technologies, regulations, and best practices. Maintain awareness of NERC and cyber security requirements and communicate relevant developments to enterprise stakeholders.
Qualifications:
  • A four-year degree in Computer Science or Engineering or related discipline from a university of recognized standing plus a minimum of six years' related information technology (IT) or industrial control system (ICS) Support experience;
  • OR
  • A two-year diploma in Electrical, Electronic, Computer Technology, related discipline from an institute of recognized standing plus a minimum of eight years'related IT or ics Support experience.
  • Certifications such as Cyber Security specific (CISSP, CISM, CRISC, OSCP, CEH, CGIH, GPE, SANS, ISAACA CSX Cybersecurity Practitioner (CSX-P), (ICS)2 Entry -Level Cybersecurity certification, technology specific (SIEM, XDR, etc.), etc.), network related (CCNA, etc.), cloud platform related (M365, Azure, etc.), operating system related (Linux, Windows, Unix, Apple IOS), management related (PMP, emergency management, etc.), software/application security, etc. would be an asset.
  • Demonstrated knowledge and experience in cyber security monitoring, detection, investigation, and incident response across information technology (IT), operational technology (OT), and industrial control system (ICS) environments. This includes experience with Security Information and Event Management (SIEM), Security Orchestration, Automation and Response (SOAR), endpoint and extended detection and response (EDR/XDR), network detection technologies, threat intelligence, detection use-case development and tuning, security analytics, incident response processes, and automated or manual containment capabilities.
  • Demonstrated ability to assess monitoring coverage, identify detection gaps, improve alert fidelity, and use operational metrics and lessons learned to continuously improve monitoring and response effectiveness.
  • Demonstrated understanding of cyber security concepts, controls, frameworks and standards including NIST and NERC CIP.
  • Demonstrated effectiveness in building and leading teams through resolving complex, urgent, and potentially high impact cyber events. Demonstrated ability to build and maintain harmonious working relationships with staff across the enterprise at all levels.
  • Demonstrated ability to communicate effectively verbally and in writing. Demonstrated ability to deliver reports, recommendations, and presentations with a drive for continuous improvement and documentation.
  • Must complete Manitoba Hydro Standards of Conduct training.
  • Must possess a valid Province of Manitoba Driver's Licence.
  • NERC CIP Training is required, must be completed prior to transfer date, and renewed annually.
  • Obtain and maintain a current Personnel Risk Assessment and a "Clear" security rating in accordance with Manitoba Hydro policy P513.
  • Reside within the Winnipeg headquarters zone or within a reasonable travelling distance from the assembly point during the periods of standby.
  • Must maintain or be eligible for SECRET clearance from the Government of Canada.
Salary Range

Starting salary will be commensurate with qualifications and experience. The range for the classification is $52.88-$72.45 Hourly, $101,332.40-$138,828.30 Annually.

We appreciate your interest in Manitoba Hydro and thank all applicants. Only those selected for the next stage of the selection process will be contacted.

If you require accommodations during the recruitment process or need this posting in an accessible format, please let us know - we're committed to a barrier-free experience for all candidates.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Monitoring and Response Lead
Monitoring and Response Lead

Kibbi • Winnipeg

On-site
CAD 101,000 - 139,000
Defined-benefit pension
Every second Monday off
Competitive salary
SOC Technology Management Lead
SOC Technology Management Lead

Manitoba Hydro • Winnipeg

On-site
CAD 101,000 - 139,000
Competitive salary
Comprehensive benefits package
Every second Monday off
SOC Technology Management Lead
SOC Technology Management Lead

Kibbi • Winnipeg

On-site
CAD 110,000 - 151,000
Competitive salary and benefits
Defined-benefit pension plan
Every second Monday off
Cyber Monitoring & Response Lead
Cyber Monitoring & Response Lead

Manitoba Hydro • Winnipeg

On-site
CAD 101,000 - 139,000
Competitive salary
Benefits package
Alternate Mondays off
Senior Cyber Monitoring & Response Lead
Senior Cyber Monitoring & Response Lead

Kibbi • Winnipeg

On-site
CAD 101,000 - 139,000
Defined-benefit pension
Every second Monday off
Competitive salary
AEMS Power System Applications Engineer
AEMS Power System Applications Engineer

Kibbi Technologies Inc. • Winnipeg

On-site
CAD 101,000 - 139,000
Competitive salary
Defined-benefit pension
Nine-day work cycle
Professional Engineer (Electrical/Computer)
Professional Engineer (Electrical/Computer)

Manitoba Hydro • Winnipeg

On-site
CAD 101,000 - 139,000
Competitive salary
Comprehensive benefits package
Nine-day work cycle
Project Engineer
Project Engineer

Manitoba Hydro • Winnipeg

On-site
CAD 101,000 - 139,000
Competitive salary and benefits
Nine-day work cycle
Comprehensive benefits package
Respectful Workplace Advisor
Respectful Workplace Advisor

CPHR Manitoba • Winnipeg

On-site
CAD 93,000 - 129,000
Competitive salary
Defined-benefit pension
Nine-day work cycle
Interrupting Equipment Maintenance Engineer (Electrical)
Interrupting Equipment Maintenance Engineer (Electrical)

Kibbi • Winnipeg

On-site
CAD 93,000 - 129,000
Competitive salary
Comprehensive benefits
Defined-benefit pension
+1