Monitoring and Response Lead

Kibbi

Winnipeg

On-site

CAD 101,000 - 139,000

Full time

4 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Defined-benefit pension
Every second Monday off
Competitive salary

Job summary

Manitoba Hydro in Winnipeg, MB, is seeking a Monitoring and Response Lead to guide the Cyber Security Operations Department's Monitoring and Response team. You will deliver enterprise IT/OT threat monitoring, detection, and incident response, and drive improvements across the SOC technology stack.

The role requires building a high-performing team, coordinating with internal and external partners, and may include 24/7 standby.

Qualifications

  • Demonstrated knowledge and experience in cyber security monitoring, detection, investigation, and incident response across IT/OT/ICS.
  • Ability to lead and develop a high-performing Monitoring & Response team.
  • Experience with SIEM, SOAR, EDR/XDR and security analytics.

Responsibilities

  • Lead and develop the Monitoring and Response team with strategic priorities.
  • Deliver enterprise IT/OT monitoring, detection and response services.
  • Coordinate response activities across internal teams and external providers.

Skills

Cybersecurity monitoring
Incident response
Threat detection
Team leadership

Education

Four-year degree in Computer Science or Engineering
Two-year diploma in Electrical/Electronic/Computer Technology

Tools

SIEM
SOAR
EDR/XDR
Threat intelligence

Job description

Monitoring and Response Lead

Winnipeg, MB


Manitoba Hydro is consistently recognized as one of Manitoba's Top Employers! We are a leader among energy companies in North America, recognized for providing highly reliable service and exceptional customer satisfaction. Join our team of Manitoba's best as we continue to build a company that champions safety, supports innovation, and delivers on our commitment to customer service - while actively fostering a diverse, equitable, and inclusive workplace reflective of the communities we serve.


Great Benefits


  • Competitive salary and comprehensive benefits package.

  • Defined-benefit pension plan for long-term financial security.

  • Enjoy a work schedule that typically provides every second Monday off (subject to location and operational requirements), supporting a balanced approach to work, family life and community.


Position Overview:

Under the general direction of the Cyber Security Operations Department Manager and as a key member of the Cyber Security Operations Department leadership team, lead and develop the Monitoring and Response team, deliver corporate-wide (IT&OT) cyber threat monitoring/detection/response services, continuously tune and enhance alerts, maximize cyber monitoring services contract value, advance monitoring and response capabilities, support and enhance the SOC technology environment, and keep abreast of cybersecurity developments.


Responsibilities:


  • Lead and develop the Monitoring and Response team: Translate departmental goals into clear strategic and operational priorities. Foster an inclusive, engaged, and high-performing culture where people can thrive, grow, and contribute to shared success. Build team capability and resiliency through coaching, mentoring, hiring, and development opportunities, creating a team that attracts, develops, and retains top talent. Oversee work prioritization, delegation, service continuity, training, performance management, and continuous improvement.

  • Deliver corporate-wide (IT&OT) cyber threat monitoring, detection, and response services: Lead the delivery and continuous improvement of enterprise monitoring, detection, investigation, and incident response capabilities across IT and OT environments. Ensure cyber threats, events, and incidents are effectively identified, analyzed, contained, eradicated, and recovered from with speed and with continuously improving measures. Lead and coordinate response activities across internal teams, service providers, and stakeholders to minimize risk and business impact while maintaining monitoring and response capabilities aligned with organizational priorities. Provide leadership during critical cyber incidents and urgent operational events. May be required to participate in a rotating 24/7 standby program. Act as the primary contract manager and escalation point for external cyber monitoring service providers, fostering strong working relationships and ensuring effective collaboration, issue resolution, service performance, and continuous improvement.

  • Exercise program: Lead a cyber security exercise program that tests and improves the organization's readiness to detect, respond to, contain, eradicate, and recover from cyber incidents. Coordinate exercises, including procurement, involving internal teams, service providers, executives, and external stakeholders, ensuring lessons learned are translated into measurable improvements to plans, processes, capabilities, and response effectiveness.

  • Continuously tune and enhance alerts: Lead continuous detection effectiveness enhancement by tuning alerts, use cases, and workflows to improve fidelity, reduce false positives, increase visibility of emerging threats, and optimize analyst efficiency. Identify alert use case gaps revealed through alert and incident response activities, and work with CSO Technology Management to remediate them. Ensure CSO Technology Management is kept informed of any changes to alert use cases.

  • Maximize Cyber Monitoring Services contract value: Oversee the delivery and performance of contracted monitoring services, ensuring service levels, capabilities, reporting, and outcomes align with organizational requirements. Drive continuous improvement and maximize value from security monitoring investments.

  • Support security control enhancements: Support the identification, planning, implementation, and sustainment of monitoring and response control enhancements identified through the Cyber Roadmap, enterprise assessments, audits, incidents, and industry best practices. Drive measurable improvements in detection, response, resilience, and cyber maturity.

  • Support and enhance the SOC technology environment: Provide operational leadership, requirements, and subject matter expertise to sustain, optimize, and expand the security operations technology portfolio. Work closely with Cyber Security Operations Technology Management, vendors, and stakeholders to ensure monitoring, detection, investigation, and response tools are effectively deployed, integrated, maintained, and aligned with business and security requirements and keep pace with evolving cyber threats.

  • Keep abreast of cybersecurity developments outside of MH: Develop and maintain effective relationships with industry peers, partners, and standards bodies to exchange information and stay informed of emerging threats, technologies, regulations, and best practices. Maintain awareness of NERC and cyber security requirements and communicate relevant developments to enterprise stakeholders.


Qualifications:


  • A four-year degree in Computer Science or Engineering or related discipline from a university of recognized standing plus a minimum of six years' related information technology (IT) or industrial control system (ICS) Support experience;

  • OR

  • A two-year diploma in Electrical, Electronic, Computer Technology, related discipline from an institute of recognized standing plus a minimum of eight years'related IT or ICT Support experience.

  • Certifications such as Cyber Security specific (CISSP, CISM, CRISC, OSCP, CEH, CGIH, GPE, SANS, ISAACA CSX Cybersecurity Practitioner (CSX-P), (ICS)2 Entry -Level Cybersecurity certification, technology specific (SIEM, XDR, etc.), network related (CCNA, etc.), cloud platform related (M365, Azure, etc.), operating system related (Linux, Windows, Unix, Apple IOS), management related (PMP, emergency management, etc.), software/application security, etc. would be an asset.

  • Demonstrated knowledge and experience in cyber security monitoring, detection, investigation, and incident response across information technology (IT), operational technology (OT), and industrial control system (ICS) environments. This includes experience with Security Information and Event Management (SIEM), Security Orchestration, Automation and Response (SOAR), endpoint and extended detection and response (EDR/XDR), network detection technologies, threat intelligence, detection use-case development and tuning, security analytics, incident response processes, and automated or manual containment capabilities.

  • Demonstrated ability to assess monitoring coverage, identify detection gaps, improve alert fidelity, and use operational metrics and lessons learned to continuously improve monitoring and response effectiveness.

  • Demonstrated understanding of cyber security concepts, controls, frameworks and standards including NIST and NERC CIP.

  • Demonstrated effectiveness in building and leading teams through resolving complex, urgent, and potentially high impact cyber events. Demonstrated ability to build and maintain harmonious working relationships with staff across the enterprise at all levels.

  • Demonstrated ability to communicate effectively verbally and in writing. Demonstrated ability to deliver reports, recommendations, and presentations with a drive for continuous improvement and documentation.

  • Must complete Manitoba Hydro Standards of Conduct training.

  • Must possess a valid Province of Manitoba Driver's Licence.

  • NERC CIP Training is required, must be completed prior to transfer date, and renewed annually.

  • Obtain and maintain a current Personnel Risk Assessment and a \"Clear\" security rating in accordance with Manitoba Hydro policy P513.

  • Reside within the Winnipeg headquarters zone or within a reasonable travelling distance from the assembly point during the periods of standby.

  • Must maintain or be eligible for SECRET clearance from the Government of Canada.


Salary Range

Starting salary will be commensurate with qualifications and experience. The range for the classification is $52.88-$72.45 Hourly, $101,332.40-$138,828.30 Annually.


Application deadline:

OCTOBER 9, 2026.


We appreciate your interest in Manitoba Hydro and thank all applicants. Only those selected for the next stage of the selection process will be contacted.


If you require accommodations during the recruitment process or need this posting in an accessible format, please let us know - we're committed to a barrier-free experience for all candidates.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Monitoring and Response Lead
Monitoring and Response Lead

Manitoba Hydro • Winnipeg

On-site
CAD 101,000 - 139,000
Competitive salary
Benefits package
Alternate Mondays off
SOC Technology Management Lead
SOC Technology Management Lead

Manitoba Hydro • Winnipeg

On-site
CAD 101,000 - 139,000
Competitive salary
Comprehensive benefits package
Every second Monday off
SOC Technology Management Lead
SOC Technology Management Lead

Kibbi • Winnipeg

On-site
CAD 110,000 - 151,000
Competitive salary and benefits
Defined-benefit pension plan
Every second Monday off
Cyber Monitoring & Response Lead
Cyber Monitoring & Response Lead

Manitoba Hydro • Winnipeg

On-site
CAD 101,000 - 139,000
Competitive salary
Benefits package
Alternate Mondays off
Senior Cyber Monitoring & Response Lead
Senior Cyber Monitoring & Response Lead

Kibbi • Winnipeg

On-site
CAD 101,000 - 139,000
Defined-benefit pension
Every second Monday off
Competitive salary
AEMS Power System Applications Engineer
AEMS Power System Applications Engineer

Kibbi Technologies Inc. • Winnipeg

On-site
CAD 101,000 - 139,000
Competitive salary
Defined-benefit pension
Nine-day work cycle
Professional Engineer (Electrical/Computer)
Professional Engineer (Electrical/Computer)

Manitoba Hydro • Winnipeg

On-site
CAD 101,000 - 139,000
Competitive salary
Comprehensive benefits package
Nine-day work cycle
Respectful Workplace Advisor
Respectful Workplace Advisor

CPHR Manitoba • Winnipeg

On-site
CAD 93,000 - 129,000
Competitive salary
Defined-benefit pension
Nine-day work cycle
Interrupting Equipment Maintenance Engineer (Electrical)
Interrupting Equipment Maintenance Engineer (Electrical)

Kibbi • Winnipeg

On-site
CAD 93,000 - 129,000
Competitive salary
Comprehensive benefits
Defined-benefit pension
+1
Project Engineer
Project Engineer

Manitoba Hydro • Winnipeg

On-site
CAD 101,000 - 139,000
Competitive salary and benefits
Nine-day work cycle
Comprehensive benefits package