Cyber Security Advisor - Exposure Management
City of CalgaryYour application goes straight to City of Calgary's own careers site.
About this job
If you are committed to public service, enjoy collaborating with others, share our values and have a desire to learn and grow, join
The City of Calgary. City employees deliver the services, run the programs and operate the facilities which make a difference in our community. We support work-life balance, promote physical and psychological safety, and offer competitive wages, pensions, and benefits. Together we make Calgary a great place to make a living, a great place to make a life. The City is committed to fostering a respectful, inclusive and equitable workplace which is representative of the community we serve. We welcome those who have demonstrated a commitment to upholding the values of equity, diversity, inclusion, anti-racism and reconciliation. Applications are encouraged from members of groups that are historically disadvantaged and underrepresented. Accommodations are available during the hiring process, upon request.The City of Calgary¿s Cyber Security Business Unit safeguards the information, technology, and operational systems that enable the delivery of services to Calgarians.
As the Cyber Security Advisor, you will be responsible for authoritative and strategic advisory services pertaining to cyber security exposures affecting enterprise assets including data, information, processes and technology systems. Specifically, you will drive the City's cyber security exposure management program, ensuring vulnerabilities, weaknesses, misconfigurations, and other exposures are identified and prioritized for appropriate treatment plans, while contributing more broadly to the City's Cyber Security mandate and roadmap. Primary duties include:
- Serve as Cyber Security¿s point of contact for security vulnerability and exposure management activities, including scanning and testing readiness, environment and asset coverage, and platform administration.
- Provide authoritative advisory guidance to Cyber Security¿s governance channels and business leadership regarding opportunities, objectives, and performance within the exposure management program.
- Develop and apply prioritization criteria for exposures, incorporating enterprise context and asset criticality, threat intelligence, exploitability, and compensating controls.
- In collaboration with Cyber Security colleagues and City partners, maintain and execute a robust exposure management program documentation plan, including remediation tracking, standards, procedures, compliance and assurance evidence, performance measures and other metrics.
- Coordinate resources and efforts from diverse City business units, technology teams, and external parties through the exposure management lifecycle ¿ from discovery and validation through remediation, exception management, and verification.
- A diploma in Computer Science, Information Technology, Cyber Security, Business Administration, or a related field and at least 8 years of experience in cyber security, vulnerability or risk management, cyber security architecture, software engineering, system administration or a related function; OR
A degree in Computer Science, Information Technology, Cyber Security, Business Administration, or a related field and at least 5 years of experience in cyber security, vulnerability or risk management, cyber security architecture, software engineering, system administration, or a related function. - One or more recognized, current cybersecurity or risk management certifications such as Certified Information Systems Security Professional (CISSP), Certified Cloud Security Professional (CCSP), Certified Information Security Manager (CISM), or Certified in Risk and Information Systems Control (CRISC) are required.
- Demonstrated experience at a senior level in a minimum of two cyber security domains (for example: cyber security risk management, cyber security architecture, data security, cyber security operations, industrial control systems security, application security, vulnerability management, continuous threat exposure management, penetration testing) is required.
- Proven experience in continuous monitoring, automated logging, and cloud-native environments in complex, public sector, or highly regulated environments would be considered an asset.
- Demonstrated Project Management skills will also be an asset.
- Success in this position requires empathy, highly developed communication and relationship building skills, a well-developed ability to influence without authority and build a shared vision for security outcomes.
A security clearance will be conducted.
Successful applicants must provide proof of qualifications.
This position may be eligible to work from home for at least part of the time as one of several flexible work options available to City employees. These arrangements depend on the operational requirements of the role, employee suitability, and are subject to change based on operational needs and corporate direction.
Position and Pay Information
- Business Unit: Cyber Security
- Union: CUPE Local 38
- Position Type: 1 Permanent
- Compensation: Pay Grade 13 $50.92 - 68.15 per hour
- Hours of work: Standard 35 hour work week.
- Days of work: This position works a 5-day work week with 1 day off in a 3 week cycle.
- Location: 133 6 Avenue SE
- Audience: Internal/External
- Apply By: October 2, 2026
- Job ID: 315212