Cybersecurity & IT Risk and Compliance Analyst
The Manitoba Public Insurance Corporation • Winnipeg, Manitoba • Full Time
Posted on Wed, Sep 9, 2026
Overview
As a Cybersecurity and IT Risk and Compliance Analyst you are responsible for working with the Information Security and IT Risk Management leaders to develop and maintain Cybersecurity and IT Risk and Compliance Management governance, frameworks, policies and processes. You will work with operational teams to provide risk and compliance management advisory, coordination, facilitation and oversight services to enable IT and business leaders to effectively and efficiently manage operational risks and meet compliance requirements within the domain or business units.
Responsibilities
- Assists the Business and Information Technology (IT) leaders in conducting business impact analysis and maintaining a map of business processes to information technology.
- Works with IT leaders to develop and maintain IT Risk Taxonomies.
- Works with IT leaders to perform Risk and Control Assessments (RCAs) and response planning for cybersecurity and IT controls.
- Assists business and IT leaders in conducting Change Risk Assessments for material changes in the IT environment.
- Works with business and IT leaders to conduct risk scenario analysis and identify emerging cybersecurity and technology risks.
- Assists IT leaders to identify and action internal and external risk loss events.
- Develops and maintains the IT Risk Register.
- Conducts periodic reporting of the cybersecurity and IT Risk Profile to business and IT leaders.
- Provides objective and independent assessment of first Line Risk Management activities
- Works with business and IT leaders to develop and maintain an inventory of external requirements and the annual IT Compliance Plan.
- Works with IT leaders to design and implement IT controls and conduct periodic control self-assessments and IT third-party service provider control assessments.
- Logs, monitors and reports control issues, actions and exceptions.
- Performs independent compliance assessments.
- Develops and maintains the inventory of internal controls.
- Coordinates and supports the third-party audit function (internal/external) for the regulatory test cycle.
- Coordinates and prepares management responses to audit findings and recommendations.
- Facilitates IT process governance, management and improvement.
- Develops and maintains the Risk Management process and tools, including third-party risk management.
- Coordinates the integration of risks with Enterprise Risk Management.
- Works with IT leaders to develop and maintain the Cybersecurity and IT Risk and Compliance Management framework, policies, standards, processes, tools and best practices.
Qualifications
Education and Experience
- University degree in Computer Science or a related discipline from a recognized university or college.
- Five years of experience in Information Technology and/or Cybersecurity.
OR
- A two-year diploma in a relevant field from an accredited institution.
- Seven years of experience in Information Technology and/or Cybersecurity
In addition to:
- A professional certification or equivalent from a recognized education institution or company relevant to audit or risk, including:
- Certified in Risk and Information Systems Control (CRISC)
- Certified Information Security Manager (CISM)
- Certified Information Systems Auditor (CISA)
- Certified in Governance of Enterprise IT (CGEIT)
Technical Knowledge & Skills:
- Knowledge of industry risk and compliance policies, procedures and best practices.
- Ability to relate to others with all levels of technical competency.
- Knowledge of IT process and control frameworks such as COBIT, NIST CSF, ISO 27002, ITIL, PMI, etc.
Employee Benefits
Health benefits
We offer a comprehensive health benefits program that includes:
- flexible health, dental and vision plans
- health spending account
- travel health coverage
- other extended health benefits such as ambulance, massage and physiotherapy
Financial security
In an effort to support financial security, we offer:
- registered pension plan
- group, dependent, and optional life insurance coverage
- sick leave to cover short-term disability
- long-term disability
Wellness
We offer programs that focus on how to better achieve a balance between work and personal commitments, as well as maintain a healthy workplace culture. This includes:
- vacation entitlement
- maternity, parental and adoptive leaves
- bereavement and family responsibility leaves
- employee and family assistance program
- mental-health programming
- onsite employee gym facility (Cityplace)
- discounted gym memberships
- wellness account
Diversity and inclusion
Manitoba Public Insurance believes that diversity and inclusion strengthens us. We consider ourselves to be a barrier-free organization where individual values, beliefs and practices are respected and appreciated for the diversity they bring to our work life.
Employee recognition
It’s important to recognize our employees for their contributions. Not only do we recognize employees as they achieve milestone years in their careers, we also have several outlets for leaders and peers to reward each other for work well done.
Professional development
We want our employees to grow, which is why we offer support in keeping their skills up to date. We offer in-house training, professional development and an educational assistance program.
Safety and health
In an effort to encourage a safe and healthy work environment, we offer various safety, health and workplace policies and programs along with technical expertise and assistance to support employee activities in safety and health.
AuditFriendly salary estimate
The employer did not post a salary for this role. Based on AuditFriendly's salary intelligence model (comparable live postings, role, seniority, and location), we estimate base pay of CA$52,000–CA$67,000 per year (median ~CA$57,000). This is an AuditFriendly estimate, not an employer-provided figure.
More live compliance_analyst roles
- HCS Compliance Analyst II - Hospital Compliance — Morrisville, North Carolina, US
- 340B Program Compliance Analyst Certified — Morrisville, North Carolina, US
- FQHC Compliance Analyst — Hendersonville, North Carolina, United States
- Compliance Analyst III - Compliance and Privacy — Morrisville, North Carolina, United States
- Compliance Analyst, Regulatory Requests at MojoRank — Chicago, Illinois, United States
- Trade Compliance Analyst at FlightSafety — Broken Arrow, Ohio, United States
- Compliance Analyst at Nassau — Hartford, Connecticut, United States
- Senior Principal International Trade Compliance Analyst at Northrop Grumman — Warner Robins, Georgia, United States
- Sr. Principal International Trade Compliance Analyst at Northrop Grumman — Warner Robins, GA, United States
- Compliance Analyst at The Walt Disney Company — Celebration, Florida, United States
- Quality And Compliance Analyst at Expeditors — Peabody, MA, US
- Senior It Compliance Analyst at AbbVie — North Chicago, IL, US
- Customs Compliance Analyst (Temporary) at LG — Englewood Cliffs, New Jersey, United States
- Senior Compliance Analyst at Centene Management Company (Remote)
- Compliance Analyst (Third-Party Management) at American Express — New York, New York, United States
- Merchant Compliance Analyst I at Merrick Bank — Woodbury, Minnesota, United States
- Compliance Analyst at LanceSoft (Remote)
- OA-EISO-BA2-Compliance Analyst at LanceSoft — Pennsylvania, United States
- Risk & Compliance Analyst at Epicor — Austin, TX, US
- Sr. Payroll & HR Compliance Analyst — North Kansas City, Missouri, United States
- SR. Payroll & HR Compliance Analyst at Integr8staff — North Kansas City, Missouri, United States
- Lease Compliance Analyst at Foot Locker — Camp Hill, Pennsylvania, United States
- Lease Compliance Analyst (Hybrid) at Foot Locker (Remote)
- Compliance Analyst - Management Accounting & Analysis (MAA) at University of Washington — Seattle, Washington, US
- NERC CIP Compliance Analyst at Genius Road — Dallas, Texas, US
- Governance, Risk, & Compliance Analyst at State of Florida (Remote)
- Compliance Analyst at ISI Enterprises — Reston, Virginia, United States
- Compliance Analyst at SAIC (Remote)
- Audit and Compliance Analyst at PlayCore Careers — Chattanooga, Tennessee, United States
- Mission Compliance Analyst at Guidehouse — Annapolis Junction, Maryland, United States
- Child Care Subsidy Fiscal Compliance Analyst at State of Nebraska — Lincoln, Nebraska, United States
- Revenue Compliance Analyst at TekWissen — San Francisco, CA, United States
- Compliance Analyst, Audit Assurance at Integrity Marketing Group — Dallas, TX
- Compliance Analyst at Apex Group — Munsbach, 9A rue Gabriel Lippmann
- 2027 Compliance Analyst Summer Internship Programme London at Barclays — Canary Wharf, 1 Churchill Place
- 2027 Compliance Analyst Summer Internship Programme Glasgow at Barclays — Glasgow Campus
- Compliance Analyst at Bamm — Jersey City, New Jersey, United States
- Compliance Analyst — Oakland, California, United States
- Compliance Analyst, Supervision at HALO INVESTING — Chicago, Illinois, United States
- Import Export Compliance Analyst at Import Export Compliance Analyst — Austin, TX, United States
- Compliance Analyst II - Primoris Energy Services - Houston, Texas at Primoris Energy Services Corp — Houston, TX, United States
- Senior Regulatory Compliance Analyst at CareFirst — Baltimore, Maryland, United States
- Governance Risk Compliance Analyst (Remote)
- Compliance Analyst at TechDigital Group — Saint Louis, Missouri, US