Monitoring and Response Lead

Manitoba Hydro

Posted: 7 hours ago Closes: Oct 19, 2026

Job Location: Winnipeg, MB

Job Type: Full Time

How To Apply: https://www.hydro.mb.ca/careers

Sign Up to Start Applying

Monitoring and Response Lead

Winnipeg, MB

Manitoba Hydro is consistently recognized as one of Manitoba's Top Employers! We are a leader among energy companies in North America, recognized for providing highly reliable service and exceptional customer satisfaction. Join our team of Manitoba's best as we continue to build a company that champions safety, supports innovation, and delivers on our commitment to customer service - while actively fostering a diverse, equitable, and inclusive workplace reflective of the communities we serve.

Great Benefits
  • Competitive salary and comprehensive benefits package.
  • Defined-benefit pension plan for long-term financial security.
  • Enjoy a work schedule that typically provides every second Monday off (subject to location and operational requirements), supporting a balanced approach to work, family life and community.

Position Overview:
Under the general direction of the Cyber Security Operations Department Manager and as a key member of the Cyber Security Operations Department leadership team, lead and develop the Monitoring and Response team, deliver corporate-wide (IT&OT) cyber threat monitoring/detection/response services, continuously tune and enhance alerts, maximize cyber monitoring services contract value, advance monitoring and response capabilities, support and enhance the SOC technology environment, and keep abreast of cybersecurity developments.

Responsibilities:
  • Lead and develop the Monitoring and Response team: Translate departmental goals into clear strategic and operational priorities. Foster an inclusive, engaged, and high-performing culture where people can thrive, grow, and contribute to shared success. Build team capability and resiliency through coaching, mentoring, hiring, and development opportunities, creating a team that attracts, develops, and retains top talent. Oversee work prioritization, delegation, service continuity, training, performance management, and continuous improvement.
  • Deliver corporate-wide (IT&OT) cyber threat monitoring, detection, and response services: Lead the delivery and continuous improvement of enterprise monitoring, detection, investigation, and incident response capabilities across IT and OT environments. Ensure cyber threats, events, and incidents are effectively identified, analyzed, contained, eradicated, and recovered from with speed and with continuously improving measures. Lead and coordinate response activities across internal teams, service providers, and stakeholders to minimize risk and business impact while maintaining monitoring and response capabilities aligned with organizational priorities. Provide leadership during critical cyber incidents and urgent operational events. May be required to participate in a rotating 24/7 standby program. Act as the primary contract manager and escalation point for external cyber monitoring service providers, fostering strong working relationships and ensuring effective collaboration, issue resolution, service performance, and continuous improvement.
  • Exercise program: Lead a cyber security exercise program that tests and improves the organization's readiness to detect, respond to, contain, eradicate, and recover from cyber incidents. Coordinate exercises, including procurement, involving internal teams, service providers, executives, and external stakeholders, ensuring lessons learned are translated into measurable improvements to plans, processes, capabilities, and response effectiveness. 
  • Continuously tune and enhance alerts: Lead continuous detection effectiveness enhancement by tuning alerts, use cases, and workflows to improve fidelity, reduce false positives, increase visibility of emerging threats, and optimize analyst efficiency. Identify alert use case gaps revealed through alert and incident response activities, and work with CSO Technology Management to remediate them. Ensure CSO Technology Management is kept informed of any changes to alert use cases
  • Maximize Cyber Monitoring Services contract value: Oversee the delivery and performance of contracted monitoring services, ensuring service levels, capabilities, reporting, and outcomes align with organizational requirements. Drive continuous improvement and maximize value from security monitoring investments.
  • Support security control enhancements: Support the identification, planning, implementation, and sustainment of monitoring and response control enhancements identified through the Cyber Roadmap, enterprise assessments, audits, incidents, and industry best practices. Drive measurable improvements in detection, response, resilience, and cyber maturity.
  • Support and enhance the SOC technology environment: Provide operational leadership, requirements, and subject matter expertise to sustain, optimize, and expand the security operations technology portfolio. Work closely with Cyber Security Operations Technology Management, vendors, and stakeholders to ensure monitoring, detection, investigation, and response tools are effectively deployed, integrated, maintained, and aligned with business and security requirements and keep pace with evolving cyber threats.
  • Keep abreast of cybersecurity developments outside of MH: Develop and maintain effective relationships with industry peers, partners, and standards bodies to exchange information and stay informed of emerging threats, technologies, regulations, and best practices. Maintain awareness of NERC and cyber security requirements and communicate relevant developments to enterprise stakeholders.

Qualifications:
  • A four-year degree in Computer Science or Engineering or related discipline from a university of recognized standing plus a minimum of six years' related information technology (IT) or industrial control system (ICS) Support experience;
    OR 
  • A two-year diploma in Electrical, Electronic, Computer Technology, related discipline from an institute of recognized standing plus a minimum of eight years'related IT or ICS Support experience.
  • Certifications such as Cyber Security specific (CISSP, CISM, CRISC, OSCP, CEH, CGIH, GPE, SANS, ISAACA CSX Cybersecurity Practitioner (CSX-P), (ICS)2 Entry -Level Cybersecurity certification, technology specific (SIEM, XDR, etc.), etc.), network related (CCNA, etc.), cloud platform related (M365, Azure, etc.), operating system related (Linux, Windows, Unix, Apple IOS), management related (PMP, emergency management, etc.), software/application security, etc. would be an asset.
  • Demonstrated knowledge and experience in cyber security monitoring, detection, investigation, and incident response across information technology (IT), operational technology (OT), and industrial control system (ICS) environments. This includes experience with Security Information and Event Management (SIEM), Security Orchestration, Automation and Response (SOAR), endpoint and extended detection and response (EDR/XDR), network detection technologies, threat intelligence, detection use-case development and tuning, security analytics, incident response processes, and automated or manual containment capabilities. 
  • Demonstrated ability to assess monitoring coverage, identify detection gaps, improve alert fidelity, and use operational metrics and lessons learned to continuously improve monitoring and response effectiveness.
  • Demonstrated understanding of cyber security concepts, controls, frameworks and standards including NIST and NERC CIP.
  • Demonstrated effectiveness in building and leading teams through resolving complex, urgent, and potentially high impact cyber events. Demonstrated ability to build and maintain harmonious working relationships with staff across the enterprise at all levels. 
  • Demonstrated ability to communicate effectively verbally and in writing. Demonstrated ability to deliver reports, recommendations, and presentations with a drive for continuous improvement and documentation.
  • Must complete Manitoba Hydro Standards of Conduct training.
  • Must possess a valid Province of Manitoba Driver's Licence.
  • NERC CIP Training is required, must be completed prior to transfer date, and renewed annually.
  • Obtain and maintain a current Personnel Risk Assessment and a "Clear" security rating in accordance with Manitoba Hydro policy P513.
  • Reside within the Winnipeg headquarters zone or within a reasonable travelling distance from the assembly point during the periods of standby.
  • Must maintain or be eligible for SECRET clearance from the Government of Canada.

Salary Range
Starting salary will be commensurate with qualifications and experience. The range for the classification is $52.88-$72.45 Hourly, $101,332.40-$138,828.30 Annually.

Apply Now!
Note: This employment opportunity is advertised on Manitoba Hydro's career website, and all candidates wishing to apply must do so using our online application system. Ready to join a team that energizes Manitoba and puts safety, innovation, and inclusion at the heart of everything we do? Visit www.hydro.mb.ca/careers to learn more about this position and to apply online.

Application deadline: OCTOBER 9, 2026.

We appreciate your interest in Manitoba Hydro and thank all applicants. Only those selected for the next stage of the selection process will be contacted.

If you require accommodations during the recruitment process or need this posting in an accessible format, please let us know - we're committed to a barrier-free experience for all candidates.

This employer accepts online applications via AMIK.ca! Apply online now for the following benefits:

  • Apply online for any job on AMIK.
  • Save jobs for later and track your job applications.
  • Add and manage all your resume in one place.