Cyber Security Analyst

Posted Yesterday
Be an Early Applicant
Pittsburgh, PA, USA
Hybrid
Senior level
Other • Real Estate • Consulting
The Role
Performs cybersecurity risk assessments, governance reviews, and technical evaluations for water and wastewater utilities. Documents IT, OT, ICS, SCADA, and network environments; analyzes monitoring and vulnerability results; develops policies, remediation recommendations, risk profiles, and client reports. The role supports client workshops, field investigations, project execution, and implementation of cybersecurity improvements while communicating technical risks to stakeholders. It requires cybersecurity and OT/ICS expertise, relevant certifications, occasional travel, and fieldwork at utility sites.
Summary Generated by Built In

Our North America Water Utilities Cybersecurity team helps communities safeguard one of their most critical assets: water. We support utilities in understanding their overall cybersecurity posture, developing risk management plans, identifying practical improvements, and/or reconceptualizing overall cybersecurity strategy to support complete re-design across the business IT, operational technology (OT), industrial control system (ICS), and Access Control / CCTV networks.
Our approach emphasizes risk-based assessments, policy and governance improvements, and program development, while integrating findings from trusted third-party technical testing providers (e.g., penetration testing, vulnerability scans, and application assessments). Coupled with our extensive experience in design, build and operation of water treatment and conveyance facilities, we help water utilities build a complete picture of their cyber risk exposure and maturity, and guide them toward sustainable improvements.
This mid-level opportunity is intended for an experienced cybersecurity, OT/ICS, SCADA, or controls professional who can contribute independently to client engagements, perform and document cybersecurity assessments, develop practical recommendations, and support implementation of cybersecurity improvements across water and wastewater environments.

Your Opportunity

Stantec is at the forefront of the water industry, delivering thousands of projects for hundreds of communities globally. Our purpose is to conceive and develop the most impactful water projects that improve the health, quality of life and sustainability of the communities we live in and serve.

You will be part of a collaborative, client-facing team that values sound technical judgment, adaptability, and continuous improvement. This role is expected to take ownership of defined workstreams, interact directly with utility stakeholders, and clearly communicate cybersecurity and OT/ICS concepts to a range of audiences—from operators and engineers to executive leadership.

Key Responsibilities
  • Perform and support cybersecurity risk assessments, program reviews, and governance-focused security evaluations for water utility clients. Independently execute defined portions of engagements and contribute technical judgment to project findings and recommendations. This may include:
  • Collection, review, and field verification of record documents, network diagrams, asset inventories, and system configurations
  • Detailed field documentation of undocumented IT/OT/ICS installations, including lifecycle, maintenance, and obsolescence considerations
  • Capture, analysis, and summary of network monitoring, vulnerability scanning, and other technical assessment results
  • Technical research and evaluation of cybersecurity technologies, architectures, standards, and control approaches
  • Develop assessment findings, remediation recommendations, technical memoranda, and client-ready reports
  • Develop, review, and harmonize cybersecurity policies, standards, procedures, incident response plans, and strategies.
  • Manage assigned tasks, budgets, schedules, deliverables, and coordination activities; contribute to overall project management as needed
  • Evaluate and incorporate findings from third-party penetration testing, vulnerability scanning, and other technical service providers into comprehensive client risk profiles and remediation plans.
  • Participate actively in client workshops, interviews, field investigations, design reviews, and presentations; facilitate defined portions of client meetings when appropriate.
  • Maintain current technical and industry knowledge and take ownership of continued professional development, including:
  • Maintenance and pursuit of relevant cybersecurity, networking, OT/ICS, and vendor certifications
  • Continued development of practical skills with network monitoring, vulnerability assessment, system scanning, analysis, and penetration-testing tools
  • Active engagement in key manufacturer, water-sector, OT/ICS cybersecurity, and industry-sponsored user groups
QualificationsCapabilities and Credentials
  • Working knowledge of cybersecurity principles, governance, risk management, network security, and OT/ICS security practices, with the ability to apply them in client environments.
  • Strong written and verbal communication skills, including the ability to develop client-ready technical deliverables and explain technical risk and recommendations to non-technical stakeholders.
  • Ability to work independently on assigned workstreams while collaborating effectively with clients, internal engineering teams, cybersecurity specialists, and third-party partners.
  • Strong organizational and project execution skills for balancing multiple concurrent projects, priorities, and deadlines.
  • Working knowledge of cybersecurity frameworks and guidance such as NIST CSF 2.0, NIST SP 800-53, NIST SP 800-82, ISA/IEC 62443, AWWA cybersecurity guidance, and applicable water-sector regulatory requirements. Familiarity with SCADA architectures, industrial networking, virtualization, Windows Server/Active Directory, SIEM/IDS/IPS, vulnerability management, or related OT technologies is highly desirable.
Education and Experience
  • Bachelor’s degree in computer science, cybersecurity, information systems, or electrical engineering required. Other 4-year undergraduate engineering degrees will be considered. Relevant graduate education and/or evidenced directly applicable experience desirable.
  • CompTIA Security+, Systems Security Certified Practitioner (SSCP) or equivalent cybersecurity/OT security certification required
  • Certified Information Security Manager (CISA) and/or Certified Information Security Systems Professional (CISSP) desirable
  • Minimum of 8 years of relevant professional experience in cybersecurity, IT/OT networking, SCADA/industrial control networks, systems engineering, or related technology disciplines, including demonstrated cybersecurity responsibilities. 
  • Water/wastewater or other critical-infrastructure experience strongly preferred.
  • Must have good driving record and valid driver's license
  1.  
  2. Continued advancement will be supported through progressively greater responsibility for technical leadership, client delivery, and project management. Attainment of advanced professional certifications, including CISSP, CISA, CISM or equivalent, will be required.
Additional Information
  • Reports to: Cybersecurity Practice Lead, Water Utilities
  • Location: Partially remote (strong preference for candidates near an existing office) 
  • Travel: Occasional travel to client sites or industry events (up to 50%)
  • Office work: Typical office desktop workstation environment. 
  • Field work: typically at sites with treatment equipment in active use and/or active construction activities. Exposure to the elements including inclement weather is probable.

This description is not a comprehensive listing of activities, duties or responsibilities that may be required of the employee. Other duties, responsibilities and activities may be assigned or may be changed at any time with or without notice.

About the Team
Pay Transparency: In compliance with pay transparency laws, pay ranges are provided for positions in locations where required. Please note, the final agreed upon compensation is based on individual education, qualifications, experience, and work location. At Stantec certain roles are bonus eligible. Actual compensation for part-time roles will be pro-rated based on the agreed number of working hours per week.

Benefits Summary: Regular full-time and part-time employees (working at least 20 hours per week) have access to medical, dental, and vision plans, a wellness program, health saving accounts, flexible spending accounts, 401(k) plan, employee stock purchase program, life and accidental death & dismemberment (AD&D) insurance, short-term/long-term disability plans, emergency travel benefits, tuition reimbursement, professional membership fee coverage and paid family leave. Regular full-time and part-time employees will receive ten paid holidays in each calendar year. In addition, employees will be eligible to accrue vacation between 10 and 20 days per year and eligible for paid sick leave (and if more generous, in accordance with state and local law).

Temporary/casual employees have access to 401(k) plans, employee stock purchase program, and paid leave, in accordance with state and local law.

The benefits information listed above may not apply to union positions because benefits for such positions are governed by applicable collective bargaining agreements

Skills Required

  • Bachelor's degree in computer science, cybersecurity, information systems, electrical engineering, or another four-year engineering discipline
  • CompTIA Security+, SSCP, or equivalent cybersecurity/OT security certification
  • Minimum of 8 years of relevant professional experience in cybersecurity, IT/OT networking, SCADA/industrial control networks, systems engineering, or related technology disciplines
  • Demonstrated cybersecurity responsibilities
  • Valid driver's license and good driving record
  • Working knowledge of cybersecurity principles, governance, risk management, network security, and OT/ICS security practices
  • Working knowledge of NIST CSF 2.0, NIST SP 800-53, NIST SP 800-82, ISA/IEC 62443, AWWA cybersecurity guidance, and applicable water-sector regulatory requirements
  • Strong written and verbal communication skills, including technical report development and communication with nontechnical stakeholders
  • Ability to work independently while collaborating with clients, engineering teams, cybersecurity specialists, and third-party partners
  • Strong organizational and project execution skills for managing multiple projects, priorities, and deadlines
  • Water, wastewater, or other critical-infrastructure experience
  • Familiarity with SCADA architectures, industrial networking, virtualization, Windows Server/Active Directory, SIEM/IDS/IPS, and vulnerability management
  • CISA, CISM, CISSP, or equivalent advanced cybersecurity certification
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Edmonton, Alberta
22,253 Employees

What We Do

We're active members of the communities we serve. That's why at Stantec, we always design with community in mind. The Stantec community unites approximately 22,000 employees working in over 350 locations across six continents. We collaborate across disciplines and industries to bring buildings, energy and resource, environmental, and infrastructure projects to life. Our work—engineering, architecture, interior design, landscape architecture, surveying, environmental sciences, project management, and project economics, from initial project concept and planning through design, construction, and commissioning—begins at the intersection of community, creativity, and client relationships. Our local strength, knowledge, and relationships, coupled with our world-class expertise, have allowed us to go anywhere to meet our clients'​ needs in more creative and personalized ways. With a long-term commitment to the people and places we serve, Stantec has the unique ability to connect to projects on a personal level and advance the quality of life in communities across the globe.

Similar Jobs

Cencora Logo Cencora

Senior Director, Identity Governance

Healthtech • Logistics • Pharmaceutical
In-Office
Conshohocken, PA, USA
51000 Employees

Cencora Logo Cencora

Senior Engineer

Healthtech • Logistics • Pharmaceutical
In-Office
Conshohocken, PA, USA
51000 Employees

HiBob Logo HiBob

People and Culture Partner

HR Tech • Information Technology • Professional Services • Sales • Software
Remote or Hybrid
United States
1350 Employees
120K-150K Annually

HiBob Logo HiBob

Sales Engineer

HR Tech • Information Technology • Professional Services • Sales • Software
Remote or Hybrid
United States
1350 Employees
108K-145K Annually

Similar Companies Hiring

Agora RE Thumbnail
Fintech • Real Estate • PropTech
Tel Aviv, IL
200 Employees
Northslope Thumbnail
Artificial Intelligence • Information Technology • Software • Analytics • Consulting • Generative AI
London, GB
100 Employees
Rosendin Thumbnail
Other • Manufacturing
San Jose, CA
6219 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account