Lead Information Security Analyst, Continuous AI Risk Management Expert (T & I) (Telework/Hybrid)

CBC/Radio-Canada

$100K — $120K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • University degree in computer science, IT, or information security.
  • Minimum five years of experience in IT security, data governance, or technology risk management.
  • Demonstrated experience in risk assessment methodologies and AI model evaluation.
  • Ability to translate complex AI concepts into structured risk frameworks.
  • Extensive knowledge of security technology and risk assessment policies.
  • Excellent communication skills for conveying technical concepts to non-technical stakeholders.
  • Relevant professional security certifications (e.g., CISSP, CRISC) preferred.
  • Bilingual in English and French required.

Responsibilities

  • Design and deploy an AI risk assessment framework tailored to ethical and algorithmic challenges.
  • Support the enterprise AI governance architecture in collaboration with key teams.
  • Maintain a centralized AI inventory classifying systems by risk level.
  • Conduct continuous risk assessments for new AI use cases.
  • Perform specialized AI security and adversarial testing.
  • Evaluate third-party AI solutions for security posture and compliance.
  • Manage the AI risk register and document model vulnerabilities.
  • Assess program maturity by developing dashboards and tracking key performance indicators.

Benefits

  • Opportunity to solve complex challenges in a respected media organization.
  • Engagement with leading-edge technologies in a hybrid work environment.
  • Contribution to a high-impact governance and security program in AI.
  • Professional development in a field at the forefront of technology.
  • Work with a dynamic team addressing nuanced media technology issues.
Full Job Description

Position Title:

Lead Information Security Analyst, Continuous AI Risk Management Expert (T & I) (Telework/Hybrid)

Status of Employment:

Contractee Long-Term (Durée déterminée)

Position Language Requirement:

English, French

Language Skills:

English (Reading - C - Advanced), English (Speaking - C - Advanced), English (Writing - B - Intermediate), French (Reading - C - Advanced), French (Speaking - C - Advanced), French (Writing - B - Intermediate)

This is a hybrid role with a mix of in-office and remote work. Work arrangements will be discussed with hiring managers per departmental guidelines.

Your Role


CBC/Radio-Canada is seeking a Lead Analyst, Continuous AI Risk Management Expert, to design, build and lead the enterprise-wide governance, security and continuous risk management program for artificial intelligence (covering both traditional AI and generative AI) across the Corporation.

In this role, you will design and deploy an enterprise AI risk assessment framework and conduct continuous evaluations of AI systems throughout the AI life cycle (from design to production). You will collaborate closely with data protection analysts, as well as the legal, compliance and enterprise architecture teams, to identify, measure and mitigate cybersecurity risks associated with AI technologies.

This position can be based in Montreal or Toronto.

What’s in It for You

Challenges. We spend our days solving problems of all kinds. Media files are highly nuanced and incredibly complicated; updating, installing and supporting technologies that are organization-wide and that impact broadcasting content is a time-sensitive, complex technical feat. And that’s just the beginning. You’ll be working with leading-edge data management, cloud, IP broadcasting, AI, security and reliability technologies.

As Lead Analyst, you will:

  • Design and deploy the AI risk assessment framework: Develop, formalize and implement a standardized risk assessment methodology tailored to AI systems, including ethical impact matrices, model criticality criteria, bias analysis, algorithmic vulnerability assessments and data exposure risks.
  • Support enterprise AI governance architecture: Collaborate closely with architecture teams and governance committees to design, integrate and evolve the security foundation for AI technologies across the Corporation.
  • Maintain the AI inventory and classification: Build and manage a centralized registry of all AI systems, models (internal, SaaS, open-source) and AI agents deployed across the organization, classified by risk level.
  • Conduct continuous model risk assessments: Perform technical risk evaluations on new AI use cases, analyzing training data security, prompt/query confidentiality, algorithmic bias and intellectual property risks.
  • Perform AI security testing: Define and execute specialized security and adversarial testing for AI and large language models (LLMs).
  • Assess third-party AI and SaaS solutions: Partner with the Third-Party Risk Management (TPRM) Analyst to evaluate the security posture, privacy controls and model-training policies of external vendors. Provide specialized AI expertise to analyze contractual data-use terms (e.g., ensuring corporate data is not used for model training), evaluate SaaS API security and verify privacy guarantees in third-party environments.
  • Manage the AI risk register: Document, maintain and map AI-specific model vulnerabilities, technical debt and approved exceptions in the risk register.
  • Assess program maturity: Conduct periodic evaluations of AI governance maturity, developing dashboards and tracking key performance indicators (KPIs) and key risk indicators (KRIs) for executive and governance committees.
  • Maintain industry expertise: Stay current on information security best practices and industry trends.

What You Bring

  • University degree in computer science, IT or information security.
  • Minimum five years' applied experience in IT security, data governance or technology risk management.
  • Demonstrated experience in designing or implementing risk assessment methodologies and evaluating AI models.
  • Proven ability to translate complex AI concepts into structured risk frameworks for project teams, with a deep understanding of AI architectures and AI-specific attack vectors.
  • Extensive knowledge of security technology and risk assessment methodologies, policies and processes.
  • Excellent written and verbal communication skills, with a demonstrated ability to translate complex technical concepts for non-technical decision-makers (e.g., governance committees, business units, legal teams).
  • Excellent analytical, evaluative and problem-solving abilities.
  • Experience with compliance programs as well as their technical and security requirements.
  • Technical expertise across key domains:
    • Standards and Frameworks: Strong command of industry standards such as ISO/IEC 27001, 27002, 27005, NIST SP 800-53 / 800-161, COBIT and ITIL.
    • Cloud and Web Architecture Security: Solid understanding of web infrastructure and cloud environment security.
    • Network and Security Technologies: Thorough understanding of network architectures (LAN/WAN, routers), network security technologies (firewalls, IDS/IPS, DNS, web filtering) and cryptographic principles (encryption at rest and in transit).
    • Architecture and Data Security: Working knowledge of database architecture concepts and secure software development best practices.
    • Operational Resilience and Physical Security: Solid understanding of business continuity and disaster recovery planning (BCP/DRP), operational resilience and physical security controls.
  • Relevant professional security certifications a definite asset (e.g., CISSP, CRISC, CBCP, CISA, CISM or equivalent).
  • Bilingualism (English and French) essential.

Candidates may be subject to skills and knowledge testing.

We thank all applicants for their interest, but only candidates selected for an interview will be contacted.

Primary Location:

1000, Rue Papineau, Montreal, Quebec, H2K 0C2

Number of Openings:

1

Work Schedule:

Full time

Similar Jobs

More Jobs at CBC/Radio-Canada

More Information Technology Jobs

Find similar Lead Information Security Analyst, Continuous AI Risk Management Expert (T & I) (Telework/Hybrid) jobs: