Air Canada

Partner, Cybersecurity Governance, Risk and Compliance

Air Canada$110K — $130K *
Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • 8-12+ years in Cybersecurity governance, risk management, and compliance.
  • Certifications: CISSP and/or CISM required; CRISC, ISO 27001, NIST, and CDMP certifications are assets.
  • Proven experience with NIST or ISO framework implementation and governance models.
  • Exposure to AI and data governance initiatives is a plus.
  • Strong understanding of cloud and SaaS environments.

Responsibilities

  • Establish security governance for strategic programs like Juniper, CRM, and CDP.
  • Implement risk and compliance reviews within the project lifecycle.
  • Design and execute an enterprise cybersecurity framework aligned with NIST or ISO standards.
  • Modernize cybersecurity policies and align them with corporate standards.
  • Define enterprise asset inventory and data classification model.
  • Manage cybersecurity risk framework including identification and remediation.
  • Establish AI governance framework with compliance controls and monitoring mechanisms.

Benefits

  • Generous employee travel program after 6 months of service.
  • Hybrid work model, allowing for a mix of in-office and remote work.
  • Comprehensive health and dental benefit plans for you and your family.
  • Access to training and development tools to enhance your skills.
Full Job Description
Job Title: Partner, Cybersecurity Governance, Risk and Compliance Department: IT - Operations Location: YUL Reporting Manager: Director, IT Operations, Infrastructure and Security Reporting to the Director, IT Operations, Infrastructure and Security. The Partner, Cybersecurity Governance, Risk and Compliance will be responsible for establishing and enforcing cybersecurity governance across strategic transformation initiatives (Juniper, CRM, CDP), while designing and implementing a structured cybersecurity framework for Air Canada Vacations aligned with industry standards (NIST or ISO 27002). This role will modernize cybersecurity policies, define and classify critical information assets, and ensure that cybersecurity is integrated into all projects and business processes from inception. WHAT YOU'LL BE DOING Cybersecurity Governance for Strategic Programs • Establish security governance structures for Juniper (Reservation System), CRM, CDP • Implement: o Security checkpoints and stage gates o Risk and compliance reviews within project lifecycle • Ensure alignment with: o Privacy requirements (PIA, data retention, etc.) o Architecture and Change Management processes • Enforce "secure by design" governance across all initiatives Cybersecurity Framework Development • Design and implement an enterprise cybersecurity framework for ACV based on NIST Cybersecurity Framework or ISO 27001 / 27002 controls • Define: o Control domains and control catalog o Security standards and procedures o Governance and accountability model Policy & Directive Modernization • Review, rationalize, and modernize Cybersecurity policies, directives and procedures • Align policies: o With Air Canada corporate standards where applicable o Reflect modern architectures (cloud, SaaS, APIs) • Establish clear policy lifecycle and governance model\ Enterprise Asset Management & Data Classification • Define and implement: o Enterprise asset inventory (applications, systems, data) o Data classification model (e.g., confidential, regulated, internal) • Identify: o Critical systems and business assets o Sensitive and regulated data sets • Ensure classification drives Access controls, Retention policies, and Security controls Risk Management & Compliance • Establish cybersecurity risk management framework: o Risk identification and assessment o Risk tracking and remediation • Formalize exception and risk acceptance processes AI Governance & Responsible Use • Define and implement AI governance framework including: o AI usage policies and directives o Risk and compliance controls for AI systems o Data usage and model governance standards • Establish: o Approval process for AI use cases o Monitoring and audit mechanisms for AI solutions • Ensure alignment with Air Canada enterprise policies (where applicable) WHAT YOU BRING TO THE TEAM • 8-12+ years in Cybersecurity governance / GRC and Risk management / Compliance • Certifications required (CISSP and / or CISM) • CRISC, an asset • ISO 27001 Lead Implementer or Lead Auditor, an asset • NIST Cybersecurity Framework Training Certification, an asset • CDMP, an asset • Proven experience: o Implementing NIST or ISO frameworks o Supporting large transformation programs o Establishing governance models o Exposure to AI/data governance initiatives • Good understanding of: o Data governance and classification o AI governance concepts (risk, ethics, controls) o Cloud and SaaS environments • Extremely organized and diligent in maintaining consistency • Autonomous and dedicated • Excellent communicator • Results oriented and the ability to manage multiple priorities with a sense of urgency and orientation to deadlines WHY WORK WITH US?
  • Our team loves to travel, and we have one of the most generous employee travel programs in the industry. You'll be eligible for travel privileges for yourself and other eligible persons once you've completed 6 months of service
  • Hybrid work model: Corporate Mandate of 4 days in office (Tuesday, Wednesday, Thursday + 4th day of your choice) and 1 day from home
  • We value your wellbeing and offer a wide variety of benefit plans, including health and dental, for you and your family
  • We offer training and development tools to help unlock your full potential
Please note that these benefits apply to permanent, full-time employees. Visit our Careers page for a full list of benefits. Linguistic Requirements When qualifications are equal, preference will be given to bilingual candidates. The position involves daily interactions with partners, clients, and colleagues located outside of Quebec.

Similar Jobs

More Jobs at Air Canada

More Information Technology Jobs

Find similar Partner, Cybersecurity Governance, Risk and Compliance jobs: