Air Canada logo
Specialist, IT and Cybersecurity Risk
full-timeDorval

Summary

Location

Dorval

Type

full-time

Explore Jobs

About this role

Being part of Air Canada is to become part of an iconic Canadian symbol, recently ranked the best Airline in North America. Let your career take flight by joining our diverse and vibrant team at the leading edge of passenger aviation.

The Specialist, IT and Cybersecurity Risk will be working in a fast paced and innovative environment supporting the overall security posture of Air Canada’s technology environment. Air Canada’s IT and OT systems are foundational to protecting the data and systems that allow its customers to fly safely.
The Specialist, IT and Cybersecurity Risk acts as an IT and cybersecurity subject matter expert and provides guidance concerning the IT and cybersecurity risks for Air Canada and its affiliates. The incumbent, will evaluate Air Canada’s existing IT and OT systems to determine potential IT and cybersecurity risks, provide inputs on IT and cybersecurity requirements for personal, commercial and financial data as well as the operation of Air Canada IT networks and infrastructure. Cybersecurity threats continue to evolve, and the IT and Cybersecurity Risk team will evolve with it.
This position will be reporting to the Manager, IT and Cybersecurity.

Responsibilities:

  • Collaborates with Strategic Procurement for the sourcing exercise and on-boarding of the third-parties for the execution of IT and cybersecurity controls.
  • Leads the execution of third-party IT and cybersecurity risk assessments (pre and post contacting, and ongoing monitoring) to ensure compliance with internal information security policies and procedures, as well as external requirements.
  • Ensures that cybersecurity clauses are embedded in the agreements with third parties.
  • Manage IT and cybersecurity risks, issues, and defects from identification to remediation.
  • Performs IT and cybersecurity risk assessments, documents them and supports the implementation of mitigating controls consistent with company strategy.
  • Generate reports to demonstrate IT and cybersecurity metrics and KPIs and KRIs.
  • Identify IT and Cybersecurity risks, communicate and develop “best practice” solutions, and recommend mitigating controls consistent with company strategy.
  • Introduce new processes and initiatives to improve IT and cybersecurity risk practice.
  • Represent the organization and take active participation in different IT or cybersecurity airline specific forums.
  • Supporting the leadership team on strategic initiatives specific to the respective portfolio.


  • A relevant University degree/technical certification, and/or relevant experience commensurate to the role
  • 6-8 years of IT technology, operations, and people leadership experience in a large company, with a minimum of 4 years of experience in IT and cybersecurity governance, risk and compliance role.
  • Strong knowledge in IT and cybersecurity risk management processes, methods, and tools.
  • Strong knowledge of cybersecurity standards, IT and cybersecurity risks, threats, prevention measures, and best practices.
  • Strong knowledge and understanding of cyber security concepts, protocols, industry best practices, strategies, frameworks and regulations such as SOX, PCI DSS, ISO, CoBIT, NIST, PIPEDA, GDPR.
  • Thorough understanding of Application Security Testing, Penetration Test, Tabletop Exercises.
  • Current information security certification (CISSP, CISM or equivalent) is an asset.
  • Exceptional analytical, organizational, and communication skills.
  • Self-motivated and independent worker.
  • Possess investigative nature and be self-motivated.
  • Results oriented with a proactive and methodical approach to problem solving.
  • Able to multi-task and work under pressure against tight deadlines and changing priorities.
  • Must be a team player with the ability to work closely with diverse groups and working styles.
  • Ability to establish and maintain effective business relationships.
  • Flexibility and willingness to work extended hours, when required.
  • Demonstrate punctuality and dependability to support overall team success in a fast-paced environment.

Conditions of Employment:

Candidates must be eligible to work in the country of interest, at the time any offer of employment is made and seeking any required work permits/visas or other authorizations which may be required is the sole responsibility of the candidates applying for this position.

Linguistic Requirements

Based on equal qualifications, preference will be given to bilingual candidates.

Diversity and Inclusion

Air Canada is strongly committed to Diversity and Inclusion and aims to create a healthy, accessible and rewarding work environment which highlights employees’ unique contributions to our company’s success.

As an equal opportunity employer, we welcome applications from all to help us build a diverse workforce which reflects the diversity of our customers, and communities, in which we live and serve.

Air Canada thanks all candidates for their interest; however only those selected to continue in the process will be contacted.

Other facts

Tech stack
IT Risk Management,Cybersecurity,Governance,Compliance,Risk Assessment,Analytical Skills,Communication Skills,Problem Solving,Teamwork,Cybersecurity Standards,Application Security Testing,Penetration Testing,Regulatory Knowledge,Organizational Skills,Self-Motivation,Proactive Approach

About Air Canada

Canada's largest airline, the country’s flag carrier and a founding member of Star Alliance, the world's most comprehensive air transportation network celebrating its 25thanniversary in 2022, Air Canada provides scheduled passenger service directly to 51 airports in Canada, 51 in the United States and 86 internationally. It is the only international network carrier in North America to receive a Four-Star ranking from Skytrax, which in 2021 gave Air Canada awards for the Best Airline Staff in North America, Best Airline Staff in Canada, Best Business Class Lounge in North America, and an excellence award for its management of the COVID-19 pandemic.

**

Air Canada est la plus importante société aérienne du Canada, le transporteur national du pays et un membre cofondateur du réseau Star Alliance — le plus vaste regroupement mondial de sociétés aériennes, qui célèbre son 25e anniversaire en 2022. Les lignes passagers régulières d’Air Canada relient sans escale 51 aéroports au Canada, 51 aux États-Unis et 86 sur le reste du globe. En Amérique du Nord, Air Canada constitue le seul transporteur aérien d’envergure internationale offrant une gamme complète de services à détenir la cote quatre étoiles de Skytrax qui, en 2021, lui a décerné les prix Meilleur personnel au sol et à bord en Amérique du Nord, Meilleur personnel au sol et à bord au Canada, Meilleur salon de classe affaires en Amérique du Nord ainsi qu’un Prix d’excellence pour sa gestion de la pandémie de la COVID-19.

Team size: 10,001+ employees
LinkedIn: Visit
Industry: Airlines and Aviation
Founding Year: 1937

What you'll do

  • The Specialist will evaluate Air Canada’s IT and OT systems for potential cybersecurity risks and manage IT and cybersecurity risks from identification to remediation. They will also lead third-party risk assessments and ensure compliance with internal and external security requirements.

Ready to join Air Canada?

Take the next step in your career journey

Frequently Asked Questions

What does a Specialist, IT and Cybersecurity Risk do at Air Canada?

As a Specialist, IT and Cybersecurity Risk at Air Canada, you will: the Specialist will evaluate Air Canada’s IT and OT systems for potential cybersecurity risks and manage IT and cybersecurity risks from identification to remediation. They will also lead third-party risk assessments and ensure compliance with internal and external security requirements..

Why join Air Canada as a Specialist, IT and Cybersecurity Risk?

Air Canada is a leading Airlines and Aviation company.

Is the Specialist, IT and Cybersecurity Risk position at Air Canada remote?

The Specialist, IT and Cybersecurity Risk position at Air Canada is based in Dorval, Quebec, Canada. Contact the company through Clera for specific work arrangement details.

How do I apply for the Specialist, IT and Cybersecurity Risk position at Air Canada?

You can apply for the Specialist, IT and Cybersecurity Risk position at Air Canada directly through Clera. Click the "Apply Now" button above to start your application. Clera's AI-powered platform will help match your profile with this opportunity and guide you through the application process. You can also learn more about Air Canada on their website.