06 Sep
|
Air Canada
|
Dorval
Being part of Air Canada is to become part of an iconic Canadian symbol, recently ranked the best Airline in North America. Let your career take flight by joining our diverse and vibrant team at the leading edge of passenger aviation.
The Partner, Product Security leads product security engagement across a portfolio of digital products and platforms, serving as the single point of entry into Cybersecurity & GRC for security support across IT, Data, & Digital (IDD). Partnering closely with product, engineering, and architecture teams, the incumbent ensures security is embedded throughout the product lifecycle - from ideation through to production deployment. Leveraging the organization's agentic capabilities, this role owns threat modeling, risk management, and secure-by-design practices, balancing delivery velocity against risk reduction.
The Partner also provides security posture leadership for assigned portfolios and drives consistent application of secure SDLC controls and governance.
This position may be located in Montreal or Toronto.
Responsibilities
Own the product security posture for an assigned portfolio of products and platformsLead security engagement across the full product lifecycle, from ideation through productionDrive and oversee threat modeling for new and existing products, using agentic tooling to scale coverage and reduce manual effortPartner with product managers and engineering leads to embed secure-by-design practices into delivery workflowsProvide risk-based security guidance during architecture and design reviewsEnsure secure Product Development Lifecycle controls are implemented and consistently applied across development teamsTrack and manage security risks, vulnerabilities, and remediation priorities to closureEstablish and govern secure usage patterns for agentic development tools and AI gateways, including guardrails for AI-assisted coding, prompt and model access controls,
and data handlingAssess the security implications of AI-enabled and agentic capabilities introduced into products, including third-party models, agents, and integrationsSupport security assessments for new technologies, integrations, and third-party solutionsCollaborate with Enterprise and Solution Architecture teams to apply reference security patternsProvide oversight and direction to Product Security Advisors (where applicable)Facilitate security decision-making and risk acceptance discussions with product and business stakeholdersMonitor security posture metrics and maturity improvements across the portfolioCoordinate security testing activities, including penetration testing and automated scanningPromote developer enablement through security education, guidance, and reusable patternsParticipate in architecture review boards and product governance forumsIdentify and deliver opportunities to automate and standardize security controls, applying agentic and AI-assisted approaches where they improve speed, consistency, or coverageSupport continuous improvement of the product security operating modelWork closely with Enterprise Architecture, Cloud, and DevOps teams, as well as across Cybersecurity & GRCQualificationsBachelor's degree in Information Technology, Computer Science, Engineering, or related fieldMinimum 8-10 years of IT experience with at least 3-5 years in security, architecture, or application developmentExperience with secure SDLC practices and threat modelingKnowledge of application, API, cloud,
and data security principlesExperience working with Agile / product-based delivery modelsStrong stakeholder management and communication skillsAbility to influence technical teams without direct authorityExperience working in large-scale enterprise environmentsSecurity certifications (CISSP, CSSLP, CCSP, or equivalent)Experience with DevSecOps tooling and CI/CD pipelinesFamiliarity with OWASP, NIST SSDF, or similar frameworksExperience in cloud-native architectures (AWS, Azure)Demonstrate punctuality and dependability to support overall team success in a fast-paced environment.
Assets: Hands-on experience with agentic development tools such as Anthropic's Claude Code, OpenAI Codex, GitHub Copilot, or comparable platformsExperience designing, securing, or operating AI gateways and associated access, logging, and data-protection controlsFamiliarity with emerging AI/LLM threat models and secure patterns for agent-based systemsConditions of Employment: Candidates must be eligible to work in the country of interest at the time any offer of employment is made and are responsible for obtaining any required work permits, visas, or other authorizations necessary for employment. Prior to their start date, candidates will also need to provide proof of their eligibility to work in the country of interest.
Linguistic RequirementsBased on equal qualifications, preference will be given to bilingual candidates.
Diversity and InclusionAir Canada is strongly committed to Diversity and Inclusion and aims to create a healthy, accessible and rewarding work environment which highlights employees' unique contributions to our company's success.
As an equal chance employer, we welcome applications from all to help us build a diverse workforce which reflects the diversity of our customers, and communities, in which we live and serve.
Air Canada thanks all candidates for their interest; however only those selected to continue in the process will be contacted.
📌 Partner, Product Security (Dorval)
🏢 Air Canada
📍 Dorval