Partner, Cybersecurity Governance, Risk and Compliance (24 Month Contract) (Montreal)

Partner, Cybersecurity Governance, Risk and Compliance (24 Month Contract) (Montreal)

04 Oct
|
Vacances Air Canada / Air Canada Vacations
|
Montreal

04 Oct

Vacances Air Canada / Air Canada Vacations

Montreal

Job Title: Partner, Cybersecurity Governance, Risk and Compliance

Department: IT - Operations

Location: YUL

Reporting Manager: Director, IT Operations, Infrastructure and Security

October 12, 2026

24-month temporary, onsite positionn

Reporting to the Director, IT Operations, Infrastructure and Security. The Partner, Cybersecurity Governance, Risk & Compliance will be responsible for establishing and enforcing cybersecurity governance across strategic transformation initiatives (Juniper, CRM, CDP), while designing and implementing a structured cybersecurity framework for Air Canada Vacations aligned with industry standards (NIST or ISO 27002).

This role will modernize cybersecurity policies, define and classify critical information assets, and ensure that cybersecurity is integrated into all projects and business processes from inception.

WHAT YOU'LL BE DOING

Cybersecurity Governance for Strategic Programs

- Establish security governance structures for Juniper (Reservation System), CRM, CDP
- Implement:
- Security checkpoints and stage gates
- Risk and compliance reviews within project lifecycle

- Ensure alignment with:

- Privacy requirements (PIA, data retention, etc.)
- Architecture and Change Management processes

- Enforce “secure by design” governance across all initiatives

Cybersecurity Framework Development

- Design and implement an enterprise cybersecurity framework for ACV based on NIST Cybersecurity Framework or ISO 27001 / 27002 controls
- Define:




- Control domains and control catalog
- Security standards and procedures
- Governance and accountability model

Policy & Directive Modernization

- Review, rationalize, and modernize Cybersecurity policies, directives and procedures
- Align policies:
- With Air Canada corporate standards where applicable
- Reflect contemporary architectures (cloud, SaaS, APIs)

- Establish clear policy lifecycle and governance model

Enterprise Asset Management & Data Classification

- Define and implement:
- Enterprise asset inventory (applications, systems, data)
- Data classification model (e.g., confidential, regulated, internal)

- Identify:

- Critical systems and business assets
- Sensitive and regulated data sets

- Ensure classification drives Access controls, Retention policies, and Security controls

Risk Management & Compliance

- Establish cybersecurity risk management framework:
- Risk identification and assessment
- Risk tracking and remediation

- Formalize exception and risk acceptance processes

AI Governance & Responsible Use

- Define and implement AI governance framework including:
- AI usage policies and directives
- Risk and compliance controls for AI systems
- Data usage and model governance standards

- Establish:

- Approval process for AI use cases
- Monitoring and audit mechanisms for AI solutions

- Ensure alignment with Air Canada enterprise policies (where applicable)

WHAT YOU BRING TO THE TEAM

#J-18808-Ljbffr

📌 Partner, Cybersecurity Governance, Risk and Compliance (24 Month Contract) (Montreal)
🏢 Vacances Air Canada / Air Canada Vacations
📍 Montreal

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: partner, cybersecurity governance, risk and compliance (24 month contract) (montreal) / montreal

Subscribe to this job alert:

Get the latest job offers by email for: partner, cybersecurity governance, risk and compliance (24 month contract) (montreal) / montreal