Analyst - Compliance - IT and Cybersecurity
AIR CANADA
View all the job opportunities for this companyBelonging to Air Canada is akin to belonging to a Canadian symbol, Air Canada recently voted best airline in North America. Take your career to new heights by joining our innovative and diverse team at the forefront of passenger air transport.
The Analyst – Compliance – IT and Cybersecurity supports the design, execution, and continuous improvement of the IT risk management, cybersecurity compliance, and control assurance program. This position helps ensure that processes, systems, and controls managed by IT comply with regulatory, contractual, and internal requirements, while promoting pragmatic, risk-based decision-making across the organization.
This position reports to the Manager – Compliance – IT and Cybersecurity.
Responsibilities:
- Support the planning, execution, and monitoring of IT risks, cybersecurity compliance, and control assurance activities across the enterprise.
- Contribute to the establishment, documentation, and evaluation of IT and cybersecurity risks, including their potential impact, likelihood, timeline, and mitigation measures.
- Maintain compliance tracking measures, risk register updates, evidence requests, and corrective action tracking to facilitate timely resolution of audit and compliance obligations.
- Support compliance activities related to PCI DSS and SOC 2 standards, Regulation 52-109, ISO requirements, privacy requirements, and other applicable IT and cybersecurity obligations.
- Coordinate with internal stakeholders, external auditors, and enterprise risk management groups to gather evidence, clarify control expectations, track issues, and communicate progress.
- Review and analyze information from various internal and external stakeholders to identify themes, gaps, trends, and opportunities to improve control effectiveness.
- Prepare clear summaries, dashboards, recommendations, and briefing materials for business stakeholders as well as stakeholders in IT, Cybersecurity, Risk, and Audit.
- Contribute to the establishment and maintenance of reproducible methods, models, metrics, and calculations used for risk assessment, control monitoring, and compliance reporting.
- Support operational analysis activities, including process documentation, requirements gathering, and technology and operational integration efforts related to compliance initiatives.
- Promote consistent practices based on risk assessment; contribute to the continuous improvement of the processes, priorities, and objectives of the Compliance – IT and Cybersecurity team.
Qualifications
- University degree or technical certification; at least three years of practical experience in information technology, cybersecurity, auditing, risk management, accounting, business, or a related field.
- Experience in IT audits, IT risk management, cybersecurity compliance, internal controls, or a related governance, risk, or compliance function.
- Experience in one or more of the following areas is an asset: PCI DSS, SOC 2, Regulation 52-109, ISO 27001, NIST, or similar control frameworks.
- Professional certifications or progress toward obtaining a certification, such as CISA, CRISC, CISSP, CPA, or any other equivalent certification, is an asset.
- Strong analytical skills and ability to review evidence, interpret control requirements, identify gaps, and clearly summarize conclusions.
- Strong written and oral communication skills; ability to tailor messages to technical, business, audit, and management audiences.
- Ability to work independently, organize competing priorities, and manage deadlines in a fast-paced environment.
- Spirit of collaboration; ability to build constructive relationships with teams in IT, Cybersecurity, Risk Management, Audit, Legal Affairs, Privacy, and Commercial Affairs.
- Demonstrated punctuality and reliability to foster the team's overall success in a fast-paced environment.
- Curiosity, sound judgment, and an attitude focused on continuous improvement.
Conditions of Employment:
Candidates must be eligible to work in the country concerned at the time an offer of employment is presented and are responsible for obtaining work permits, visas, or other necessary authorizations. Proof of eligibility must be provided prior to the start date.
Linguistic Requirements
All things being equal, preference will be given to bilingual candidates.
Diversity and Inclusion
Air Canada is strongly committed to diversity and inclusion and aims to create a healthy, accessible, and rewarding workplace that highlights the unique contribution of our employees to our company's success.
As an equal opportunity employer, we encourage diverse applications so that we can build a workforce that is varied and representative of our customers and the communities where we live and offer our services.
Air Canada thanks all candidates for their interest, but only those selected for an interview will be contacted.
Details
- City
- DORVAL, QUÉBEC, CANADA
Need help?
- support@aerowork.ca
- Phone
- 1-450-403-4300