Cybersecurity & Compliance Leader (CCL)
Pratt & Whitney
View all the job opportunities for this companyAbout Pratt & Whitney Canada
Pratt & Whitney Canada (P&WC) is a global leader in aerospace innovation, proudly headquartered in Longueuil, Quebec, since 1928. We design and manufacture next-generation aircraft engines that power the world's largest fleet of business, general aviation, and regional aircraft and helicopters.
For nearly 100 years, our teams have been at the forefront of propulsion technology, pushing boundaries to make flight more efficient and reliable. Our engines support missions that truly matter, from transporting people and essential goods, to enabling emergency medical services, humanitarian operations, and wildfire suppression around the world.
An Employer of Choice
Pratt & Whitney Canada was named one of Canada's Best Employers for 2026 by Forbes, marking the 11th consecutive year the company has earned this recognition. Pratt & Whitney Canada also ranked #1 employer in the aerospace and defense industry in the country. In addition, our headquarters continues to be recognized among the top employers in the Montreal region.
Together, these distinctions reinforce our reputation as an employer of choice in Montreal, across Canada, and around the world.
Why Join Pratt & Whitney Canada's Digital Technology Team?
We are on a digital transformation journey, redefining how we work, optimizing operations and transforming products and services to elevate employee and customer experiences.
As part of our Digital Technology team, you'll help shape the future, working with advanced tools, automating processes and innovating across all business functions. Our global organization is committed to cultivating an empowered and skilled team to bring advanced solutions and leading-edge digital capabilities to market for our customers.
Position Summary
The RTX Pratt & Whitney Cybersecurity organization is seeking a highly motivated and experienced Cybersecurity & Compliance Leader (CCL) to serve as a strategic partner to assigned business domains. This role sits at the intersection of cyber risk, compliance, and business operations, ensuring that enterprise cybersecurity priorities are understood, adopted, and executed within the business while providing leadership visibility into local risk posture.
The CCL is a trusted advisor, risk translator, and business-facing liaison, responsible for aligning cyber and compliance requirements with business objectives, driving risk governance, and ensuring readiness for internal and external regulatory expectations. The role is a key contributor to Pratt & Whitney's Cyber Mission Assurance and overall enterprise cyber posture.
CCLs are not operators—they drive risk ownership, clarity, and business action, ensuring cyber enables mission success, operational continuity, and customer trust. This CCL will also be responsible for establishing a DT Controls program, in partnership with Enterprise Services, to ensure we're validating the work done at the 1st line of defense independently of the other lines.
Our Team's Guiding Principles
- Business First, Cyber Always: Every engagement starts with business outcomes and ends with secure enablement.
- Standardize Where Possible, Tailor Where Needed: Consistency breeds efficiency; flexibility ensures relevance.
- Proactive over Reactive: Drive forward deployment and early alignment, not last-minute fire drills.
- One Team, Many Voices: Maintain unity across CMS while respecting each BU's unique mission and terrain.
What will your day-to-day look like?
Cyber & Compliance Risk Leadership
- Serve as the single, business-facing point of accountability for cyber & compliance risk posture within assigned domains.
- Provide an integrated view of risks spanning IT, OT, cloud, engineering, suppliers, and regulatory environments.
- Ensure risk decisions are owned, resourced, and prioritized by the business.
Business Partnership & Strategic Alignment
- Embed cybersecurity considerations into business strategies, programs, and major initiatives (e.g., modernization, engineering systems, manufacturing operations).
- Represent business needs to the cybersecurity, compliance, and Digital Technology organizations to ensure alignment and prioritization.
- Translate enterprise cyber strategy, standards, and roadmaps into actionable, business-relevant plans.
Governance, Accountability & Risk Reviews
- Lead business-facing cyber and compliance governance forums, including risk reviews, program touchpoints, and compliance readiness discussions.
- Ensure traceability and follow-through on mitigation actions, funding decisions, and risk acceptance.
- Provide leaders with clear, concise, and actionable insights on posture, gaps, and progress.
Compliance Readiness & Sustainment
- Partner with internal and external stakeholders to maintain audit readiness across relevant regulatory frameworks (e.g., CMMC, government customer requirements, RTX policies).
- Identify control gaps, coordinate business remediation, and ensure evidence and documentation are complete and accurate.
Communication, Change Management & Stakeholder Engagement
- Communicate cyber risks, policies, and changes in a clear, tailored, business-friendly manner.
- Influence leaders and teams through relationship-building and strong cross-functional partnerships.
- Drive awareness and cultural adoption of secure behaviors and compliance obligations.
Performance Measurement & Continuous Improvement
- Define and socialize KPIs, metrics, and indicators of cyber posture aligned with enterprise models.
- Identify systemic trends and improvement opportunities; partner with technical teams to shape solutions.
- Promote optimization, innovation, and CORE principles in support of operational excellence.
- CORE Principles: Drive best practices using RTX CORE (Customer Oriented Results and Excellence) principles to foster innovation and operational efficiency.
What do you need to be successful?
Required Qualifications
- Bachelor's Degree from an accredited college or university in Computer Science, Computer Engineering, Cybersecurity or a related discipline with 12+ years of prior relevant experience OR Advanced Degree in a related field and 10+ years of experience.
- Strong comprehension of information security practices/frameworks including identifying risks, emerging cyber security threats, and risk mitigation processes.
- Demonstrated experience across more than one cybersecurity discipline (e.g., security architecture, compliance, vulnerability management, incident response, application security).
- Demonstrated experience in team leadership and ability to lead through influence to drive creation and execution of operational plans and service delivery.
- Ability to write succinct briefings, presentations, and reports to convey analysis, trends, strategies and then use effective communication skills to present analytical data and tailor the message to a variety of technical and non-technical audiences.
- Strong deductive reasoning, critical thinking, prioritization and follow through with attention to detail while seeking opportunities to innovate and excel.
Preferred Qualifications
- Ability to effectively lead and inspire cross-functional teams by leveraging influence, fostering collaboration and building consensus to drive cybersecurity initiatives and enhance security posture.
- Adept at understanding business strategy, planning, processes, ability to inject cybersecurity into the business through teamwork and influence.
- Able to attain and preserve credibility with the team through sustained cyber, digital and/or aerospace & defense industry knowledge.
- Adaptive to change and comfortable with navigating complex, evolving organization structures.
- Passion in working with customers and functional partners, building strong trust relationships, and championing an inclusive environment that encourages different viewpoints and ideas.
- Knowledgeable in Agile development, related concepts, and execution.
- Certified security expert CISSP, CEH, GEVA, or similar.
What do we offer?
- Pension and savings plan with employer contributions
- Group insurance program
- Opportunities for advancement (career progression)
- Merit or recognition program
- Health and wellness program, including virtual health care
- Recreational and sports club
- Nearby daycares
- Transportation accessibility or public transit program and free parking
Working at Pratt & Whitney Canada
The masculine pronoun is used without discrimination and solely for the purpose of making the text easier to read. We will consider applications from all qualified candidates.
At Pratt & Whitney Canada, we combine passion, boldness, and precision to design, manufacture, and maintain the most advanced and reliable aircraft engines in the world. Our work and the quality of our products contribute to the success of our customers, who in turn save lives, support commerce, connect communities, and protect freedoms.
At Pratt & Whitney Canada, you have the opportunity to make a difference every day—just look up. Are you ready to go beyond?
The selected candidate will be required to complete a criminal background check and any applicable clearances with respect to the handling and transfer of controlled goods. Employment is conditional upon the successful completion of these checks and obtaining the required clearances. Failure to do so will result in the withdrawal of the employment offer.
Details
- City
- Montréal, Québec
Need help?
- support@aerowork.ca
- Phone
- 1-450-403-4300