Partner, Cybersecurity Governance, Risk and Compliance
- Montréal, QC
- Hybride
- Publié 8 sept. 2026
- 1 poste
Ouvre un site externe
- Type d’emploi
- Temps plein
- Niveau d’expérience
- Chef d’équipe · 12+ ans
- Formation minimale
- Diplôme professionnel
- Langue de l’offre
- anglais
- Heures de travail
- 40 heures par semaine
- Présence au bureau
- 4 jours par semaine
Résumé du poste
The Manager, Cybersecurity Governance, Risk & Compliance will establish and enforce cybersecurity governance across strategic transformation initiatives while designing a structured framework aligned with industry standards. This role involves modernizing cybersecurity policies, defining critical information assets, and integrating security into all business processes.
Détails du poste
WHO WE ARE At Air Canada Vacations, we’re in the business of making dreams travel. That’s why we offer vacation packages, tours, cruises and more tailored to everyone’s individual needs. We like to say we have a vacation for every traveller because we do! If you're someone who's passionate about exploring the world and sharing that enthusiasm with our customers, we'd love to welcome you to our team. For over 50 years, Air Canada Vacations has been making travel easy, so come and join us in helping fellow Canadians create unforgettable memories wherever they go. Don’t miss this opportunity! Submit your application by September 18, 2026 to be considered for this exciting opportunity. Job Title: Partner, Cybersecurity Governance, Risk and Compliance Department: IT - Operations Location: YUL Reporting Manager: Director, IT Operations, Infrastructure and Security Reporting to the Director, IT Operations, Infrastructure and Security. The Partner, Cybersecurity Governance, Risk & Compliance will be responsible for establishing and enforcing cybersecurity governance across strategic transformation initiatives (Juniper, CRM, CDP), while designing and implementing a structured cybersecurity framework for Air Canada Vacations aligned with industry standards (NIST or ISO 27002). This role will modernize cybersecurity policies, define and classify critical information assets, and ensure that cybersecurity is integrated into all projects and business processes from inception. WHAT YOU'LL BE DOING Cybersecurity Governance for Strategic Programs • Establish security governance structures for Juniper (Reservation System), CRM, CDP • Implement: o Security checkpoints and stage gates o Risk and compliance reviews within project lifecycle • Ensure alignment with: o Privacy requirements (PIA, data retention, etc.) o Architecture and Change Management processes • Enforce “secure by design” governance across all initiatives Cybersecurity Framework Development • Design and implement an enterprise cybersecurity framework for ACV based on NIST Cybersecurity Framework or ISO 27001 / 27002 controls • Define: o Control domains and control catalog o Security standards and procedures o Governance and accountability model Policy & Directive Modernization • Review, rationalize, and modernize Cybersecurity policies, directives and procedures • Align policies: o With Air Canada corporate standards where applicable o Reflect modern architectures (cloud, SaaS, APIs) • Establish clear policy lifecycle and governance model\ Enterprise Asset Management & Data Classification • Define and implement: o Enterprise asset inventory (applications, systems, data) o Data classification model (e.g., confidential, regulated, internal) • Identify: o Critical systems and business assets o Sensitive and regulated data sets • Ensure classification drives Access controls, Retention policies, and Security controls Risk Management & Compliance • Establish cybersecurity risk management framework: o Risk identification and assessment o Risk tracking and remediation • Formalize exception and risk acceptance processes AI Governance & Responsible Use • Define and implement AI governance framework including: o AI usage policies and directives o Risk and compliance controls for AI systems o Data usage and model governance standards • Establish: o Approval process for AI use cases o Monitoring and audit mechanisms for AI solutions • Ensure alignment with Air Canada enterprise policies (where applicable) WHAT YOU BRING TO THE TEAM • 8–12+ years in Cybersecurity governance / GRC and Risk management / Compliance • Certifications required (CISSP and / or CISM) • CRISC, an asset • ISO 27001 Lead Implementer or Lead Auditor, an asset • NIST Cybersecurity Framework Training Certification, an asset • CDMP, an asset • Proven experience: o Implementing NIST or ISO frameworks o Supporting large transformation programs o Establishing governance models o Exposure to AI/data governance initiatives • Good understanding of: o Data governance and classification o AI governance concepts (risk, ethics, controls) o Cloud and SaaS environments • Extremely organized and diligent in maintaining consistency • Autonomous and dedicated • Excellent communicator • Results oriented and the ability to manage multiple priorities with a sense of urgency and orientation to deadlines WHY WORK WITH US? Our team loves to travel, and we have one of the most generous employee travel programs in the industry. You’ll be eligible for travel privileges for yourself and other eligible persons once you’ve completed 6 months of service Hybrid work model: Corporate Mandate of 4 days in office (Tuesday, Wednesday, Thursday + 4th day of your choice) and 1 day from home We value your wellbeing and offer a wide variety of benefit plans, including health and dental, for you and your family We offer training and development tools to help unlock your full potential Please note that these benefits apply to permanent, full-time employees. Visit our Careers page for a full list of benefits. OUR COMMITMENT TO DIVERSITY, EQUITY, AND INCLUSION Air Canada Vacations is committed to ensuring a Diverse, Equitable, and Inclusive Workplace, fundamental to its core values. We celebrate the uniqueness of every individual, listen to every voice, and instill a sense of belonging in our people that allows each team member’s authentic self to truly shine. We encourage individuals of all backgrounds to apply as we strive to create a diverse team that mirrors the diversity of the customers and communities we serve as an equal opportunity employer. Should you require any accommodation, please inform us and we will work with you to meet your accessibility needs. For any accessibility-related assistance, requests for information in accessible alternative formats or to report any accessibility problems, please share in your application. Linguistic Requirements When qualifications are equal, preference will be given to bilingual candidates. The position involves daily interactions with partners, clients, and colleagues located outside of Quebec.
Ce que vous ferez
The Manager, Cybersecurity Governance, Risk & Compliance will establish and enforce cybersecurity governance across strategic transformation initiatives while designing a structured framework aligned with industry standards. This role involves modernizing cybersecurity policies, defining critical information assets, and integrating security into all business processes.
Exigences
Candidates must have 8–12+ years of experience in cybersecurity governance, risk management, and compliance. Professional certifications such as CISSP or CISM are required, with additional assets including CRISC, ISO 27001, and NIST framework training.
Avantages
• Employee travel program • Health insurance • Dental insurance • Training and development tools
Compétences indiquées
- Asset Management · Souhaitée
- Compliance · Souhaitée
- Risk Management · Souhaitée
- Communication · Souhaitée
- Gestion de projet · Souhaitée
Autres compétences pertinentes
Relevées dans la description du poste. Confirmez les exigences importantes ci-dessus.
- Cybersecurity governance
- Risk management
- Compliance
- NIST framework
- ISO 27001
- ISO 27002
- Data classification
- AI governance
- Policy modernization
- Asset management
- Cloud security
- SaaS security
- Strategic planning
- Communication
- Project management
- Cyber Governance
- Workplace Inclusivity
- Industry Standards
- Accountability
- NIST Cybersecurity Framework (CSF)
- Cyber Security Policies
- Juniper Network Technologies
- Cybersecurity Risk Management
- Security Governance
- Ethical Standards And Conduct
- Change Management Processes
- Access Controls
- Application Programming Interface (API)
- Artificial Intelligence
- Asset Management
- Auditing
- Multilingualism
- Customer Relationship Management
- Business Process
- Certified Information Systems Security Professional
- Certified Information Security Manager
- Software As A Service (SaaS)
- Security Controls
- Training And Development
- Certified In Risk And Information Systems Control
- Cyber Security
- Data Governance
- Data Retention
- Governance
- Governance Risk Management And Compliance
- Information Technology Operations
- ISO/IEC 27002
- ISO/IEC 27001
- Risk Management
- Systems Development Life Cycle
Domaines d’emploi
- Technology
- Security & Safety
- Management & Leadership
- Data & Analytics
- Consulting
- AI Governance Cybersecurity Consultant
- Cyber Security Manager / Administrator
- Database and Network Professionals Not Elsewhere Classified
- Information Security Engineers
- Computer Occupations, All Other
D’autres postes auxquels postuler directement
Des possibilités semblables publiées par des employeurs qui recrutent sur Jobs.ca, sans formulaire externe.
Connectability Inc.
Technical Sales Specialist
Employeur directCandidature simplifiée- Hybride
- Publié 5 sept. 2026
Korvell Rénovation Inc.
Manœuvre de chantier
CommanditéEmployeur directCandidature simplifiée- Sur place
- Montréal, QC
- Publié 17 sept. 2026
Bédard Ressources Humaines
Gestionnaire d'usine - Industrie alimentaire #1812
CommanditéEmployeur directCandidature simplifiée- Sur place
- Publié 9 sept. 2026