Being part of Air Canada is to become part of an iconic Canadian symbol, recently ranked the best Airline in North America. Let your career take flight by joining our diverse and vibrant team at the leading edge of passenger aviation.
The Analyst, IT & Cyber Compliance supports the design, execution and continuous improvement of the IT risk, cybersecurity compliance, and control assurance program. This role helps ensure that IT-operated processes, systems and controls align with regulatory, contractual and internal requirements, while enabling pragmatic risk-based decision-making across the organization.
This role will be reporting to the Manager, IT & Cybersecurity Compliance.
Responsibilities:
- Support the planning, execution and monitoring of IT risk, cybersecurity compliance, and control assurance activities across the enterprise.
- Assist in identifying, documenting and assessing IT and cybersecurity risks, including potential impact, likelihood, timeframe and mitigation approach.
- Maintain compliance action items, risk register updates, evidence requests and remediation tracking to support timely closure of audit and compliance obligations.
- Support compliance activities related to PCI DSS, SOC 2, NI 52-109, ISO and privacy requirements and other applicable IT and cybersecurity obligations.
- Coordinate with internal stakeholders, external auditors and enterprise risk groups to collect evidence, clarify control expectations, track issues, and communicate status.
- Review and analyze information from multiple internal and external stakeholders to identify themes, gaps, trends, and opportunities to improve control effectiveness.
- Prepare clear summaries, dashboards, recommendations, and briefing materials for IT, cybersecurity, risk, audit, and business stakeholders.
- Contribute to the development and maintenance of repeatable methods, templates, metrics and calculations used for risk assessment, control monitoring, and compliance reporting.
- Support business analysis activities, including process documentation, requirements gathering and technology/business integration efforts related to compliance initiatives.
- Promote consistent, risk-informed practices and contribute to continuous improvement of IT & Cyber Compliance processes, priorities, and objectives.
Qualifications
- University degree or technical certification, with 3+ years of practical experience in information technology, cybersecurity, audit, risk management, accounting, business or related field.
- Experience in IT audit, IT risk management, cybersecurity compliance, internal controls, or related governance/risk/compliance function.
- Exposure to one or more of the following is an asset: PCI DSS, SOC 2, NI 52-109, ISO 27001, NIST or similar control frameworks.
- Professional certifications or progress toward a certification are assets, such as CISA, CRISC, CISSP, CPA, or equivalent credentials.
- Strong analytical skills, with the ability to review evidence, interpret control requirements, identify gaps, and summarize findings clearly.
- Strong written and verbal communication skills, with the ability to adapt messages for technical, business, audit, and leadership audiences.
- Ability to work independently, organize competing priorities, and manage deadlines in a fast-moving environment.
- Collaborative working style, with the ability to build constructive relationships across IT, cybersecurity, risk, audit, legal, privacy, and business teams.
- Demonstrate punctuality and dependability to support overall team success in a fast-paced environment.
- Curiosity, sound judgement and continuous improvement mindset.
Conditions of Employment:
Candidates must be eligible to work in the country of interest at the time any offer of employment is made and are responsible for obtaining any required work permits, visas, or other authorizations necessary for employment. Prior to their start date, candidates will also need to provide proof of their eligibility to work in the country of interest.
Linguistic Requirements
Based on equal qualifications, preference will be given to bilingual candidates.
Diversity and Inclusion
Air Canada is strongly committed to Diversity and Inclusion and aims to create a healthy, accessible and rewarding work environment which highlights employees’ unique contributions to our company’s success.
As an equal opportunity employer, we welcome applications from all to help us build a diverse workforce which reflects the diversity of our customers, and communities, in which we live and serve.
Air Canada thanks all candidates for their interest; however only those selected to continue in the process will be contacted.