IT & Cyber Compliance Analyst
Air Canada
- Location
- DORVAL, QUEBEC, CANADA
- Employment
- Full Time
- Work model
- On-Site
- Level
- Mid
- Posted
- 2h ago
Skills
About this role
<p><span style="font-family:Arial, Helvetica, sans-serif;font-size:14px;"><strong>Being part of Air Canada is to become part of an iconic Canadian symbol, recently ranked the best Airline in North America. Let your career take flight by joining our diverse and vibrant team at the leading edge of passenger aviation.</strong></span></p><p><span style="font-family:Arial, Helvetica, sans-serif;font-size:14px;">The Analyst, IT & Cyber Compliance supports the design, execution and continuous improvement of the IT risk, cybersecurity compliance, and control assurance program. This role helps ensure that IT-operated processes, systems and controls align with regulatory, contractual and internal requirements, while enabling pragmatic risk-based decision-making across the organization. </span><br><br><span style="font-family:Arial, Helvetica, sans-serif;font-size:14px;">This role will be reporting to the Manager, IT & Cybersecurity Compliance.</span></p><p><span style="font-family:Arial, Helvetica, sans-serif;font-size:14px;"><strong>Responsibilities:</strong></span></p><ul><li><span style="font-family:Arial, Helvetica, sans-serif;font-size:14px;">Support the planning, execution and monitoring of IT risk, cybersecurity compliance, and control assurance activities across the enterprise.</span></li><li><span style="font-family:Arial, Helvetica, sans-serif;font-size:14px;">Assist in identifying, documenting and assessing IT and cybersecurity risks, including potential impact, likelihood, timeframe and mitigation approach.</span></li><li><span style="font-family:Arial, Helvetica, sans-serif;font-size:14px;">Maintain compliance action items, risk register updates, evidence requests and remediation tracking to support timely closure of audit and compliance obligations.</span></li><li><span style="font-family:Arial, Helvetica, sans-serif;font-size:14px;">Support compliance activities related to PCI DSS, SOC 2, NI 52-109, ISO and privacy requirements and other applicable IT and cybersecurity obligations.</span></li><li><span style="font-family:Arial, Helvetica, sans-serif;font-size:14px;">Coordinate with internal stakeholders, external auditors and enterprise risk groups to collect evidence, clarify control expectations, track issues, and communicate status.</span></li><li><span style="font-family:Arial, Helvetica, sans-serif;font-size:14px;">Review and analyze information from multiple internal and external stakeholders to identify themes, gaps, trends, and opportunities to improve control effectiveness.</span></li><li><span style="font-family:Arial, Helvetica, sans-serif;font-size:14px;">Prepare clear summaries, dashboards, recommendations, and briefing materials for IT, cybersecurity, risk, audit, and business stakeholders.</span></li><li><span style="font-family:Arial, Helvetica, sans-serif;font-size:14px;">Contribute to the development and maintenance of repeatable methods, templates, metrics and calculations used for risk assessment, control monitoring, and compliance reporting.</span></li><li><span style="font-family:Arial, Helvetica, sans-serif;font-size:14px;">Support business analysis activities, including process documentation, requirements gathering and technology/business integration efforts related to compliance initiatives.</span></li><li><span style="font-family:Arial, Helvetica, sans-serif;font-size:14px;">Promote consistent, risk-informed practices and contribute to continuous improvement of IT & Cyber Compliance processes, priorities, and objectives. </span></li></ul><p><strong>Qualifications</strong></p><ul><li><span style="font-family:Arial, Helvetica, sans-serif;font-size:14px;">University degree or technical certification, with 3+ years of practical experience in information technology, cybersecurity, audit, risk management, accounting, business or related field.</span></li><li><span style="font-family:Arial, Helvetica, sans-serif;font-size:14px;">Experience in IT audit, IT risk management, cybersecurity compliance, internal controls, or related governance/risk/compliance function.</span></li><li><span style="font-family:Arial, Helvetica, sans-serif;font-size:14px;">Exposure to one or more of the following is an asset: PCI DSS, SOC 2, NI 52-109, ISO 27001, NIST or similar control frameworks.</span></li><li><span style="font-family:Arial, Helvetica, sans-serif;font-size:14px;">Professional certifications or progress toward a certification are assets, such as CISA, CRISC, CISSP, CPA, or equivalent credentials.</span></li><li><span style="font-family:Arial, Helvetica, sans-serif;font-size:14px;">Strong analytical skills, with the ability to review evidence, interpret control requirements, identify gaps, and summarize findings clearly.</span></li><li><span style="font-family:Arial, Helvetica, sans-serif;font-size:14px;">Strong written and verbal communication skills, with the ability to adapt messages for technical, business, audit, and leadership audiences.</span></li><li><span style="font-family:Arial, Helvetica, sans-serif;font-size:14px;">Ability to work independently, organize competing priorities, and manage deadlines in a fast-moving environment.</span></li><li><span style="font-family:Arial, Helvetica, sans-serif;font-size:14px;">Collaborative working style, with the ability to build constructive relationships across IT, cybersecurity, risk, audit, legal, privacy, and business teams.</span></li><li><span style="font-family:Arial, Helvetica, sans-serif;font-size:14px;">Demonstrate punctuality and dependability to support overall team success in a fast-paced environment.</span></li><li><span style="font-family:Arial, Helvetica, sans-serif;font-size:14px;">Curiosity, sound judgement and continuous improvement mindset.</span></li></ul><p><span style="font-family:Arial, Helvetica, sans-serif;font-size:14px;"><strong>Conditions of Employment:</strong></span></p><p><span style="font-family:Arial, Helvetica, sans-serif;font-size:14px;">Candidates must be eligible to work in the country of interest at the time any offer of employment is made and are responsible for obtaining any required work permits, visas, or other authorizations necessary for employment. Prior to their start date, candidates will also need to provide proof of their eligibility to work in the country of interest.</span></p><p><span style="font-family:Arial, Helvetica, sans-serif;font-size:14px;"><strong>Linguistic Requirements</strong></span></p><p><span style="font-family:Arial, Helvetica, sans-serif;font-size:14px;">Based on equal qualifications, preference will be given to bilingual candidates.</span></p><p><span style="font-family:Arial, Helvetica, sans-serif;font-size:14px;"><strong>Diversity and Inclusion</strong></span></p><p><span style="font-family:Arial, Helvetica, sans-serif;font-size:14px;">Air Canada is strongly committed to Diversity and Inclusion and aims to create a healthy, accessible and rewarding work environment which highlights employees’ unique contributions to our company’s success.</span></p><p><span style="font-family:Arial, Helvetica, sans-serif;font-size:14px;">As an equal opportunity employer, we welcome applications from all to help us build a diverse workforce which reflects the diversity of our customers, and communities, in which we live and serve.</span></p><p><span style="font-family:Arial, Helvetica, sans-serif;font-size:14px;"><strong>Air Canada thanks all candidates for their interest; however only those selected to continue in the process will be contacted.</strong></span></p>