- Company Name
- Air Canada
- Job Title
- Specialist, IT and Cybersecurity Risk
- Job Description
-
**Job Title:** Specialist, IT and Cybersecurity Risk
**Role Summary:**
Responsible for assessing, managing, and mitigating IT and cybersecurity risks across enterprise and OT systems. Acts as a subject‑matter expert, leading third‑party risk assessments, embedding security controls into vendor agreements, and driving continuous improvement of the organization’s security posture.
**Expectations:**
- Deliver comprehensive risk assessments and remediation plans for internal and third‑party environments.
- Translate complex threat landscapes into actionable controls aligned with corporate strategy.
- Produce metrics, KPIs, and risk indicators to inform senior leadership.
- Foster collaboration across procurement, operations, and security teams.
**Key Responsibilities:**
1. Collaborate with procurement to onboard and monitor third‑party vendors, ensuring compliance with security policies.
2. Lead initial, ongoing, and post‑contact risk assessments for outsourced and internal IT/OT environments.
3. Ensure cybersecurity clauses and controls are integrated into vendor contracts.
4. Manage risk lifecycle: identify, document, prioritize, and remediated risks and defects.
5. Generate and present IT/Cybersecurity risk reports, KPI dashboards, and KRI insights.
6. Design and propose best‑practice solutions and mitigation controls.
7. Introduce and champion new processes to enhance risk management practices.
8. Represent the organization in industry‑specific cybersecurity forums and initiatives.
9. Support strategic projects aligned with portfolio objectives.
**Required Skills:**
- Deep knowledge of IT and cybersecurity risk frameworks (e.g., NIST, ISO 27001, COBIT, PCI DSS, SOX, GDPR, PIPEDA).
- Expertise in vulnerability assessment tools, penetration testing, application security testing, and tabletop exercises.
- Proficiency in risk assessment methodology, threat modeling, and risk mitigation strategy.
- Strong analytical, organizational, and communication abilities.
- Ability to influence cross‑functional teams and build business relationships.
- Self‑motivated, results‑oriented, and capable of managing multiple priorities under pressure.
**Required Education & Certifications:**
- Bachelor’s degree in Computer Science, Information Security, or related field (or equivalent experience).
- Minimum 6‑8 years of IT operations and governance experience, with at least 4 years in IT/cybersecurity risk & compliance.
- Current professional security certification (CISSP, CISM, or equivalent) is an asset.