Partner, Product Security

Air Canada

Dorval

On-site

CAD 120,000 - 180,000

Full time

6 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Air Canada is seeking a Partner, Product Security to lead security across a portfolio of digital products and platforms, partnering with product, engineering and architecture teams to embed secure-by-design practices throughout the product lifecycle.

The role emphasizes threat modeling, risk management, secure SDLC governance, and security posture leadership, with responsibilities spanning architecture reviews, testing coordination, AI gateway security, and ongoing risk mitigation.

Qualifications

  • Bachelor’s degree in IT, CS, engineering, or related field.
  • 8–10 years IT experience with 3–5 years in security, architecture, or application development.
  • Experience with secure SDLC practices and threat modeling.
  • Knowledge of application, API, cloud, and data security principles.
  • Experience working with Agile/product-based delivery models.
  • Strong stakeholder management and communication skills.
  • Ability to influence technical teams without direct authority.
  • Experience working in large-scale enterprise environments.
  • Security certifications (CISSP, CSSLP, CCSP, or equivalent).
  • Experience with DevSecOps tooling and CI/CD pipelines.
  • Familiarity with OWASP, NIST SSDF, or similar frameworks.
  • Experience in cloud-native architectures (AWS, Azure).
  • Demonstrate punctuality and dependability to support overall team success in a fast-paced environment.

Responsibilities

  • Own the product security posture for an assigned portfolio of products and platforms.
  • Lead security engagement across the full product lifecycle, from ideation through production.
  • Drive and oversee threat modeling for new and existing products, using agentic tooling to scale coverage and reduce manual effort.
  • Partner with product managers and engineering leads to embed secure-by-design practices into delivery workflows.
  • Provide risk-based security guidance during architecture and design reviews.
  • Ensure secure Product Development Lifecycle controls are implemented and consistently applied across development teams.
  • Track and manage security risks, vulnerabilities, and remediation priorities to closure.
  • Establish and govern secure usage patterns for agentic development tools and AI gateways, including guardrails for AI-assisted coding, prompt and model access controls, and data handling.
  • Assess the security implications of AI-enabled and agentic capabilities introduced into products, including third-party models, agents, and integrations.
  • Support security assessments for new technologies, integrations, and third-party solutions.
  • Collaborate with Enterprise and Solution Architecture teams to apply reference security patterns.
  • Provide oversight and direction to Product Security Advisors (where applicable).
  • Facilitate security decision-making and risk acceptance discussions with product and business stakeholders.
  • Monitor security posture metrics and maturity improvements across the portfolio.
  • Coordinate security testing activities, including penetration testing and automated scanning.
  • Promote developer enablement through security education, guidance, and reusable patterns.
  • Participate in architecture review boards and product governance forums.
  • Identify and deliver opportunities to automate and standardize security controls, applying agentic and AI-assisted approaches where they improve speed, consistency, or coverage.
  • Support continuous improvement of the product security operating model.
  • Work closely with Enterprise Architecture, Cloud, and DevOps teams, as well as across Cybersecurity & GRC.

Skills

Stakeholder management
Communication
Influence technical teams
Agile/product-based delivery
Security governance
Risk management
Security posture leadership

Education

Bachelor’s degree in IT/CS/Engineering

Tools

CI/CD pipelines

Job description

Being part of Air Canada is to become part of an iconic Canadian symbol, recently ranked the best Airline in North America. Let your career take flight by joining our diverse and vibrant team at the leading edge of passenger aviation.

The Partner, Product Security leads product security engagement across a portfolio of digital products and platforms, serving as the single point of entry into Cybersecurity & GRC for security support across IT, Data, & Digital (IDD). Partnering closely with product, engineering, and architecture teams, the incumbent ensures security is embedded throughout the product lifecycle - from ideation through to production deployment. Leveraging the organization's agentic capabilities, this role owns threat modeling, risk management, and secure-by-design practices, balancing delivery velocity against risk reduction. The Partner also provides security posture leadership for assigned portfolios and drives consistent application of secure SDLC controls and governance.

This position may be located in Montreal or Toronto.
Responsibilities
  • Own the product security posture for an assigned portfolio of products and platforms
  • Lead security engagement across the full product lifecycle, from ideation through production
  • Drive and oversee threat modeling for new and existing products, using agentic tooling to scale coverage and reduce manual effort
  • Partner with product managers and engineering leads to embed secure-by-design practices into delivery workflows
  • Provide risk-based security guidance during architecture and design reviews
  • Ensure secure Product Development Lifecycle controls are implemented and consistently applied across development teams
  • Track and manage security risks, vulnerabilities, and remediation priorities to closure
  • Establish and govern secure usage patterns for agentic development tools and AI gateways, including guardrails for AI-assisted coding, prompt and model access controls, and data handling
  • Assess the security implications of AI-enabled and agentic capabilities introduced into products, including third-party models, agents, and integrations
  • Support security assessments for new technologies, integrations, and third-party solutions
  • Collaborate with Enterprise and Solution Architecture teams to apply reference security patterns
  • Provide oversight and direction to Product Security Advisors (where applicable)
  • Facilitate security decision-making and risk acceptance discussions with product and business stakeholders
  • Monitor security posture metrics and maturity improvements across the portfolio
  • Coordinate security testing activities, including penetration testing and automated scanning
  • Promote developer enablement through security education, guidance, and reusable patterns
  • Participate in architecture review boards and product governance forums
  • Identify and deliver opportunities to automate and standardize security controls, applying agentic and AI-assisted approaches where they improve speed, consistency, or coverage
  • Support continuous improvement of the product security operating model
  • Work closely with Enterprise Architecture, Cloud, and DevOps teams, as well as across Cybersecurity & GRC
Qualifications
  • Bachelor’s degree in Information Technology, Computer Science, Engineering, or related field
  • Minimum 8–10 years of IT experience with at least 3–5 years in security, architecture, or application development
  • Experience with secure SDLC practices and threat modeling
  • Knowledge of application, API, cloud, and data security principles
  • Experience working with Agile / product-based delivery models
  • Strong stakeholder management and communication skills
  • Ability to influence technical teams without direct authority
  • Experience working in large-scale enterprise environments
  • Security certifications (CISSP, CSSLP, CCSP, or equivalent)
  • Experience with DevSecOps tooling and CI/CD pipelines
  • Familiarity with OWASP, NIST SSDF, or similar frameworks
  • Experience in cloud-native architectures (AWS, Azure)
  • Demonstrate punctuality and dependability to support overall team success in a fast-paced environment.
Assets
  • Hands-on experience with agentic development tools such as Anthropic's Claude Code, OpenAI Codex, GitHub Copilot, or comparable platforms
  • Experience designing, securing, or operating AI gateways and associated access, logging, and data-protection controls
  • Familiarity with emerging AI/LLM threat models and secure patterns for agent-based systems
Conditions Of Employment

Candidates must be eligible to work in the country of interest at the time any offer of employment is made and are responsible for obtaining any required work permits, visas, or other authorizations necessary for employment. Prior to their start date, candidates will also need to provide proof of their eligibility to work in the country of interest.

Linguistic Requirements

Based on equal qualifications, preference will be given to bilingual candidates.

Diversity and Inclusion

Air Canada is strongly committed to Diversity and Inclusion and aims to create a healthy, accessible and rewarding work environment which highlights employees’ unique contributions to our company’s success.

As an equal opportunity employer, we welcome applications from all to help us build a diverse workforce which reflects the diversity of our customers, and communities, in which we live and serve.

Air Canada thanks all candidates for their interest; however only those selected to continue in the process will be contacted.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Product Partner - Security
Product Partner - Security

AIR CANADA • Dorval

On-site
CAD 120,000 - 160,000
Outils DevSecOps et IA
Partenaire - Produits - Sûreté
Partenaire - Produits - Sûreté

Air Canada • Dorval

On-site
CAD 140,000 - 190,000
Partner, Cybersecurity Governance, Risk and Compliance
Partner, Cybersecurity Governance, Risk and Compliance

Air Canada Vacations • Montreal (administrative region)

On-site
CAD 120,000 - 180,000
Travel privileges
Hybrid work model
Health & dental benefits
+1
Product Owner - Marketing Technology
Product Owner - Marketing Technology

Air Canada • Toronto

On-site
CAD 90,000 - 130,000
Bilingual English and French
Senior Staff Cloud Security Engineer – Financial Services - Office of the CISO
Senior Staff Cloud Security Engineer – Financial Services - Office of the CISO

ServiceNow • Toronto

On-site
CAD 120,000 - 180,000
C-IT-200 Product Cybersecurity Specialist Intern
C-IT-200 Product Cybersecurity Specialist Intern

CAE Inc • Montreal (administrative region)

Hybrid
CAD 13,000 - 20,000
Free parking
Gym and wellness facilities
Hybrid work model
C-IT-200 Product Cybersecurity Specialist Intern-EN
C-IT-200 Product Cybersecurity Specialist Intern-EN

CAE • Montreal (administrative region)

Hybrid
CAD 13,000 - 20,000
Flexible schedules and work from home
Open concept Workspace
Internship cost reimbursement up to $加
+5
Technical Analyst (New Capability Distribution)
Technical Analyst (New Capability Distribution)

Socket.dev • Toronto

On-site
CAD 75,000 - 110,000
Partner, Strategy and Programs/Partenaire - Stratégie et Programmes
Partner, Strategy and Programs/Partenaire - Stratégie et Programmes

Air Canada • Toronto

On-site
CAD 80,000 - 100,000
Airport Operations Manager
Airport Operations Manager

AIR CANADA • Halifax, Quebec

On-site
CAD 90,000 - 120,000