Lead AI risk analyst securing CBC/Radio-Canada’s public-service media technology. Designing enterprise AI governance, risk assessments and adversarial testing across the AI lifecycle.
Responsibilities
Design, build and lead the enterprise-wide governance, security and continuous risk management program for traditional and generative AI
Design and deploy an enterprise AI risk assessment framework
Conduct continuous evaluations of AI systems throughout the AI life cycle from design to production
Collaborate with data protection analysts, legal, compliance and enterprise architecture teams
Develop and implement standardized AI risk assessment methodologies, including ethical impact matrices, model criticality criteria, bias analysis, algorithmic vulnerability assessments and data exposure risks
Support the design, integration and evolution of the security foundation for AI technologies
Build and manage a centralized inventory of AI systems, models and agents, classified by risk level
Conduct technical risk evaluations of new AI use cases
Define and execute specialized security and adversarial testing for AI and LLMs
Evaluate the security posture, privacy controls and model-training policies of third-party AI and SaaS vendors
Analyze contractual data-use terms, SaaS API security and privacy guarantees
Maintain the AI risk register, documenting model vulnerabilities, technical debt and approved exceptions
Evaluate AI governance maturity and develop dashboards tracking KPIs and KRIs for executive and governance committees
Stay current on information security best practices and industry trends
Requirements
University degree in computer science, IT or information security
Minimum five years' applied experience in IT security, data governance or technology risk management
Experience designing or implementing risk assessment methodologies and evaluating AI models
Deep understanding of AI architectures and AI-specific attack vectors
Extensive knowledge of security technology and risk assessment methodologies, policies and processes
Excellent written and verbal communication skills
Excellent analytical, evaluative and problem-solving abilities
Experience with compliance programs and their technical and security requirements
Strong command of ISO/IEC 27001, 27002, 27005, NIST SP 800-53 / 800-161, COBIT and ITIL
Understanding of web infrastructure and cloud environment security
Understanding of network architectures, network security technologies and cryptographic principles
Working knowledge of database architecture concepts and secure software development best practices
Understanding of business continuity and disaster recovery planning, operational resilience and physical security controls
Bilingualism (English and French) essential
Candidates may be subject to skills and knowledge testing
Successful candidates must complete a mandatory criminal record check and other background checks as required
Benefits
Telework/hybrid work arrangement with a mix of in-office and remote work
Work with leading-edge data management, cloud, IP broadcasting, AI, security and reliability technologies
Inclusive workplace and equal opportunity
Accommodation support during the recruitment process
Security Analyst II protecting Intact’s insurance operations through incident response and SIEM monitoring. Supporting security platforms, incident resolution, dashboards, and IT security initiatives.
IT security analyst protecting Desjardins hardware, software, data, and access controls. Analyzing vulnerabilities, risks, and security processes while developing recommendations and action plans.
Analyste cybersécurité administrant et optimisant les plateformes protégeant les services essentiels de la Ville de Montréal. Déploiement de solutions, gestion des incidents et automatisation opérationnelle.
Analyste SOC détectant les menaces et répondant aux incidents pour I - TRACING, pure - player indépendant de la cybersécurité. Exploitation SIEM, analyse de vulnérabilités et suivi de remédiation.
Develop governance frameworks and lead cybersecurity project planning. Collaborate with stakeholders to enhance security posture in a financial environment.
Join TTC as a Cybersecurity Risk Specialist! Conduct risk assessments, maintain risk registers, and support mitigation strategies for a major public transit system.