Enable job alerts via email!

Director, Privacy Risk & Compliance

Equitable Bank

Toronto

Hybrid

CAD 150,000 - 200,000

Full time

9 days ago

Job summary

A Canadian financial institution is seeking a Privacy Risk Management Lead in Toronto to develop and enhance its privacy risk management program. This role involves oversight of compliance with privacy laws and regulations, as well as leading a team of privacy professionals. The ideal candidate has substantial experience in privacy and risk management, along with a strong understanding of Canadian privacy laws. Competitive benefits and a hybrid work model are offered.

Benefits

Competitive discretionary bonus
Market-leading RRSP match program
Medical, dental, vision, life, and disability benefits
Employee Share Purchase Plan
Generous vacation policy and personal days
Annual professional development allowance
Comprehensive Career Development program

Qualifications

  • 7-10 years of progressive experience in privacy, compliance, or risk management roles.
  • Proven experience in designing and operationalizing privacy risk management programs.
  • Strong analytical, communication, and stakeholder engagement skills.

Responsibilities

  • Develop and enhance the Privacy Risk Management Program.
  • Oversee compliance with privacy laws and regulations.
  • Lead a team of privacy professionals.

Skills

Privacy Risk Management
Compliance Oversight
Leadership
Analytical Skills

Education

University degree in Law, Business, Risk Management, or related field
CIPP / C, CIPM or equivalent certification

Job description

Privacy Risk Management Program

  • Lead the ongoing development, implementation, and enhancement of the Bank’s enterprise-wide Privacy Risk Management Program.
  • Support the Chief Privacy Officer in developing privacy strategies aligned with the Bank’s risk appetite and regulatory expectations.
  • Oversee the Bank’s privacy risk assessment framework, including PIAs (Privacy Impact Assessments), risk reviews, and mitigation strategies.
  • Drive the integration of privacy by design principles into product development, technology initiatives, and data governance practices.

Regulatory Compliance Management (RCM) for Privacy

  • Serve as 2nd Line of Defense overseeing the Bank’s compliance with privacy laws, regulations, and key guidance documents.
  • Oversee identification, documentation, and communication of privacy-related regulatory requirements and controls.
  • Ensure appropriate controls, processes, and testing are in place to meet compliance expectations under OSFI’s RCM Guideline E-13 and other applicable requirements.
  • Monitor and report on the effectiveness of privacy controls and escalate deficiencies to senior leadership and governance committees.
  • Own and champion the Bank’s Enterprise Privacy Policy, working cross-functionally to ensure a robust and compliant privacy posture.

Leadership & Advisory

  • Act as a trusted advisor to senior executives, legal, risk, and business leaders on privacy risks, trends, and emerging regulations.
  • Lead a team of privacy professionals; mentor, coach, and develop staff to support the privacy compliance agenda.
  • Represent the Bank in industry forums and regulatory discussions related to privacy and data protection.

Monitoring & Incident Management

  • Oversee privacy incident response, breach investigation, and regulatory reporting protocols.
  • Conduct root cause analysis and recommend enhancements to prevent recurrence of privacy breaches.

Training & Awareness

  • Develop and implement a privacy training and awareness strategy tailored to diverse employee groups and risk levels.
  • Promote a culture of privacy and ethical data handling throughout the organization.

People Leadership & Team Management

  • Lead, mentor, and develop a team of compliance professionals, ensuring high standards of performance, engagement, and professional growth.
  • Set clear goals, provide regular feedback, and conduct performance and talent development reviews.
  • Foster a team culture built on collaboration, integrity, inclusion, and continuous improvement.
  • Identify and address resourcing needs, including succession planning and upskilling to support evolving compliance requirements.
  • Encourage innovation in compliance methodologies, use of data, and technology-enabled solutions.

Let's About Talk You!

  • University degree in Law, Business, Risk Management, or a related field; CIPP / C, CIPM, or equivalent privacy certification is strongly preferred.
  • 7-10 years of progressive experience in privacy, compliance, or risk management roles, preferably within financial services or regulated sectors.
  • Proven experience designing and operationalizing privacy risk management programs in complex environments.
  • Deep knowledge of Canadian privacy laws (PIPEDA, CPPA, provincial equivalents), and a strong understanding of global privacy frameworks (e.g., GDPR, CCPA) is a plus.
  • Familiarity with OSFI guidelines, especially E-13 (RCM) and E-21 (Operational Resilience), is an asset.
  • Strategic mindset with ability to translate legal / regulatory requirements into operational solutions.
  • Strong analytical, communication, and stakeholder engagement skills.
  • Demonstrated leadership and team management capabilities.
  • High level of integrity, discretion, and professionalism.

What we offer [For full-time permanent roles]: Competitive discretionary bonus, market-leading RRSP match program, medical, dental, vision, life, and disability benefits, Employee Share Purchase Plan, maternity/parental top-up, generous vacation policy and personal days, virtual events, annual professional development allowance, and a comprehensive Career Development program. The role involves hybrid working with in-office time at Equitable Bank’s office located at 2200-25 Ontario Street, Toronto, ON.

Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.

Similar jobs