Privacy Operations Manager

Vivid Soft Global

Toronto

On-site

CAD 110,000 - 160,000

Full time

43 hours ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Vivid Soft Global is seeking a Privacy Operations Manager to run day-to-day privacy operations for a healthcare-sector client engagement. The role involves managing a distributed team of privacy analysts and the service desk, handling PHI access/correction requests, consent operations, and incident intake within PHIPA timelines.

You will oversee privacy logging, audits, and reporting, align runbooks to PHIPA, FIPPA, and client policy updates, and collaborate with security and ITSM teams to embed

Qualifications

  • 5+ years in privacy operations or information governance in regulated environments
  • 4+ years hands-on service desk/privacy ops at scale
  • 4+ years processing PHI access/correction requests
  • 3+ years administering consent management
  • 3+ years privacy incident/breach handling
  • 3+ years log/audit review and evidence preservation
  • 3+ years audit, compliance, reporting for stakeholders
  • 3+ years knowledge of PHIPA, FIPPA, PIPEDA in operations
  • 2+ years supervising/mentoring analysts or service desk agents
  • 2+ years in consulting/client-facing roles
  • Experience with ITSM platforms (ServiceNow/Jira) and case/log tooling
  • Privacy certifications (or active progress)
  • Eligibility for background screening and security clearance
  • Bachelor’s degree in Health Informatics/Information Management/Engineering/Technology/IS

Responsibilities

  • Run day-to-day privacy operations, manage service desk intake, triage, prioritization, and SLA adherence
  • Handle PHI access and correction requests including identity verification and redaction review
  • Administer consent directives, withdrawals, overrides, and documentation
  • Oversee privacy incident and breach processes from intake to escalation
  • Manage privacy logging operations, configuration, retention and log reviews
  • Provide privacy audit/compliance reporting on demand and on schedule
  • Maintain runbooks, SOPs, and templates aligned to PHIPA, FIPPA, and policy updates
  • Supervise a distributed privacy analyst team with workload allocation and performance management
  • Coordinate with security, ITSM, and app support to embed privacy controls in workflows
  • Support internal audits, client assurance reviews, and regulator requests with evidence packages
  • Advise stakeholders on operational privacy risk and process improvements
  • Drive continuous improvement through automation and tooling enhancements

Skills

Privacy ops
Service desk
PHI requests
Consent mgmt
Breach handling
Log auditing
Audit reporting
PHIPA/FIPPA/PIPEDA
Team supervision
Consulting/client-facing
ITSM (ServiceNow/Jira)
Privacy certs
Background screening

Education

Bachelor's degree in related field

Tools

ServiceNow/Jira Service Management

Job description

Client Preferrances to someone who are local to Ontario

Job Description:

We're seeking a Privacy Operations Manager to run day-to-day privacy operations for a healthcare-sector client engagement — managing the privacy service desk, PHI access/correction request handling, consent operations, and incident intake/containment, while supervising a distributed team of privacy analysts.

Day-to-Day Responsibilities:
  • Run day-to-day privacy operations, managing the service desk intake queue, triage, prioritization, and SLA turnaround
  • Manage end-to-end handling of PHI access and correction requests — identity verification, record retrieval, redaction review, response letters, statutory PHIPA timeline tracking
  • Administer consent operations, including consent directives, withdrawal/reinstatement, override handling, and escalation/documentation to the accountable privacy executive
  • Operate privacy incident and breach process at intake/containment stage, maintaining the incident register and escalating notifiable events within contractual timeframes
  • Own privacy logging operations — configuration, integrity, retention, and proactive/reactive review of access and audit logs
  • Deliver scheduled and ad hoc privacy audit/compliance reporting covering request volumes, aging, incident trends, override rates, and remediation status
  • Maintain privacy operational runbooks, SOPs, and templates, keeping them aligned to PHIPA, FIPPA, and client policy updates
  • Supervise, coach, and quality-assure a distributed team of privacy analysts and service desk agents — workload allocation, capacity planning, performance management
  • Partner with security operations, service management, and application support to resolve cross-functional privacy issues and embed privacy controls into ITSM workflows
  • Support internal audits, client assurance reviews, and regulator requests by assembling evidence packages and case files
  • Advise stakeholders on operational privacy risk, process gaps, and control improvements
  • Drive continuous improvement — automation, tooling enhancements, metric definition, backlog reduction
Required Qualifications:
  • 5+ years in privacy operations, information governance, or compliance, with strong focus on regulated environments (healthcare, public sector, consulting)
  • 4+ years hands-on service desk/privacy operations experience at scale
  • 4+ years processing access and correction requests, including identity verification, redaction, statutory response timelines
  • 3+ years administering consent management, including override handling and documentation
  • 3+ years in privacy incident and breach handling — intake, containment, case documentation, escalation
  • 3+ years with access/audit logging — log review, anomaly investigation, evidence preservation
  • 3+ years producing audit, compliance, and operational reporting for internal and client stakeholders
  • 3+ years working knowledge of PHIPA, FIPPA, and PIPEDA in an operational setting
  • 2+ years supervising/mentoring analysts or service desk agents
  • 2+ years in consulting or client-facing roles
  • Working knowledge of ITSM platforms (ServiceNow, Jira Service Management) and case management/log analysis tooling
  • Privacy certification: CIPP/C, CIPM, or equivalent (or active progress toward)
  • Eligibility for background screening and security clearance for client environment access
  • Bachelor's degree in Health Informatics, Information Management, Business, Engineering, Technology, Information Systems, or related field
Nice to Have:
  • Consulting/client-facing experience within Canadian public healthcare sector
  • Experience supporting health information custodians, prescribed entities, or HINPs
  • Familiarity with provincial digital health assets, consent directive models, ONE ID
  • Exposure to privacy audit tooling or automated access-monitoring solutions
  • Additional certifications: CIPT, CISM, CISA, CHPC, ITIL, Lean Six Sigma
  • Bilingual proficiency in English and French
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Privacy Program Executive – PHIPA/FIPPA/PIPEDA
Privacy Program Executive – PHIPA/FIPPA/PIPEDA

United Software Group Inc • Toronto

On-site
CAD 150,000 - 230,000
RQ09375 - Privacy Impact Assessment (PIA) Specialist - Senior
RQ09375 - Privacy Impact Assessment (PIA) Specialist - Senior

Rubicon Path • Toronto

Hybrid
CAD 100,000 - 130,000
RQ09055 - Privacy Impact Assessment (PIA) Specialist - Senior
RQ09055 - Privacy Impact Assessment (PIA) Specialist - Senior

Rubicon Path • Toronto

On-site
CAD 80,000 - 100,000
Competitive salary
Health insurance
Professional development opportunities
Privacy Lead
Privacy Lead

Inforoute-Sante-Du-Canada-Inc • Montreal (administrative region)

On-site
CAD 110,000 - 140,000
RQ09302 - Privacy Impact Assessment (PIA) Specialist - Senior
RQ09302 - Privacy Impact Assessment (PIA) Specialist - Senior

Rubicon Path • Toronto

On-site
CAD 80,000 - 100,000
Senior Privacy Experts/Data Privacy Officer (SME's) (SS - 06272025 - PTJPE/DPO)
Senior Privacy Experts/Data Privacy Officer (SME's) (SS - 06272025 - PTJPE/DPO)

Rippedboxstation • Canada

Remote
CAD 60,000 - 80,000
Privacy Officer
Privacy Officer

publichealthontario • Toronto

On-site
CAD 110,000 - 150,000
RQ09522 - Privacy Impact Assessment (PIA) Specialist - Senior
RQ09522 - Privacy Impact Assessment (PIA) Specialist - Senior

Rubicon Path • Toronto

Hybrid
CAD 80,000 - 110,000
Privacy Lead
Privacy Lead

Canada Health Infoway • Montreal (administrative region)

On-site
CAD 110,000 - 160,000
Privacy Officer
Privacy Officer

Public Health Ontario • Toronto

On-site
CAD 110,000 - 155,000