
Enable job alerts via email!
Generate a tailored resume in minutes
Land an interview and earn more. Learn more
A public sector consulting firm in Toronto is seeking an experienced Privacy Impact Assessment (PIA) Specialist. This role requires expertise in developing privacy impact assessments, leading stakeholder discussions related to privacy, and ensuring compliance with best practices in data protection. Candidates should have extensive experience in public sector healthcare projects, with a focus on managing privacy risks associated with personal health information. The position allows for hybrid working arrangements.
Job Openings RQ08931 - Privacy Impact Assessment (PIA) Specialist - Senior
Description
NOTE
Assignment Type: This position is currently listed as "Hybrid" and consultants will be required to work onsite at the work location 3 days a week and 2 days from home, or as per schedule agreed to with the Hiring Manager.
Extension/Amendment Attestation: Extension(s) only allowed using unused days/funds left on contract. No additional funds will be added beyond maximum contract value. The Statement of Work (SOW) shall expire on April 3, 2026. HSC may exercise its option(s) to extend a SOW beyond April 3, 2026. Such extension(s) will be allowable only if the Master Service Agreement is extended beyond April 5, 2026 and be upon the same terms, conditions and covenants contained in the SOW.
The resources needed till October 15, 2026 will include an option to extend, at the same rate, until October 15, 2026 if Tender_12075 Managed Service Provider for Contingent IT Resources is also extended for a further one year, else an RFS under the Successor VOR will be issued for the services required April 5, 2026 to October 15, 2026.
==========================================================================
Responsibilities:
SkillsExperience and Skill Set Requirements
Public Sector Experience
· 5+ years of experience working with federal/provincial/broader public-sector healthcare providers
· Experience with GO-ITS Digital Health standards, and internal branch standards would be an asset.
5 points
Technical Skills
10+ years of experience in the following:
· Privacy impact assessment methodologies, tools and techniques
· Application of threat and risk analysis principles, program analysis, business analysis
· Understanding of policy development to lead or participate in the development of options and strategies on information management and privacy protection
· Practical knowledge of information technology concepts and processes that impact the protection of personal information (i.e. information management, knowledge management, intellectual property/copyright, information technology and electronic service delivery channels)
· Practical knowledge of broad political, legal, fiscal, social and governance dimensions to ensure that privacy principles, directives, notices and directions are considered in the development of new programs/initiatives
· Managing privacy risks in the collection, use and disclosure of Personal Health Information (PHI)
· Leading end-to-end operational risk assessments, selecting risk methodologies, identifying privacy compliance gaps, priorities, dependencies and redundancies, and recommending process remediation or simplification
50 points
Core Skills and Experience
10+ years of experience in the following:
· Demonstrated experience and competency to resolve complex issues, identify options and make recommendations
· Demonstrated experience and competency to analyze policy proposals to assess / identify I&IT business implications and develop strategic policy planning options and impact analyses for clients
· Demonstrated experience and competency to acquire and apply relevant legislation, regulations and directives to ensure proposed initiatives conform to legislation
· Demonstrated experience and competency to identify and evaluate emerging privacy issues, changes, and trends in current and future that impact government policy directions
· Experience in program analysis/evaluation techniques to assess the impact of proposed, or new/changed policies/fiscal or governance arrangements for new programs
· Demonstrated experience and competency to prepare comprehensive reports, options analyses, briefing materials and presentations and propose responses on privacy issues
· Experience in consultation and negotiation to gain support for policy and program initiatives
· Demonstrated experience and competency to develop effective relationships with senior management and stakeholders
· Strong oral and written communications and principles and methods, to draft papers, reports, options analyses, correspondence, briefing notes, speeches, and materials.
35 points
General Skills
· Demonstrated strong leadership and people management skills
· Exceptional analytical, trouble-shooting, problem solving and decision-making skills
· Demonstrated strong interpersonal, verbal and written communication, and presentation skills
· Proven troubleshooting and critical thinking experience
· Demonstrated ability to apply strong listening skills to facilitate issue resolution
· Effective consulting skills to engage with all stakeholders with proven track record for building strong working relationships
· Strong interpersonal, facilitation and negotiation skills with ability to build rapport with stakeholders and drive negotiations to a successful outcome
· Excellent customer service skills, including tact and diplomacy to ensure client needs are managed effectively
· A motivated, flexible, detail-oriented and creativse team player with perseverance, excellent organization and multi-tasking abilities, and a proven track record for meeting strict deadlines.
10 points
MUST HAVES:
10+ years of experience in the following:
· Privacy impact assessment methodologies, tools and techniques
Application of threat and risk analysis principles, program analysis, business analysis
Experience with large complex IT Health-related projects
· Experience with GO-ITS Digital Health standards, and internal branch standards would be an asset.