RQ11631-Privacy Impact Assessment Specialist -Intermediate

Analyst Technical Solutions

Toronto

On-site

CAD 85,000 - 120,000

Full time

14 days+
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Central Agencies Cluster seeks an intermediate Privacy Impact Assessment Specialist to lead and support PIAs ensuring compliance with FIPPA, MFIPPA, PHIPA and PIPEDA.

The role requires strong privacy and security knowledge, plus ability to translate complex regulations into actionable guidance for IT and policy teams.

Qualifications

  • Excellent knowledge of privacy concepts and security concepts.
  • Ability to interpret privacy laws and policies (FIPPA, PHIPA, PIPEDA).
  • Experience in leading privacy impact assessments in public sector contexts.
  • Strong communication skills for technical and non-technical audiences.
  • Ability to manage multiple PIAs in dynamic environments.

Responsibilities

  • Lead or support the development of PIAs evaluating legality and privacy risks.
  • Provide privacy advice, recommendations, and directions with IT input.
  • Create data flow and business process diagrams to support PIA findings.
  • Coordinate with policy teams to ensure alignment with regulations and OPS processes.

Skills

Privacy concepts
Security concepts
Policy interpretation
Communication skills
Risk management
Project management

Job description

Organization: Central Agencies Cluster

Ministry Ministry of Treasury Board Secretariat

Description

Requesting 1 PIA (Privacy Impact Assessment) Specialist -Intermediate who will provide the privacy work in scope for this assessment:

  • Follow Corporate Governance
  • PIA will support CPOD Initiative and align with any new and relevant privacy requirements per new FIPPA amendments.
  • Conduct a Privacy Impact Assessment, provide privacy advice, recommendations and directions, with the consultation from IT Source.
  • The deliverable is a Privacy Impact Assessment which will align to Corporate Governance
Responsibilities:

Required to lead or support the development of a privacy impact assessment that evaluates whether new technologies, information systems, or proposed programs or policies meet legal and policy privacy requirements, determine and mitigate risks, and address clients’ concerns. These requirements include ensuring that the program complies with provincial, municipal, federal and private sector access and privacy legislation, as well as relevant regulations, statutes, OPS policies, Directives, standards, guidelines and internationally accepted Fair Information Practices.

General Skills:

Excellent knowledge of privacy and security concepts, trends, and issues. This will include an understanding of their impact on business processes, as well as skill with interpretation and communication of principles and compliance requirements Knowledge of, and experience in researching and applying relevant information privacy laws, regulations, jurisprudence (particularly as it relates to the Information and Privacy Commissioner of Ontario) and risk countermeasures Experience in conducting Privacy Impact Assessments in public sector context Knowledge of, and experience with privacy enhancing best practices Knowledge and ability to interpret and apply Ontario’s Freedom of Information and Protection of Privacy Act (FIPPA) and its municipal equivalent the Municipal Freedom of Information and Protection of Privacy Act (MFIPPA), Personal Health Information Protection Act (PHIPA) their respective regulations and related jurisprudence Familiarity with federal Personal Information Protection and Electronic Documents Act (PIPEDA) and US PATRIOT Act Policy Knowledge Familiarity with OPS Privacy Impact Assessment Process and Tools released by the Ontario Ministry of Government Services; Good understanding of related disciplines, such as IT security, IT system design, policy development (privacy or security), business architecture, legal processes, Freedom of Information administration, business analysis, risk management, project management. Operational Program and Business Design Skills Ability to lead, mange or support the development of a PIA either independently or as part of a team by directing and gathering input from specific individuals within the organization Knowledge and ability to create and understand data flow diagrams and business process diagrams Ability to recognize the need for, and seek input from external experts as required Excellent communication skills with technical and business audiences and non- access and privacy experts. Technology and Systems Knowledge Analytical skills to understand the current and future access and privacy implications of policies, decisions and business initiatives Knowledge of Information Technology concepts and processes that impact the protection of personal information, including (but not limited to) Internet tools, system interfaces, information security, information architecture and data flows Information and Record Keeping Knowledge Experience in developing risk assessment tools, methodologies, policies and procedures to effectively manage personal information Knowledge of policies, directives, standards, business rules, procedures and guidelines relating to records management including classification, retention and disposition of information Knowledge and understanding of Accessibility for Ontarians with Disability Act (AODA) and related regulations and standards

Desirable Skills: Professional certification from a related discipline such as IT security, architecture Experience providing education and training related to privacy Knowledge of, and experience with the policies and procedures of the Ontario government (e.g. business case development, project approvals and policy development)

Privacy Impact Assessment Specialist - Evaluation Criteria
40% - Privacy Assessment Experience, Policy and Legislative Requirements
  • Experienced in privacy legislation including Freedom of Information and Protection of Privacy Act (FIPPA), Personal Health Information Protection Act (PHIPA), the Personal Information Protection and Electronic Documents Act (PIPEDA)
  • Experienced in conducting privacy assessments involving personal information, citing examples in the resume.
  • Experienced in leading and conducting privacy assessments involving online and/or digital solutions.
  • Experienced working with policy development teams; reviewing and comparing policies and legislation to make informed recommendations to ensure adequate privacy protections and considerations are addressed within policy/legislation.
30% - Technical understanding
  • Experience with privacy risks and conducting PIAs and the unique security and privacy challenges associated with various platforms.
  • Demonstrated experience and familiarity with strong security, encryption and privacy protection approaches to digital solutions, including web based and backend integrations via API or similar approaches.
  • Experience with privacy risks and conducting PIAs associated with integration between legacy systems, web applications, digital and cloud-based solutions to obtain, retrieve and synchronize information.
  • Familiar with cloud-based technologies including the security and privacy considerations, limitations, and best practices for data protection.
  • Experience, knowledge, and understanding of privacy protection standards and best practices, business, information and security architecture principles and emerging technology related to the protection of privacy and personal information.
20% - Leadership and Communications
  • Demonstrated strong communication and engagement skills with the ability to lead teams in discovery sessions to elicit details of technical solutions, business processes and/or policies, strong writing skills to document findings, recommendations, etc.
  • Demonstrated ability to interpret both technical (e.g. architecture design documents, process flows, state transition diagrams, etc.) and non-technical documentation to conduct assessments of impacts and to develop mitigation strategies.
  • Strong organizational and time management skills to manage multiple and concurrent requests in an agile and highly dynamic work environment setting.
  • Strong presentation abilities to communicate findings, recommendations, etc. to senior management and executives to inform decision-making; able to communicate complex problems/issues in simple terms.
10% - OPS Experience
  • Prior experience with leading and conducting multiple PIAs in OPS setting/ environment, including demonstrated knowledge and experience with OPS processes, existing templates and expectations to obtain approvals/sign-off.
Must Have:

Experienced in privacy legislation including Freedom of Information and Protection of Privacy Act (FIPPA), Personal Health Information Protection Act (PHIPA), the Personal Information Protection and Electronic Documents Act (PIPEDA)

Experienced in conducting privacy assessments involving personal information, citing examples in the resume.

Experienced in leading and conducting privacy assessments involving online and/or digital solutions.

Experience with privacy risks and conducting PIAs and the unique security and privacy challenges associated with various platforms.

Prior experience with leading and conducting multiple PIAs in OPS setting/environment, including demonstrated knowledge and experience with OPS processes, existing templates and expectations to obtain approvals/sign-off.

Strong organizational and time management skills to manage multiple and concurrent requests in an agile and highly dynamic work environment setting.

Nice to Have:

Demonstrated ability to interpret both technical (e.g. architecture design documents, process flows, state transition diagrams, etc.) and non-technical documentation to conduct assessments of impacts and to develop mitigation strategies.

Familiar with cloud-based technologies including the security and privacy

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

RQ09055 - Privacy Impact Assessment (PIA) Specialist - Senior
RQ09055 - Privacy Impact Assessment (PIA) Specialist - Senior

Rubicon Path • Toronto

On-site
CAD 80,000 - 100,000
Competitive salary
Health insurance
Professional development opportunities
RQ09302 - Privacy Impact Assessment (PIA) Specialist - Senior
RQ09302 - Privacy Impact Assessment (PIA) Specialist - Senior

Rubicon Path • Toronto

On-site
CAD 80,000 - 100,000
Privacy Impact Assessment (PIA) Specialist
Privacy Impact Assessment (PIA) Specialist

GovTech Talent Solutions Inc. • Toronto

On-site
CAD 90,000 - 130,000
Privacy Impact Assessment (PIA) Specialist (RQ11603) Government Services Integration Cluster
Privacy Impact Assessment (PIA) Specialist (RQ11603) Government Services Integration Cluster

Softline Technology Inc. • Toronto

Hybrid
CAD 90,000 - 120,000
RQ09134 - Privacy Impact Assessment (PIA) Specialist - Senior
RQ09134 - Privacy Impact Assessment (PIA) Specialist - Senior

Rubicon Path • Toronto

On-site
CAD 80,000 - 100,000
RQ09375 - Privacy Impact Assessment (PIA) Specialist - Senior
RQ09375 - Privacy Impact Assessment (PIA) Specialist - Senior

Rubicon Path • Toronto

On-site
CAD 100,000 - 130,000
RQ08931 - Privacy Impact Assessment (PIA) Specialist - Senior
RQ08931 - Privacy Impact Assessment (PIA) Specialist - Senior

Rubicon Path • Toronto

On-site
CAD 100,000 - 130,000
RQ09522 - Privacy Impact Assessment (PIA) Specialist - Senior
RQ09522 - Privacy Impact Assessment (PIA) Specialist - Senior

Rubicon Path • Toronto

On-site
CAD 80,000 - 110,000
Privacy Specialist
Privacy Specialist

Akkodis • Toronto

Hybrid
CAD 80,000 - 110,000
Privacy Impact Assessment (PIA) Specialist - Senior (PHIPA / PIPEDA exp)
Privacy Impact Assessment (PIA) Specialist - Senior (PHIPA / PIPEDA exp)

Bevertec • Toronto

On-site
CAD 131,000 - 138,000
Onsite five days a week
Contract role