Staff - Non Union### ## **Job Category**M&P - AAPS## **Job Profile**AAPS Salaried - Accounting, Level D### ## **Job Title**Senior Privacy and Information Security Risk Advisor### ## **Department**Privacy and Information Security | Safety & Risk Services | VP Finance and Operations### ## **Compensation Range**$7,622.83 - $11,886.67 CAD MonthlyThe Compensation Range is the span between the minimum and maximum base salary for a position. The midpoint of the range is approximately halfway between the minimum and the maximum and represents an employee that possesses full job knowledge, qualifications and experience for the position. In the normal course, employees will be hired, transferred or promoted between the minimum and midpoint of the salary range for a job.### ## **Posting End Date**April 21, 2026**Note:** Applications will be accepted until 11:59 PM on the Posting End Date.**Job End Date**OngoingThis position is expected to be filled by promotion/reassignment and is included here to inform you of its vacancy at the University.At UBC, we believe that attracting and sustaining a diverse workforce is key to the successful pursuit of excellence in research, innovation, and learning for all faculty, staff, and students. Our commitment to employment equity helps achieve inclusion and fairness, brings rich diversity to UBC as a workplace, and creates the necessary conditions for a rewarding career.**Job Summary**The Senior Privacy and Information Security Risk Advisor operates within the Privacy & Information Security Management (PrISM) Safety & Risk Service (SRS) team. UBC’s PrISM program is an ongoing initiative to reduce the risk of a major privacy or information security breach at UBC through security governance, technology advancement, training, awareness and communications, risk management and compliance support, system identification and classification.The PrISM SRS team is a key component of the PrISM program, delivering Privacy Impact Assessments (PIA) that consider privacy, operational, application, and security risks and threats; campus-wide training; and risk advisory services to UBC. The team’s focus is to maintain public trust in UBC, protect personal information of the UBC community, and keep UBC's confidential information secure, whilst enabling technology-supported business initiatives to succeed.This is an exciting opportunity to work with a dynamic, risk-focused team that collaborates across UBC, including with management and staff in other units, such as the Cybersecurity team, University Counsel, Enterprise Risk and Assurance, the Office of the CIO, and UBC IT teams.The Senior Privacy and Information Security Risk Advisor will work with units across the University to identify key privacy and information security risks,
determine appropriate risk mitigation activities, and ensure commitment to their completion in a timely manner. They will conduct or oversee PIAs required under FIPPA, including assessments of security risks and controls, utilizing UBC assessment frameworks and tools.The ideal candidate will be well-versed in information security threats, risks, and controls, be skilled in facilitation activities to ensure reasonable privacy and information security measures are in place through every phase of the project’s life cycle, and be comfortable driving change through advocacy and influencing. They will be capable of developing strong, trusted relationships across UBC at various levels of the organization.**Organizational Status*** This position is part of the PrISM SRS team and reports to the Manager, PrISM SRS. The incumbent will collaborate and work closely with management and staff in other units, including the Office of the University Counsel, the Office of the CIO, CyberSecurity, Enterprise Data Governance, Records Management Office, UBC IT, and Faculty IT teams. It will also involve working closely with other IT functions and data stewards within UBC’s faculties and operational entities.**Work Performed*** Conduct or oversee Privacy Impact Assessments, including Security Threat Risk Assessments, utilizing UBC assessment frameworks and tools.* Work with units across the University to identify key privacy and information security risks and determine appropriate risk mitigation activities, and ensure commitment to their completion in a timely manner.* Provide privacy and information security technical expertise and mentoring to project teams and other advisors to ensure reasonable privacy and information security measures are in place through every phase of the project’s life cycle, including project planning, architecture, requirements definition, procurement, implementation, and operationalization of new technology services.* Engage broadly (through training, workshops, and relationship building) within assigned projects to raise awareness of privacy and information security risk and mitigations.* Manage liaison relationship with clients to ensure technology solutions comply with applicable privacy legislation and regulations, UBC policy, and information security standards,
whilst enabling business initiatives.* Provide updates and formal reports to the relevant committee and stakeholders, including the PrISM Executive Team and program/project governance bodies as required.* Conduct formal reviews with project sponsors at project completion to confirm acceptance and satisfaction.* Select and follow project management methods, procedures, and quality objectives, and track metrics for assessing progress on privacy and security risk assessments throughout assigned projects.* Assess variances from the assessment project plans, budgets, and schedules, develop and implement changes as necessary to ensure that the project remains within specified scope and is within time and quality objectives, and keep management aware of the situation.* Develop relevant content to inform PrISM SRS clients and risk advisors on acceptable use of UBC tools.* Acquire and maintain a working knowledge of the University's technical and business environment in order to better understand the business and its priorities. Based on client feedback, develop recommendations and present options for security improvements.* Build and maintain strong and productive working relationships with team members, stakeholders, UBC IT, and other vendors / consultants.* Maintain appropriate professional designations and up-to-date knowledge of current information security frameworks such as ISO 27000 series and NIST Cybersecurity Framework, methods, techniques, and tools.**Consequence of Error/Judgement**UBC is a complex organization that collects and uses information to support its mandate. An information breach (especially relating to personal or other high-risk information) could have a significant financial and reputational impact on the University. The Senior Privacy and Information Security Risk Advisor plays a critical role in the identification of key privacy and information security risks and provides appropriate recommendations to reduce these risks to an acceptable level.Sound judgment must be exercised. Lack of positive judgment and/or inability to adopt sound risk management techniques may result in the failure to detect significant privacy and information security-related exposures to the University's confidential information.**Supervision Received**The Senior Privacy and Information Security Risk Advisor receives direction from the Manager, PrISM SRS, on the work performed. The incumbent must be able to work independently as well as contribute actively and collaborate openly as a team member.**Supervision Given**Plans, directs, and supervises the work of project team members, such as other consultants and staff assigned to the project.**Minimum Qualifications**Undergraduate degree in a relevant discipline and a minimum of 7 years of experience or the#J-18808-Ljbffr
📌 Senior Privacy And Information Security Risk Advisor - C$7,622.8 - C$11,886.7 A Month (Toronto)
🏢 UBC
📍 Toronto