Privacy Impact Assessment (PIA) Specialist - Senior (Toronto)

Privacy Impact Assessment (PIA) Specialist - Senior (Toronto)

13 Aug
|
S M Software Solutions
|
Toronto

13 Aug

S M Software Solutions

Toronto

Privacy Impact Assessment (PIA) Specialist – Senior

Client: Ministry of Public and Business Service Delivery and Procurement

Job Title: RQ10486 – Privacy Impact Assessment (PIA) Specialist – Senior

Work Location: 222 Jarvis Street, Toronto, Ontario, Canada – Onsite Estimated Start Date: 08/31/2026

Estimated End Date: 08/30/2027

Business Days: 252

Extension: Probable after the initial mandate

Hours: 7.25 hours per day

Security Level: CRJMC

Application Deadline: Thursday, August 13, 2026, at 10:00 AM EST

Contact Email: [email protected]

Role Overview

We are seeking a Senior Privacy Impact Assessment (PIA) Specialist to lead and support privacy assessments for digital identity, digital credential, mobile, web, cloud, and integrated technology solutions.

The successful candidate will provide privacy and data governance expertise, assess privacy and security risks, support consent management, interpret applicable privacy legislation, and ensure digital solutions align with government policies, directives, standards, and regulatory requirements.

The ideal candidate will have strong experience with Privacy Impact Assessments, FIPPA, PHIPA, PIPEDA, Self-Sovereign Identity (SSI), Verifiable Credentials, decentralized identity models, digital wallets, consent management, privacy-enhancing technologies, and digital identity ecosystems. Role Snapshot

Requisition: RQ10486

Role: Privacy Impact Assessment (PIA) Specialist – Senior

Client: Ministry of Public and Business Service Delivery and Procurement

Location: 222 Jarvis Street, Toronto, Ontario – Onsite

Contract: August 31, 2026 – August 30, 2027

Duration: 252 Business Days

Hours: 7.25 hours/day

Security Level: CRJMC

Extension: Probable

Key Responsibilities

- Privacy Assessment, Consent Management & Legislative Compliance – 35%
- Lead or support Privacy Impact Assessments for new technologies, information systems, programs, and policies.
- Evaluate solutions against applicable privacy, legal, regulatory, security, and policy requirements.
- Conduct PIAs involving personal information and personal health information.
- Conduct privacy assessments involving online and mobile digital solutions.
- Apply and interpret FIPPA, PHIPA, PIPEDA, MFIPPA, related regulations, and applicable jurisprudence.
- Assess third-party applications, private-sector/non-profit solutions, and service integration providers.
- Work with legal counsel and policy teams to review legislation and develop informed recommendations.
- Develop and implement consent management approaches, conceptual models, logical models, and supporting business requirements.
- Identify privacy risks and develop mitigation strategies.
- Develop privacy-enhancing tools, techniques, policies, and practices.
- Develop KPIs and report privacy and data governance metrics.
- Align privacy practices with broader government programs and practices.
- Digital Identity, Credentials & Privacy Governance
- Provide expertise on credential-holder-centric ecosystems and decentralized identity models, including Self-Sovereign Identity (SSI).
- Assess digital credential platforms, supporting technologies, and digital wallets.
- Provide expertise with Verifiable Credentials and SSI-based approaches.
- Evaluate privacy implications of selective disclosure and zero-knowledge proofs.
- Develop designs and architectures supporting a privacy/data governance function for the Digital Identity Program and potentially ODS.
- Provide privacy and data governance advisory services.




- Assist with development of statutory and regulatory instruments addressing digital identity and digital credential privacy matters.
- Assess how SSI models affect privacy, consent, and data governance.
- Develop approaches and frameworks to strengthen privacy protection across digital identity initiatives.
- Technical Privacy & Security Assessment – 25%
- Assess privacy risks associated with legacy systems, web applications, mobile applications, cloud solutions, and system integrations.
- Conduct PIAs involving mobile applications and their unique privacy and security challenges.
- Evaluate security, encryption, privacy protection, APIs, web-based solutions, and backend integrations.
- Assess decentralized credential systems, supporting platforms, and digital wallets.
- Evaluate native and third-party digital wallet technologies.
- Assess local data protection practices on mobile devices.
- Evaluate cloud-based digital wallet technologies and related data protection practices.
- Apply privacy protection standards, business architecture principles, information architecture, security architecture, and emerging technologies.
- Analyze data flows and system interfaces affecting personal information protection.
- Create and interpret data flow diagrams and business process diagrams.
- Develop risk assessment tools, methodologies, policies, and procedures for managing personal information.
- Leadership, Stakeholder Engagement & Communications – 25%
- Lead discovery sessions with technical, business, legal, policy, and other stakeholders.
- Gather information regarding technical solutions, business processes, policies, and privacy requirements.
- Interpret technical and non-technical documentation to assess privacy impacts and develop mitigation strategies.
- Review architecture designs, process flows, state transition diagrams, and related technical documentation.
- Document findings, recommendations, risks, and mitigation strategies.
- Present privacy and technical findings to senior management and executives.
- Communicate complex privacy and technical issues in clear, business-friendly language.
- Manage multiple concurrent requests in an agile and highly dynamic setting.
- Recognize when external subject matter experts are required and coordinate appropriate input.
- Digital Credential Frameworks & Standards – 15%
- Develop, apply, and/or evaluate digital identity and trust frameworks such as PCTF, eIDAS, or similar frameworks.
- Apply knowledge of digital credential standards such as NIST and W3C.
- Evaluate SSI models and their impact on privacy, consent, and data governance.
- Assess emerging digital credential technologies and privacy protection approaches.
- Provide guidance on privacy and security considerations within decentralized credential ecosystems.

Required Skills & Experience Skill / Experience Required Privacy Impact Assessments involving FIPPA and PHIPA Required Privacy assessments involving personal and personal health information Required PIAs for online and mobile digital solutions Required Credential-holder-centric ecosystems / decentralized identity Required Self-Sovereign Identity (SSI)



Required Verifiable Credentials Required Digital credential platforms and digital wallets Required Privacy-enhancing tools and techniques Required Consent management frameworks and policies Required Privacy and data governance advisory services Required Security, encryption, APIs, web, mobile and backend integrations Required Cloud-based privacy and security assessment Required Data flow and business process diagrams Required KPI development and metrics reporting Required Privacy/data governance architecture and design Required FIPPA, PHIPA and PIPEDA knowledge Required Strong stakeholder engagement and communication Required Digital credential standards including NIST/W3C Required SSI impact on privacy, consent and data governance Required

General Skills

- Excellent knowledge of privacy and security concepts, trends, risks, and issues.
- Strong understanding of privacy principles and compliance requirements.
- Experience researching and applying privacy laws, regulations, jurisprudence, and risk countermeasures.
- Knowledge of privacy-enhancing best practices.
- Knowledge of FIPPA, MFIPPA, PHIPA, PIPEDA, related regulations, and applicable jurisprudence.
- Familiarity with the OPS Privacy Impact Assessment Process and Tools.
- Understanding of IT security, IT system design, privacy/security policy development, business architecture, legal processes, Freedom of Information administration, business analysis, risk management, and project management.
- Strong analytical skills related to privacy implications of policies, decisions, and business initiatives.
- Knowledge of information security, information architecture, data flows, system interfaces, and Internet technologies.
- Experience developing risk assessment methodologies, policies, tools, and procedures.
- Knowledge of records management policies, classification, retention, and disposition.
- Knowledge and understanding of Accessibility for Ontarians with Disabilities Act (AODA) requirements.
- Excellent written and verbal communication skills with technical and business audiences.

Highly Desired Skills

- Previous Public Sector / Ontario Public Service experience.
- Current OPS security clearance.
- Professional certification in a related discipline such as IT security or architecture.
- Experience providing privacy education and training.
- Knowledge of Ontario government policies and procedures, including business case development, project approvals, and policy development.

Mandatory Submission Requirements If you are interested and your profile matches the requirements, please send the following documents to [email protected] by Thursday, August 13, 2026, at 10:00 AM EST :

- Updated Resume in Word format – Mandatory
- References – Mandatory
- Expected Hourly Rate – Mandatory
- Visa Status – Mandatory
- LinkedIn ID – Mandatory

Note: Applications without all mandatory documents cannot be processed or submitted.

How to Apply

Please submit your complete profile and mandatory documents to [email protected] by Thursday, August 13, 2026, at 10:00 AM EST .

If this opportunity is not suitable for you, please forward it to qualified Senior Privacy Impact Assessment Specialists, Privacy Specialists, Privacy & Data Governance Specialists, Digital Identity Specialists, or Privacy Architects with strong experience in PIA, FIPPA, PHIPA, SSI, Verifiable Credentials, digital wallets, consent management, privacy governance, and digital identity solutions.

📌 Privacy Impact Assessment (PIA) Specialist - Senior (Toronto)
🏢 S M Software Solutions
📍 Toronto

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: privacy impact assessment (pia) specialist - senior (toronto) / toronto

Subscribe to this job alert:

Get the latest job offers by email for: privacy impact assessment (pia) specialist - senior (toronto) / toronto