21 Aug
|
Teckhorizon
|
Ontario
21 Aug
Teckhorizon
Ontario
Our Client is looking for a Senior Privacy Impact Assessment Specialist who will lead and support Privacy Impact Assessments for new technologies, information systems, digital solutions, programs and policies. The consultant will assess compliance with applicable privacy legislation and government policies, identify privacy and security risks, develop mitigation strategies and provide privacy and data governance advisory services.
The role requires strong experience with Ontario privacy legislation, digital identity and credential ecosystems, mobile and cloud solutions, consent management, security and encryption practices, and privacy risks associated with modern application architectures.
Key Responsibilities
Lead and conduct Privacy Impact Assessments (PIAs) involving personal information and personal health information.
Assess privacy risks associated with mobile applications, web applications, APIs, cloud solutions, legacy systems and third-party integrations.
Evaluate compliance with FIPPA, PHIPA, MFIPPA, PIPEDA and related privacy requirements, policies and jurisprudence.
Develop privacy risk mitigation recommendations, privacy-enhancing tools, policies, procedures and supporting documentation.
Develop and implement consent management frameworks, conceptual and logical models, business requirements and supporting practices.
Provide privacy and data governance advisory services to program, business, architecture, security, legal and policy stakeholders.
Support development of statutory and regulatory instruments related to digital identity, digital credentials and privacy.
Develop data-flow diagrams, business-process diagrams, privacy architecture models and supporting assessment artifacts.
Develop privacy-related KPIs, metrics and reporting mechanisms.
Facilitate discovery sessions with technical and business stakeholders to understand solution architecture, data flows, business processes and privacy implications.
Review architecture documents, process flows,
policies and legislative requirements and recommend appropriate privacy controls.
Present assessment findings, risks and recommendations to senior management and executives.
Must-Have Experience
Strong experience conducting Privacy Impact Assessments involving both PHIPA and FIPPA, with examples clearly demonstrated in the resume.
Experience leading PIAs for online and/or mobile digital solutions handling personal and health-related information.
Experience with digital credential platforms, decentralized identity and Self-Sovereign Identity (SSI) models.
Experience with credential-holder-centric ecosystems, digital wallets and decentralized credential technologies.
Understanding of Verifiable Credentials, selective disclosure and zero-knowledge proof concepts.
Experience assessing privacy and security risks involving mobile, web, backend/API and cloud-based solutions.
Strong understanding of encryption, security controls and privacy-protection techniques.
Experience developing and implementing consent management frameworks.
Ability to develop privacy-enhancing tools and techniques.
Ability to develop privacy/data governance operating models, designs and architectures.
Experience providing privacy and data governance advisory services.
Strong knowledge of data flows, business process modelling and information architecture.
Experience working with legal and/or policy teams to interpret legislation and recommend appropriate legal, privacy and record-keeping approaches.
Privacy Legislation & Policy Knowledge
Strong knowledge of:
Freedom of Information and Protection of Privacy Act (FIPPA)
Municipal Freedom of Information and Protection of Privacy Act (MFIPPA)
Personal Health Information Protection Act (PHIPA)
Personal Information Protection and Electronic Documents Act (PIPEDA)
Relevant Ontario privacy regulations and jurisprudence
Information and Privacy Commissioner of Ontario requirements
OPS Privacy Impact Assessment processes and tools
Records classification, retention and disposition requirements
Accessibility for Ontarians with Disabilities Act (AODA)
Digital Identity & Credential Experience
Candidates should have experience with:
Self-Sovereign Identity (SSI)
Verifiable Credentials
Digital wallets
Credential-holder-centric ecosystems
Selective disclosure
Zero-knowledge proofs
Decentralized credential platforms
Mobile and cloud-based wallet security
Trust frameworks such as PCTF, eIDAS or equivalent
Digital credential standards including NIST and W3C
Leadership & Communication
Robust facilitation and stakeholder-engagement skills.
Ability to lead discovery sessions involving business, architecture, legal, policy, security and technical teams.
Ability to interpret technical architecture documents, process flows and non-technical policies.
Strong written communication and assessment-documentation skills.
Ability to manage multiple concurrent requests in a fast-paced Agile environment.
Strong presentation skills with the ability to communicate privacy risks and recommendations to executives and senior management.
Nice to Have
Ontario Public Sector or broader public-sector experience.
Current OPS security clearance.
Experience providing privacy education and training.
Skilled certification in a related discipline such as IT security or architecture.
Knowledge of Ontario government business-case, project-approval and policy-development processes.
#J-18808-Ljbffr
📌 Privacy Advisor (Ontario)
🏢 Teckhorizon
📍 Ontario