23 Aug
|
United Software Group
|
Toronto
23 Aug
United Software Group
Toronto
Job Title: Privacy Compliance and Assurance Lead
Location: Toronto, Ontario, Canada
:
We're seeking a Privacy Compliance and Assurance Lead to support end-to-end privacy compliance and assurance activities across third-party risk and vendor management programs for a client engagement. This role bridges audit, privacy compliance, and third-party assurance — coordinating with external auditors, client stakeholders, and cross-functional teams to keep the privacy control environment audit-ready.
Day-to-Day Responsibilities:
- Support end-to-end privacy compliance and assurance activities across third-party risk and vendor management programs
- Lead third-party privacy assurance reviews, audits, and evidence collection for client delivery engagements
- Interface with independent assurance providers and external auditors to coordinate assurance reporting (SOC 2, ISO 27701)
- Maintain and validate client-specific privacy compliance documentation, audit evidence repositories, and control frameworks
- Collaborate with client legal, security, procurement, and business teams to assess third-party privacy risk and remediate gaps
- Support preparation of audit findings, assurance reports, and executive-level compliance summaries
- Contribute to continuous improvement of privacy compliance methodologies and delivery standards
- Participate in multi-stakeholder governance meetings to communicate assurance findings and risk implications
- Help develop data-backed, risk-based recommendations to strengthen privacy and third-party assurance posture
Required Qualifications:
- 5+ years in privacy compliance, third-party risk management, IT audit, or professional advisory/consulting services
- Demonstrated experience managing third-party privacy assurance programs, audits, and evidence management in complex corporate or public sector environments
- Deep familiarity with assurance frameworks: SOC 2, ISO 27701, ISO 27001, NIST Privacy Framework
- Working knowledge of Canadian privacy legislation (PHIPA, PIPEDA) and healthcare regulatory requirements
- Robust analytical, audit documentation, and client-facing communication skills
- Experience working within cross-functional, client-facing consulting delivery teams
- Ability to synthesize audit/assurance findings into actionable, risk-based recommendations
- Bachelor's degree in Privacy, Information Security, Law, Risk Management, Business Administration, or related field
Nice to Have:
- CIPP/C, CIPM, CISA, CRISC, or equivalent privacy/audit credentials
- Exposure to public sector or healthcare privacy/assurance engagements, particularly within Ontario's health system
- Hands-on experience with GRC/audit evidence platforms: ServiceNow GRC, Archer, OneTrust, or similar
📌 Privacy Compliance and Assurance Lead (Toronto)
🏢 United Software Group
📍 Toronto