RQ09134 - Privacy Impact Assessment (PIA) Specialist - Senior
On-siteToronto, Ontario, Canada
Job Summary
Lead the development of Privacy Impact Assessments to evaluate new technologies, systems, and policies against legal and privacy requirements, specifically ensuring compliance with FIPPA, PHIPA, PIPEDA, and Ontario Ministry of Government Services standards. Conduct risk determinations and mitigate threats while addressing client concerns, utilizing data flow diagrams and business process analyses to interpret technical and non-technical documentation. Collaborate with policy development teams, external experts, and senior management to drive decision-making on privacy protections for legacy, web, mobile, and cloud-based solutions. Manage concurrent requests in an agile environment, documenting findings and recommendations to obtain necessary approvals and sign-offs within the OPS setting.
Required Qualifications
- Extensive experience doing Privacy Assessment Experience, Policy (no training provided)
- Experienced in privacy legislation including Freedom of Information and Protection of Privacy Act (FIPPA), Personal Health Information Protection Act (PHIPA), the Personal Information Protection and Electronic Documents Act (PIPEDA)
- Experience with privacy risks and conducting PIAs associated with integration between legacy systems, web applications, mobile and cloud-based solutions to obtain, retrieve and synchronize information
- Experience in developing, applying and/or evaluating digital identity trust frameworks such as the PCTF, eIDAS, or similar
- Experience with Digital Identity standards such as NIST, FIDO, Open ID Connect, SAML
Desired Qualifications
- Professional certification from a related discipline such as IT security, architecture
- Experience providing education and training related to privacy
- Knowledge of, and experience with the policies and procedures of the Ontario government (e.g. business case development, project approvals and policy development)
- Experience in conducting Privacy Impact Assessments in public sector context
- Knowledge of, and experience in researching and applying relevant information privacy laws, regulations, jurisprudence (particularly as it relates to the Information and Privacy Commissioner of Ontario) and risk countermeasures
- Excellent knowledge of privacy and security concepts, trends, and issues. This will include an understanding of their impact on business processes, as well as skill with interpretation and communication of principles and compliance requirements
- Knowledge and ability to interpret and apply Ontarios Freedom of Information and Protection of Privacy Act (FIPPA) and its municipal equivalent the Municipal Freedom of Information and Protection of Privacy Act (MFIPPA), Personal Health Information Protection Act (PHIPA) their respective regulations and related jurisprudence
- Familiarity with federal Personal Information Protection and Electronic Documents Act (PIPEDA) and US PATRIOT Act
- Policy Knowledge
- Familiarity with OPS Privacy Impact Assessment Process and Tools released by the Ontario Ministry of Government Services
- Good understanding of related disciplines, such as IT security, IT system design, policy development (privacy or security), business architecture, legal processes, Freedom of Information administration, business analysis, risk management, project management
- Ability to lead, mange or support the development of a PIA either independently or as part of a team by directing and gathering input from specific individuals within the organization
- Knowledge and ability to create and understand data flow diagrams and business process diagrams
- Ability to recognize the need for, and seek input from external experts as required
- Excellent communication skills with technical and business audiences and non- access and privacy experts
- Analytical skills to understand the current and future access and privacy implications of policies, decisions and business initiatives
- Knowledge of Information Technology concepts and processes that impact the protection of personal information, including (but not limited to) Internet tools, system interfaces, information security, information architecture and data flows
- Experience in developing risk assessment tools, methodologies, policies and procedures to effectively manage personal information
- Knowledge of policies, directives, standards, business rules, procedures and guidelines relating to records management including classification, retention and disposition of information
- Knowledge and understanding of Accessibility for Ontarians with Disability Act (AODA) and related regulations and standards
- Experience providing education and training related to privacy
- Knowledge of, and experience with the policies and procedures of the Ontario government (e.g. business case development, project approvals and policy development)
- Experience providing education and training related to privacy
- Experience with privacy risks and conducting PIAs associated with integration between legacy systems, web applications, mobile and cloud-based solutions to obtain, retrieve and synchronize information
- Experience with privacy risks and conducting PIAs involving mobile app solutions and the unique security and privacy challenges associated with such platforms
- Demonstrated experience and familiarity with strong security, encryption and privacy protection approaches to digital solutions, including mobile; web based and backend integrations via API or similar approaches
- Familiar with Digital Wallet technologies (native within OS or third party) including the security and privacy considerations, limitations, and best practices for local data protection on mobile devices
- Familiar with cloud based digital wallet technologies including the security and privacy considerations, limitations, and best practices for data protection
- Experience, knowledge and understanding of privacy protection standards and best practices, business, information and security architecture principles and emerging technology related to the protection of privacy and personal information
- Demonstrated strong communication and engagement skills with ability to lead teams in discovery sessions to elicit details of technical solutions, business processes and/or policies, strong writing skills to document findings, recommendation, etc
- Demonstrated ability to interpret both technical (e.g. architecture design documents, process flows, state transition diagrams, etc.) and non-technical documentation to conduct assessment of impacts and to develop mitigation strategies
- Strong organizational and time management skills to manage multiple and concurrent requests in an agile and highly dynamic work environment setting
- Strong presentation abilities to communicate findings, recommendations, etc. to senior management and executives to inform decision making; able to communicate Page 6 of 12 complex problems/issues in simple terms
- Experience in developing, applying and/or evaluating digital identity trust frameworks such as the PCTF, eIDAS, or similar
- Experience with Digital Identity standards such as NIST, FIDO, Open ID Connect, SAML
- Prior experience with leading and conducting multiple PIAs in OPS setting/ environment, including demonstrated knowledge and experience with OPS processes, existing templates and expectations to obtain approvals/sign off
- Prior to OPS experience
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.