Senior Privacy Impact Assessment (PIA) Specialist
Job Summary
- Lead or support the development and completion of Privacy Impact Assessments independently or as part of a team.
- Evaluate proposed technologies information systems programs policies and digital solutions against applicable privacy requirements.
- Identify privacy risks and develop appropriate mitigation strategies and recommendations.
- Research and interpret applicable privacy legislation regulations jurisprudence policies directives standards and guidelines.
- Assess privacy implications associated with online and digital solutions.
- Conduct assessments involving personal health information and third-party solutions including private-sector non-profit and service-integration providers.
- Work with policy development teams to review and compare policies and legislation and provide recommendations for appropriate privacy protections.
- Lead discovery sessions and gather information from technical and business stakeholders.
- Interpret technical documentation such as architecture designs process flows and state-transition diagrams.
- Create and interpret data-flow diagrams and business-process diagrams.
- Assess privacy implications of system interfaces APIs information architecture data flows cloud solutions and integrations.
- Develop and apply risk assessment tools methodologies policies and procedures for protecting personal information.
- Provide privacy-related education and training where required.
- Communicate findings risks recommendations and mitigation strategies to senior management and executives.
- Manage multiple concurrent PIA requests in an agile and dynamic environment.
- Seek input from external subject-matter experts where required.
- Support privacy approvals sign-offs and related OPS processes.
- Strong experience with privacy legislation including:
- Freedom of Information and Protection of Privacy Act (FIPPA)
- Personal Health Information Protection Act (PHIPA)
- Personal Information Protection and Electronic Documents Act (PIPEDA)
- Demonstrated experience conducting privacy assessments involving personal information with specific examples clearly documented in the resume.
- Demonstrated experience leading and conducting privacy assessments involving online and/or digital solutions.
- Demonstrated experience leading and conducting assessments involving personal health information and third-party solutions such as private-sector/non-profit applications and/or service integration providers.
- Experience working with policy-development teams and reviewing/comparing policies and legislation to make informed recommendations concerning privacy protections.
- Experience identifying privacy risks and conducting PIAs across different technology platforms.
- Strong understanding of security encryption privacy protection and data-protection approaches for digital solutions.
- Experience assessing web-based solutions and backend integrations using APIs or similar technologies.
- Experience assessing privacy risks associated with integrations between:
- Legacy systems
- Web applications
- Digital solutions
- Cloud-based solutions
- Experience with cloud technologies and an understanding of their security and privacy considerations limitations and data-protection best practices.
- Knowledge of privacy protection standards and best practices.
- Understanding of business information and security architecture principles.
- Awareness of emerging technologies and their implications for protecting privacy and personal information.
- Strong communication and stakeholder-engagement skills.
- Ability to lead discovery sessions and elicit information regarding technical solutions business processes and policies.
- Strong written communication skills for documenting assessment findings risks recommendations and mitigation strategies.
- Ability to interpret both technical and non-technical documentation.
- Ability to translate technical and complex privacy issues into practical recommendations.
- Strong organizational and time-management skills.
- Ability to manage multiple concurrent requests in a dynamic and agile environment.
- Strong presentation skills including the ability to communicate findings and recommendations to senior management and executives in clear understandable language.
- Experience developing applying and/or evaluating digital identity trust frameworks.
- Prior experience leading and conducting multiple PIAs within an Ontario Public Service (OPS) environment.
- Demonstrated knowledge and experience with OPS PIA processes existing templates expectations approvals and sign-off requirements.
- Excellent knowledge of privacy and security concepts trends and issues.
- Ability to interpret and communicate privacy principles and compliance requirements to technical and non-technical audiences.
- Knowledge and experience researching and applying privacy laws regulations jurisprudence and risk countermeasures.
- Knowledge of privacy-enhancing best practices.
- Knowledge of MFIPPA Municipal Freedom of Information and Protection of Privacy Act.
- Knowledge of PHIPA and its regulations and related jurisprudence.
- Familiarity with PIPEDA and the US PATRIOT Act.
- Familiarity with the OPS Privacy Impact Assessment Process and Tools.
- Understanding of related disciplines including:
- IT Security
- IT/System Design
- Privacy/Security Policy Development
- Business Architecture
- Legal Processes
- Freedom of Information Administration
- Business Analysis
- Risk Management
- Project Management
- Knowledge of information and records-management practices including classification retention and disposition.
- Knowledge of Accessibility for Ontarians with Disabilities Act (AODA) and related regulations and standards.
- Professional certification in a related discipline such as IT Security or Architecture.
- Experience providing privacy education and training.
- Experience with Ontario Government policies and procedures including:
- Business case development
- Project approvals
- Policy development
- Previous OPS/public-sector experience.
- FIPPA PHIPA and PIPEDA experience
- Hands-on experience conducting privacy assessments involving personal information
- Experience leading/conducting PIAs for online and/or digital solutions
- Experience conducting assessments involving personal health information and third-party solutions/service-integration providers
- OPS or broader public-sector experience.
- Location: 20 Dundas St W Toronto Ontario
- Onsite: 5 days per week
- Contract: October 1 2026 to March 31 2027
- Extension: One possible extension term
- Openings: 1
- Allocation: 100%
- Security Clearance: No clearance required
- Submission Limit: Maximum 1 candidate
- Closing: September 30 2026 at 12:00 PM EST
Required Skills:
Mandatory Qualifications & Experience 1. Privacy Legislation & PIA Experience 40% Candidates must demonstrate: Strong experience with privacy legislation including: Freedom of Information and Protection of Privacy Act (FIPPA) Personal Health Information Protection Act (PHIPA) Personal Information Protection and Electronic Documents Act (PIPEDA) Demonstrated experience conducting privacy assessments involving personal information with specific examples clearly documented in the resume. Demonstrated experience leading and conducting privacy assessments involving online and/or digital solutions. Demonstrated experience leading and conducting assessments involving personal health information and third-party solutions such as private-sector/non-profit applications and/or service integration providers. Experience working with policy-development teams and reviewing/comparing policies and legislation to make informed recommendations concerning privacy protections. 2. Technical Understanding 30% Candidates must demonstrate: Experience identifying privacy risks and conducting PIAs across different technology platforms. Strong understanding of security encryption privacy protection and data-protection approaches for digital solutions. Experience assessing web-based solutions and backend integrations using APIs or similar technologies. Experience assessing privacy risks associated with integrations between: Legacy systems Web applications Digital solutions Cloud-based solutions Experience with cloud technologies and an understanding of their security and privacy considerations limitations and data-protection best practices. Knowledge of privacy protection standards and best practices. Understanding of business information and security architecture principles. Awareness of emerging technologies and their implications for protecting privacy and personal information. 3. Leadership & Communication 20% Candidates must demonstrate: Strong communication and stakeholder-engagement skills. Ability to lead discovery sessions and elicit information regarding technical solutions business processes and policies. Strong written communication skills for documenting assessment findings risks recommendations and mitigation strategies. Ability to interpret both technical and non-technical documentation. Ability to translate technical and complex privacy issues into practical recommendations. Strong organizational and time-management skills. Ability to manage multiple concurrent requests in a dynamic and agile environment. Strong presentation skills including the ability to communicate findings and recommendations to senior management and executives in clear understandable language. 4. Digital Identity Frameworks & Standards 5% Experience developing applying and/or evaluating digital identity trust frameworks. 5. Ontario Public Service Experience 5% Prior experience leading and conducting multiple PIAs within an Ontario Public Service (OPS) environment. Demonstrated knowledge and experience with OPS PIA processes existing templates expectations approvals and sign-off requirements. Additional Required Knowledge The successful candidate should also have: Excellent knowledge of privacy and security concepts trends and issues. Ability to interpret and communicate privacy principles and compliance requirements to technical and non-technical audiences. Knowledge and experience researching and applying privacy laws regulations jurisprudence and risk countermeasures. Knowledge of privacy-enhancing best practices. Knowledge of MFIPPA Municipal Freedom of Information and Protection of Privacy Act. Knowledge of PHIPA and its regulations and related jurisprudence. Familiarity with PIPEDA and the US PATRIOT Act. Familiarity with the OPS Privacy Impact Assessment Process and Tools. Understanding of related disciplines including: IT Security IT/System Design Privacy/Security Policy Development Business Architecture Legal Processes Freedom of Information Administration Business Analysis Risk Management Project Management Knowledge of information and records-management practices including classification retention and disposition. Knowledge of Accessibility for Ontarians with Disabilities Act (AODA) and related regulations and standards. Nice-to-Have Qualifications Professional certification in a related discipline such as IT Security or Architecture. Experience providing privacy education and training. Experience with Ontario Government policies and procedures including: Business case development Project approvals Policy development Previous OPS/public-sector experience. Critical Must-Have Screening Criteria Recruiters should not submit candidates who cannot clearly demonstrate the following four areas in their resume: FIPPA PHIPA and PIPEDA experience Hands-on experience conducting privacy assessments involving personal information Experience leading/conducting PIAs for online and/or digital solutions Experience conducting assessments involving personal health information and third-party solutions/service-integration providers Preferred OPS or broader public-sector experience. Work Arrangement & Contract Details Location: 20 Dundas St W Toronto Ontario Onsite: 5 days per week Contract: October 1 2026 to March 31 2027 Extension: One possible extension term Openings: 1 Allocation: 100% Security Clearance: No clearance required Submission Limit: Maximum 1 candidate Closing: September 30 2026 at 12:00 PM EST
Required Education:
Bachelors Degree in Computer Science Information Technology Cybersecurity Law Business Administration or a related disciplinePrivacy Information Security Risk Management or Architecture certification is an assetCIPP/C CIPM CISSP CISM or related privacy/security certification is an asset