Privacy Specialist 7+ years of experience
Offre en anglaisLead and conduct privacy impact assessments for digital identity solutions, specifically focusing on mobile and decentralized credential ecosystems. Develop privacy-enhancing tools, consent management frameworks, and data governance architectures to align with government programs.
- Sur place
- Toronto, ON
- Publié 11 août 2026
- Postuler avant le 10 sept. 2026
- 1 poste
D’autres postes auxquels postuler directement
Des possibilités semblables publiées par des employeurs qui recrutent sur Jobs.ca, sans formulaire externe.
Résumé du poste
Requirements Experience and Skill Set Requirements: Must Haves: Experience and understanding of credential holder centric ecosystems (decentralized identity models like SSI), supporting platforms and digital wallets Experienced in leading and conducting privacy assessments involving online and/or mobile digital solutions that handle personal and health related information, Demonstrated experience and familiarity with strong security, encryption and privacy protection approaches to digital solutions, including mobile; web based and backend integrations via API or similar approaches Experience with decentralized credential systems, supporting platforms/technologies and digital wallets that can secure a Holder's personal information and protect their privacy through selective disclosure and zero-knowledge proofs. Skill Set Requirements: Must-have experience in: Conducting privacy impact assessments involving both PHIPA and FIPPA, citing examples in resume Conducting PIAs involving mobile app solutions and the unique security and privacy challenges associated with such platforms Experience and understanding of digital credential platforms and decentralized models for credentials (self-sovereign identity-SSI) Develop privacy-enhancing tools and techniques Develop KPIs and report metrics Developing ways and means to align with broader government programs and practices Developing designs and architectures to inform a ‘privacy/data governance function’ that can be implemented for the DI Program and potentially all of ODS Experience in developing and implementing Consent management frameworks, policy and supporting business practices. In addition, must have the ability to: Provide privacy and data governance advisory services Assist with development of statutory and regulatory instruments to address digital identity and related privacy matters • Experience with Verifiable Credentials , specifically SSI model approaches. • Knowledge and ability to create and understand data flow diagrams and business process diagrams; • Ability to recognize the need for, and seek input from external experts as required; • Conduct PIAs as required • Develop privacy-enhancing tools and techniques • Develop KPIs and report metrics • Develop ways and means to align with broader government programs and practices • Develop designs and architectures to inform a ‘privacy/data governance function’ for the DI Program and potentially all of ODS • Provide privacy and data governance advisory services • Assist with development of statutory and regulatory instruments to address digital credentials and related privacy matters Nice to have: Public Sector experience Privacy Assessment, Consent Management, Policy and Legislative Requirements: Experienced in privacy legislation including Freedom of Information and Protection of Privacy Act (FIPPA), Personal Health Information Protection Act (PHIPA), the Personal Information Protection and Electronic Documents Act (PIPEDA) Experienced in conducting privacy assessments involving personal information and personal health information citing examples in resume. Experienced in leading and conducting privacy assessments involving online and/or mobile digital solutions that handle personal and health related information, Experience and understanding of credential holder centric ecosystems (decentralized identity models like SSI), supporting platforms and digital wallets Lead and conducted assessments involving personal health information involving third party solutions (e.g private sector or non-profit application solutions) and/or service integration providers Experienced working with legal council and/or policy development teams; reviewing and comparing policies and legislation to make informed recommendations to ensure adequate legal and/or statutory authorities, privacy protections and record keeping considerations are addressed in support of program and project specific objectives. SME and experienced in developing approaches for consent management; developing conceptual and logical models, identifying system and business requirements Technical understanding: Experience with privacy risks and conducting PIAs associated with integration between legacy systems, web applications, mobile and cloud based solutions to obtain, retrieve and synchronize information. Experience with privacy risks and conducting PIAs involving mobile app solutions and the unique security and privacy challenges associated with such platforms Demonstrated experience and familiarity with strong security, encryption and privacy protection approaches to digital solutions, including mobile; web based and backend integrations via API or similar approaches. Experience with decentralized credential systems, supporting platforms/technologies and digital wallets that can secure a Holder's personal information and protect their privacy through selective disclosure and zero-knowledge proofs. Familiar with Digital Wallet technologies (native within OS or third party) including the security and privacy considerations, limitations and best practices for local data protection on mobile devices Familiar with cloud based digital wallet technologies including the security and privacy considerations, limitations and best practices for data protection Experience, knowledge and understanding of privacy protection standards and best practices, business, information and security architecture principles and emerging technology related to the protection of privacy and personal information Leadership and Communications: Demonstrated strong communication and engagement skills with ability to lead teams in discovery sessions to elicit details of technical solutions, business processes and/or policies; strong writing skills to document findings, recommendation, etc Demonstrated ability to interpret both technical (e.g architecture design documents, process flows, state transition diagrams, etc) and non technical documentation to conduct assessment of impacts and to develop mitigation strategies Strong organizational and time management skills to manage multiple and concurrent requests in an agile and highly dynamic work environment setting. Strong presentation abilities to communicate findings, recommendations, etc to senior management and executives to inform decision making; able to communicate complex problems/issues in a simple terms Digital Credential Frameworks and Standards: Experience in developing, applying and/or evaluating trust frameworks such as the PCTF, eIDAS, or similar. Experience with digital credential standards such as NIST, W3C, etc. Experience with and understanding of SSI models, how they relate/impact privacy, consent, data governance.
Ce que vous ferez
Lead and conduct privacy impact assessments for digital identity solutions, specifically focusing on mobile and decentralized credential ecosystems. Develop privacy-enhancing tools, consent management frameworks, and data governance architectures to align with government programs.
Exigences
Requires over 7 years of experience with a deep understanding of SSI, digital wallets, and privacy legislation including PHIPA and FIPPA. Must be proficient in conducting PIAs for mobile and cloud-based solutions and familiar with W3C and NIST credential standards.
Autres compétences pertinentes
Relevées dans la description du poste. Confirmez les exigences importantes ci-dessus.
- Privacy Impact Assessments
- Self-Sovereign Identity (SSI)
- Decentralized Identity
- Digital Wallets
- PHIPA
- FIPPA
- PIPEDA
- Consent Management
- Zero-Knowledge Proofs
- Verifiable Credentials
- Data Governance
- Encryption
- API Security
- Data Flow Diagramming
- Trust Frameworks
- Privacy-Enhancing Technologies
Domaines d’emploi
- Technology
- Government & Public Sector
- Legal
- Security & Safety
- Consulting
Renseignements supplémentaires
- Expérience minimale
- 5+ ans
- Postuler avant le
- 10 sept. 2026
- Langue de l’offre
- anglais
- Heures de travail
- 40 heures par semaine
- Niveau d’expérience
- Mid-Senior level
- Mode de candidature
- La candidature directe est offerte