Aviso
Privacy Risk Specialist
AvisoCanada1 day ago
Full-timeLegal

Aviso:

At Aviso, we are dedicated to improving the financial well-being of Canadians. As a leading wealth management organization, we are committed to leadership, innovation, partnership, responsibility, and community. Working with talented and energetic professionals who exemplify our values every day, you will quickly notice that our people and dynamic ‘oneaviso' culture sets us apart. If you are looking for interesting and challenging work, at a company committed to its people, find out more about what Aviso has to offer at www.aviso.ca.

The Opportunity:

We're looking for a seasoned Privacy Risk Specialist with a strong work ethic along with excellent analytical and communication skills to join our privacy team. The ideal candidate will be someone who is creative and thinks outside-the-box and is a self-starter who takes ownership over initiatives.

Reporting to Director, Privacy, the Privacy Risk Specialist will help enhance Aviso's data privacy framework and implement privacy strategies and processes to support Aviso's Legal & Privacy Department and other members of the Company as required. The Privacy Risk Specialist will implement industry best practices and solutions to reduce risk and ensure the protection of customer data. The Privacy Risk Specialist will leverage their knowledge of privacy law, regulations and best practices to assist with privacy inquiries from all departments of the organization and will act as an initial point of contact and lead for the management of all Privacy Impact Assessments (PIAs).

Who you are:

  • Service - You put your clients' needs first. You advocate service excellence, and work to deliver client-centric solutions, and proactively develop strategic partnerships that allow Aviso Wealth to become a trusted advisor and partner
  • Execution - You are committed to achieving your goals and to succeed. This includes focusing on "getting things done", as well as recognizing and taking advantage of opportunities as they arise. You are consistently looking for ways to improve your personal best and see value in continuous improvement. You take accountability for your actions and learn from mistakes
  • Collaboration - You work collaboratively with others with the common goal of driving positive results. Making meaningful contributions to your team to achieve organizational goals is a priority. You proactively encourage collaboration, build trust and inclusion, and work to establish effective relationships both inside and outside of the organization

What your day looks like:

As a Privacy Risk Specialist, you will be a seasoned subject matter expert and key contributor to the advancement of Aviso's Privacy Program, ensuring that privacy obligations are met in alignment with internal policies, Privacy by Design principles, and applicable legislation. You will lead the maintenance and execution of a comprehensive Privacy Impact Assessment (PIA) framework, including control standards that support enterprise-wide compliance and risk mitigation. Working closely with IT, developers and project teams, you will embed privacy into system design through control mapping and proactive risk identification, enabling secure and compliant data handling across all environments.

Privacy Program Leadership

  • Seasoned SME to serve as the central point of contact for all privacy-related projects, vendor engagements, new system integrations, and AI-related inquiries
  • Lead the development and implementation of Aviso's privacy management framework, including tools, policies, processes, and training
  • Promote a culture of privacy awareness and provide expert guidance across the organization

Assessment & Compliance

  • Conduct complex and technical Privacy Impact Assessments (PIAs), Transfer Impact Assessments (TIAs), AI Assessments, and Privacy Compliance Audits, while also performing privacy risk and vendor assessments. These activities embed Privacy by Design and Default principles into products and services to ensure robust privacy compliance and risk mitigation
  • Create and maintain processes for TIAs and ensure alignment with cross-jurisdictional data processing requirements
  • Monitor and interpret emerging privacy legislation and AI governance standards to ensure proactive compliance

Governance & Oversight

  • Collaborate with internal stakeholders to maintain records of processing activities and ensure data lifecycle compliance
  • Evaluate vulnerabilities identified through PIAs, TIAs or AI Assessments and lead the implementation of corrective actions
  • Communicate emerging privacy risks and manage consistency of practices across business units
  • Conduct systematic audits to identify areas for improvement and non-compliance

Reporting & Metrics

  • Develop and track KPIs/KRIs related to privacy assessments and program performance
  • Present regular reports and insights to executives and governance committees when applicable
  • Maintain logs of outstanding remediation plans and ensure timely updates from initiative owners

Stakeholder Engagement

  • Work closely with business units, IT, legal, and external regulators to uphold privacy governance
  • Provide privacy consultation and support during system development, procurement, and modernization initiatives
  • Ensure timely identification and resolution of privacy risks without impacting project timelines
  • Participate in the Product Operating Model and provide subject matter expertise on privacy controls during the design and implementation of pilot programs

Requirements

Your experience and skills:

  • Privacy Impact Assessment Expertise: Minimum 3 -5 years of experience conducting PIAs for medium to high complexity projects, including both cloud-based and on-premise environments
  • Operational Privacy Experience: At least 5 years of hands-on operational privacy experience in a corporate or financial  industry setting
  • Privacy Requirements Drafting: 5+ years of experience drafting and reviewing privacy requirements for data sharing agreements
  • Legislative Knowledge: Deep understanding and practical implementation of Canadian privacy legislation, including PIPEDA, provincial laws (e.g., BC/AB PIPA, Quebec's Law 25), CASL, FISA 702, EO 12333, OECD Privacy Principles, and other emerging privacy and AI regulations
  • Technical PIA Execution: Proven experience performing PIAs and TIAs on complex IT applications across cloud and on-premise infrastructures
  • Information Security Acumen: Strong grasp of technical and information security concepts relevant to privacy risk assessment
  • Reporting & Issue Management: Skilled in preparing and communicating PIA findings to business units, tracking outstanding issues, and coordinating with project teams for resolution
  • Privacy Control Optimization: Ability to provide actionable recommendations to enhance privacy controls across business lines
  • Investigations & Audits: Experience conducting privacy investigations, compliance reviews, and audits where applicable
  • Policy Development & Implementation: Demonstrated success in initiating, developing, and implementing privacy policies, procedures, and practices using solid project management skills
  • Collaboration & Influence: Ability to build trust, foster professional relationships, and contribute to an inclusive and high-performance culture
  • Regulatory Engagement: Experience working with regulatory bodies and navigating regulatory matters
  • Cross-Functional Coordination: Capable of managing workstreams that span multiple departments
  • Self-Starter Mindset: Innovative thinker with strong analytical, research, documentation, and project management skills

Nice-to-Haves

  • Educational Background: Degree in law, information technology, business, or a related field
  • Certifications: IAPP certifications such as CIPP/C,  CIPP/M, or AIGP
  • IT/Data Governance Experience: Familiarity with IT systems or data governance practices
  • Industry Experience: Background in the financial services or securities industry
  • Language Skills: Fluent communication skills in English are required and bilingual skills in French are an asset

Benefits

Why Aviso?

At Aviso, you will find a dynamic and inclusive culture that rewards innovation and celebrates success.
Here are a few things that set us apart:

  • Competitive compensation package that rewards and recognizes individual contributions
  • Excellent health, dental and insurance benefits to meet the diverse needs of our employees
  • Generous vacation time, fitness benefit, parental leave top-up options
  • Matching contributions to our retirement program
  • Commitment to the continuous improvement of our staff through learning & development and an education assistance program
  • Regular social events to foster teamwork

Your Information

By submitting your application, you consent to the collection, use, and disclosure of your provided personal information for the purposes of assessing your qualifications and suitability for employment with Aviso. Your information will be handled in accordance with applicable Canadian privacy laws, including the Personal Information Protection and Electronic Documents Act (PIPEDA) and relevant provincial legislation. Your data may be shared with authorized personnel involved in the recruitment process and retained only as long as necessary to fulfill these purposes or as required by law.

Further information is available on the Privacy link on our Career Page - Privacy Policies

Equal Employment Opportunity

Aviso welcomes and encourages applications from all qualified individuals including persons with disabilities. If you require an accommodation, we will work with you to meet your needs in all stages of the hiring process.

We thank all applicants for their interest, however, only those selected for further consideration will be contacted.

No recruiters or agencies, please.

Company Overview:

Aviso is a leading wealth management and investment services provider for the Canadian financial industry, with approximately $145 billion in total assets under administration and management, and over 1,000 employees. We're building a comprehensive, technology-enabled, client-centric wealth services ecosystem. Our clients include our partners, advisors, and investors. We're a trusted partner for nearly all credit unions across Canada, in addition to a wide range of portfolio managers, investment dealers, insurance and trust companies, and introducing brokers. Our partners depend on Aviso for specific solutions that give them a competitive edge in a rapidly evolving, highly competitive industry. Our investment dealer and mutual fund dealer and our insurance services support thousands of investment advisors. Our asset manager, NEI Investments, specializes in investing responsibly. Our online brokerage, Qtrade Direct Investing®, empowers self-directed investors, and our fully automated investing service, Qtrade Guided Portfolios®, serves investors who prefer a hands-off approach. Aviso Correspondent Partners provides custodial and carrying broker services to a wide range of firms. We have offices in Toronto, Vancouver, Montreal, and Winnipeg. Aviso is backed by the collective strength of our owners: the credit union Centrals, Co-operators/CUMIS, and Desjardins. We're proud to power businesses that empower investors.

A career with Aviso means being part of a group of talented, energetic professionals who live their values every day, and belonging to an organization dedicated to your success and career development. If you're looking for interesting and challenging work, at a company committed to its people, apply to join our team.

Salary

This position is posted with an expected salary range of $115,000 - $130,000 CAD annually. Individual compensation packages are based on various factors unique to each candidate and the requirements of the position.

Key Skills

Ranked by relevance