Description
3 month remote contract with high chance of extension
Secret clearance required
Senior Privacy Consultant
Key Responsibilities:
- Lead the development, implementation, and maintenance of comprehensive Privacy Management Plans and Privacy Impact Assessments (PIAs) across diverse IT and cloud-native solutions, ensuring alignment with the Treasury Board Secretariat (TBS) Directive on Privacy Practices.
- Review, interpret, and operationalize strict privacy obligations on large government programs to ensure compliance across all phases of the data lifecycle (collection, usage, retention, disclosure, and disposal).
- Partner with Security Assessment & Authorization (SA&A) teams to map privacy controls within the Security Requirements Traceability Matrix (SRTM) and align system architectures with frameworks like ITSG-33, ISO/IEC 27002, and ISO/IEC 27018.
- Serve as a subject matter expert and primary conduit for privacy-related matters, navigating complex inquiries related to the Privacy Act and Access to Information Act (ATIP) for various government clients.
- Establish, manage, and execute privacy breach protocols, including maintaining rigorous disclosure tracking, conducting root-cause investigations, and executing remediation strategies to protect against outsized operational risks.
- Draft standard operating procedures (SOPs), ATIP request workflows, privacy breach response plans, and executive briefing materials tailored to both corporate and federal leadership.
- Plan and conduct comprehensive privacy risk assessments and compliance audits to proactively identify gaps, orchestrating pragmatic remediation strategies that keep projects moving forward securely.
Required Skills and Expertise:
- Strong, demonstrable experience working within the Government of Canada (GoC) GRC ecosystem, with deep knowledge of security, compliance, and privacy processes.
- Advanced understanding of Canadian public sector privacy legislation, including the Privacy Act, Access to Information Act, PIPEDA, and provincial equivalents.
- Extensive familiarity with federal and international security and privacy frameworks, including TBS Directives, ITSG-33, ISO/IEC 27018 (protection of PII in public clouds), and ISO/IEC 27001/2.
- Proven track record of translating abstract privacy principles into concrete architectural requirements and operational workflows for complex IT environments.
- Expert-level capability in drafting highly technical PIAs, Privacy Management Plans, and control responses that pass rigorous federal evaluation.
- Exceptional communication and presentation skills, with a proven ability to bridge the gap between technical teams, legal advisors, and executive-level government stakeholders.
- Relevant professional certifications (e.g., CIPP/C, CIPM, CIPT, CRISC, or equivalent GRC designations) are highly desirable.
ACCESSIBILITY
We’re committed to fostering an inclusive, equitable, and accessible workplace where every team member feels valued, respected, and supported, and has the opportunity to reach their full potential. We welcome and encourage applications from people with disabilities.
Accommodations are available on request for candidates taking part in all aspects of the selection process. For a confidential inquiry, simply email your recruiter directly or to make arrangements.
If you have questions regarding accessible employment at Ateko please email our Human Resources team at
Ateko
Derek Weber – Senior Recruiter





