FREE ACCESS
5,000–10,000 jobs/day
See all jobs on Scoutfield
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.
Core Competencies
Role fitCore Competencies
Use this summary to align your resume positioning with the role.
Demonstrates expertise in privacy, governance, and information security programs, with a strong ability to conduct Privacy Impact Assessments and integrate Privacy by Design principles. Proficient in drafting policies and conducting risk assessments while ensuring compliance with relevant regulations and frameworks.
Highest-signal resume keywords
Privacy Impact Assessments (PIAs/DPIAs)Information Security GovernanceRisk ManagementISO 27001 ComplianceCIPP/C Certification
ATS Keywords
Tailor your resumeApplicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills
Privacy GovernanceInformation SecurityRisk AnalysisPolicy DevelopmentData ProtectionAccess ManagementCloud SecurityData GovernanceCompliance AuditsVendor Security Assessments
Soft Skills
CollaborationCommunicationAnalytical ThinkingProblem Solving
Certifications & Qualifications
CIPP/CCIPP/ECIPMSecurity+CISSPCISMCRISC
Industry Keywords
GDPRLaw 25NISTSOC 2Data Processing Agreements (DPAs)Personal Information LifecycleCross-Border TransfersData ResidencyInformation ClassificationPrivacy by Design
About the role
Key responsibilities & impact- Contribute to the implementation, maintenance, and evolution of EXFO’s privacy, governance, and information security programs
- Advise business units on the protection of information assets, risk management, and legal, regulatory, and contractual requirements
- Develop and maintain governance, privacy, and information security policies, procedures, and controls
- Conduct Privacy Impact Assessments (PIAs/DPIAs) and support business and technology projects
- Participate in risk assessments, vendor assessments, compliance audits, and third-party risk analyses
- Contribute to the management of privacy and security incidents, including investigations, analyses, and remediation measures
- Participate in awareness and compliance activities
- Collaborate with business, legal, and technology teams to integrate privacy and security requirements from the design stage
- Develop, monitor, and present compliance, risk, and maturity metrics
- Perform other related duties as required
Requirements
What you’ll need- University degree in computer science, cybersecurity, information governance, law, business administration, or a related field
- Minimum of 5 to 7 years of experience in privacy, information security, governance, risk management, compliance, or information technology
- Ability to maintain and evolve privacy, governance, and information security programs
- Ability to interpret and apply Law 25, the GDPR, ISO 27001, and other applicable frameworks
- Experience conducting Privacy Impact Assessments (PIAs/DPIAs) and information risk analyses
- Ability to integrate Privacy by Design and Security by Design principles
- Ability to draft and maintain policies, procedures, standards, privacy notices, Data Processing Agreements (DPAs), and governance documentation
- Ability to conduct vendor security and privacy assessments
- Knowledge of data governance, data residency, cross-border transfers, retention, and the personal information lifecycle
- Strong knowledge of information security, access management, cloud security, information classification, and data protection
- Good knowledge of ISO 27001, SOC 2, NIST, or equivalent frameworks
- Fluency in spoken and written French and English
- Authorized to work in Canada
- CIPP/C, CIPP/E, CIPM, Security+, CISSP, CISM, CRISC, or equivalent certifications considered an asset
- A combination of relevant education and experience will also be considered
Benefits
Comp & perks- EXFO is an equal opportunity employer
- Inclusive environment committed to diversity
- Hybrid work arrangement
