Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
Scoutfield Logo

See all jobs on Scoutfield

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
EXFO

Senior Analyst, Privacy and Information Security

EXFO

. Contribute to the implementation, maintenance, and evolution of EXFO’s privacy, governance, and information security programs .

Posted 10/8/2026full-timeQuebec City • CanadaSeniorWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates expertise in privacy, governance, and information security programs, with a strong ability to conduct Privacy Impact Assessments and integrate Privacy by Design principles. Proficient in drafting policies and conducting risk assessments while ensuring compliance with relevant regulations and frameworks.

Highest-signal resume keywords
Privacy Impact Assessments (PIAs/DPIAs)Information Security GovernanceRisk ManagementISO 27001 ComplianceCIPP/C Certification

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
Privacy GovernanceInformation SecurityRisk AnalysisPolicy DevelopmentData ProtectionAccess ManagementCloud SecurityData GovernanceCompliance AuditsVendor Security Assessments
Soft Skills
CollaborationCommunicationAnalytical ThinkingProblem Solving
Certifications & Qualifications
CIPP/CCIPP/ECIPMSecurity+CISSPCISMCRISC
Industry Keywords
GDPRLaw 25NISTSOC 2Data Processing Agreements (DPAs)Personal Information LifecycleCross-Border TransfersData ResidencyInformation ClassificationPrivacy by Design

About the role

Key responsibilities & impact
  • Contribute to the implementation, maintenance, and evolution of EXFO’s privacy, governance, and information security programs
  • Advise business units on the protection of information assets, risk management, and legal, regulatory, and contractual requirements
  • Develop and maintain governance, privacy, and information security policies, procedures, and controls
  • Conduct Privacy Impact Assessments (PIAs/DPIAs) and support business and technology projects
  • Participate in risk assessments, vendor assessments, compliance audits, and third-party risk analyses
  • Contribute to the management of privacy and security incidents, including investigations, analyses, and remediation measures
  • Participate in awareness and compliance activities
  • Collaborate with business, legal, and technology teams to integrate privacy and security requirements from the design stage
  • Develop, monitor, and present compliance, risk, and maturity metrics
  • Perform other related duties as required

Requirements

What you’ll need
  • University degree in computer science, cybersecurity, information governance, law, business administration, or a related field
  • Minimum of 5 to 7 years of experience in privacy, information security, governance, risk management, compliance, or information technology
  • Ability to maintain and evolve privacy, governance, and information security programs
  • Ability to interpret and apply Law 25, the GDPR, ISO 27001, and other applicable frameworks
  • Experience conducting Privacy Impact Assessments (PIAs/DPIAs) and information risk analyses
  • Ability to integrate Privacy by Design and Security by Design principles
  • Ability to draft and maintain policies, procedures, standards, privacy notices, Data Processing Agreements (DPAs), and governance documentation
  • Ability to conduct vendor security and privacy assessments
  • Knowledge of data governance, data residency, cross-border transfers, retention, and the personal information lifecycle
  • Strong knowledge of information security, access management, cloud security, information classification, and data protection
  • Good knowledge of ISO 27001, SOC 2, NIST, or equivalent frameworks
  • Fluency in spoken and written French and English
  • Authorized to work in Canada
  • CIPP/C, CIPP/E, CIPM, Security+, CISSP, CISM, CRISC, or equivalent certifications considered an asset
  • A combination of relevant education and experience will also be considered

Benefits

Comp & perks
  • EXFO is an equal opportunity employer
  • Inclusive environment committed to diversity
  • Hybrid work arrangement