Director Privacy and Data Ethics, Canadian Privacy Office
Sun Life Financial Voir toutes les offres
- Toronto, ON
- 110.000-180.000 $ par an
- Permanent
- Temps-plein
- Lead and elevate an effective Canadian Privacy Office team to serve as a privacy and AI consulting hub for the Canadian Business Units
- Provide expert advisory support and independent effective challenge for complex initiatives involving personal information, including the use of AI/GenAI/Agentic technologies
- Provide oversight and strategic direction on privacy components in all pillars of the RCM program, including regulatory changes, regulatory compliance issues, control assessments and effectiveness reviews, monitoring and testing
- Develop, report and monitor privacy Key Risk Indicators (KRIs) and other program metrics to support ongoing control monitoring and program maturity
- Lead the design, build and implementation of digital tools that automate and streamline activities performed by the Canadian Privacy Office and drive operational excellence
- Oversee privacy incident management, personal information access requests, privacy complaints, regulatory investigations and interactions, acting as a primary escalation point
- Review and challenge PIAs and bias assessments for complex initiatives (e.g. technology platforms, AI solutions), identifying control gaps and providing strategic recommendations
- Support the AVP execute their advisory and oversight accountability as a BUCO for the Client Digital Experience Office, including identification of regulatory requirement and key controls, regulatory change management, issue identification, remediation tracking, control assessments, and compliance monitoring activities
- Create and present reports and observations to senior business stakeholders, including input to the Senior Compliance Officer and Enterprise Chief Privacy Officer reports
- Lead the development of privacy and responsible data use training, guidance documents and employee-facing content, aligned with current regulations, regulatory expectations and industry best practices
- Partner with Compliance, Global Privacy, Legal and Risk teams to foster a culture of compliance throughout the organization by promoting ethical behavior, accountability, and adherence to regulatory standards
- 10+ years of experience working in privacy compliance roles in a complex matrixed financial institution, preferably OSFI regulated, with minimum 5 years in leadership positions managing privacy teams and programs
- Excellent communication skills with proven ability to translate complex privacy and AI concepts for senior leaders and diverse business audiences, applying strong business acumen, verbal and written communication skills
- Experience with Regulatory Compliance Management frameworks and programs
- Demonstrated success navigating complex, multi-matrix organizations in fast-paced environments, managing multiple strategic priorities simultaneously while providing operational oversight
- Exercise expert judgement when advising on complex projects with conflicting and ambiguous requirements
- Comfortable with data-driven decision making and working in digital transformation environments
- Ability to build and maintain relationships with regulators, senior leaders, and cross-functional stakeholders, with track record of influencing change and building consensus across IT, legal, risk and senior leadership levels
- Proven ability to lead, develop, and mentor privacy compliance teams with experience managing resources, and strategic planning for privacy tools, frameworks and governance structures
- Knowledge of and experience with developing AI Agents, using GenAI tools, and identifying and deploying innovative solutions to drive efficiency and accuracy
- Extensive knowledge of PIPEDA, provincial privacy legislation and other relevant privacy frameworks
- Understanding of relevant OSFI guidelines and regulatory guidance on AI and emerging technologies
- Knowledge of AI governance and responsible AI principles
- Understanding of data systems, cybersecurity concepts, and privacy-enhancing technologies
- University degree
- CIPP/C (Certified Information Privacy Professional - Canada) or CIPM (Certified Information Privacy Manager) or willingness to obtain within a year