Senior Privacy, Security & AI Governance Consultant

CGI

$95K — $185K *
Education, Government & Non-Profit
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • 8+ years of experience in cybersecurity, privacy, risk management, or IT governance.
  • Experience conducting Security Threat and Risk Assessments (STRAs) and Privacy Impact Assessments (PIAs).
  • Strong knowledge of information security governance and risk management frameworks.
  • Working understanding of BC FIPPA/FOIPPA privacy legislation.
  • Experience with operational security and privacy incident management.
  • Excellent communication skills for engaging with both technical and executive audiences.
  • Demonstrated ability to collaborate across teams, clients, and organizations.

Responsibilities

  • Provide privacy and security advisory services across CGI client engagements.
  • Interpret and apply privacy legislation and cybersecurity requirements for clients.
  • Lead Security Threat and Risk Assessments (STRAs) and Privacy Impact Assessments (PIAs).
  • Develop and maintain privacy and security policies, standards, and practices.
  • Support privacy and security incident management and remediation activities.
  • Advise on responsible AI and Generative AI governance.
  • Support data governance initiatives for client organizations.

Benefits

  • Comprehensive health and wellness programs.
  • Flexible work environment including hybrid work options.
  • Professional development and continuous learning opportunities.
  • Collaborative team culture with a focus on innovation.
  • Access to cutting-edge technology and resources.
Full Job Description
Find similar career opportunities

Senior Privacy, Security & AI Governance Consultant

Category: Cyber Security

Main location: Canada, British Columbia, Victoria

Position ID:J0926-1253

Employment Type: Full Time

Position Description:

CGI is seeking an experienced Senior Privacy, Security & AI Governance Consultant to provide privacy, cybersecurity, risk and governance leadership across client engagements within CGI's British Columbia Business Unit.
This is a hybrid delivery and consulting role. Approximately 50% of the position will initially support a major BC public sector health information system as its Privacy and Security Officer (PSO), with the remaining capacity supporting privacy and security requirements across other CGI BC accounts, business development activities, and CGI's growing Generative AI, Artificial Intelligence and Data Governance consulting practices.
The successful candidate will combine strong practical knowledge of privacy and information security with the ability to advise executives, business stakeholders, architects and delivery teams. The individual should be comfortable moving between operational security responsibilities, regulatory compliance, risk assessment, client advisory engagements and emerging areas such as responsible AI, AI governance and enterprise data governance.

Your future duties and responsibilities:

Privacy, Security & Risk Management
. Provide senior privacy and security leadership and advisory services across CGI client engagements.
. Interpret and apply applicable privacy legislation, cybersecurity requirements, contractual obligations and industry standards.
. Provide practical guidance regarding the protection of personal, sensitive, confidential and regulated information.
. Lead or support Security Threat and Risk Assessments (STRAs) and Privacy Impact Assessments (PIAs) for new solutions, technology changes, cloud services and application modernization initiatives.
. Identify, assess, document and communicate privacy and security risks and recommend appropriate mitigation strategies.
. Provide oversight and guidance regarding administrative, technical and physical security controls.
. Develop and maintain privacy and security policies, standards, procedures, playbooks and control frameworks.
. Support privacy and cybersecurity incident management, including triage, investigation, containment, impact assessment, notification analysis, recovery and lessons learned.
. Support vulnerability and remediation management, including assessment of emerging vulnerabilities and security advisories and coordination with technical teams.
. Support cybersecurity preparedness activities, including incident response planning and tabletop exercises.
. Support privacy and security compliance assessments and external audits, including evidence gathering, control validation, auditor engagement, remediation and reporting.
. Develop and deliver privacy and security awareness, guidance and training.
BC Public Sector & Health Privacy/Security
. Provide privacy and security expertise for CGI engagements with BC Government ministries, Crown organizations, health authorities, post secondary institutions and other public sector clients.
. Interpret and apply BC Freedom of Information and Protection of Privacy Act (FIPPA/FOIPPA) requirements and associated privacy obligations.
. Apply BC Government Office of the Chief Information Officer (OCIO) Information Security Policy, standards, guidance and security assessment practices.
. Understand privacy and security requirements associated with BC health information and applicable provincial health information legislation.
. Work effectively with client privacy offices, security teams, CISO/CIO organizations, risk teams and government security authorities.
. Coordinate privacy and security activities across CGI, client and third party organizations.
. Support remediation and tracking of security and privacy risks identified through assessments, audits and government risk registers.
AI & Generative AI Governance
. Advise CGI and clients on the responsible adoption and governance of Artificial Intelligence and Generative AI technologies.
. Develop and assess AI governance frameworks, policies, standards and operating models.
. Conduct or support AI risk and impact assessments, including privacy, security, data protection, ethical, regulatory and operational considerations.
. Advise clients on appropriate controls for Generative AI, Large Language Models (LLMs), AI agents and AI enabled applications.
. Assess risks related to confidential information, personal information, model inputs and outputs, prompt handling, training data, data residency, retention and third party AI services.
. Support development of AI acceptable use policies and governance processes.
. Advise solution architects and development teams on privacy by design, security by design and responsible AI by design principles.
. Assist clients in establishing AI governance committees, decision rights, approval processes, risk classification and ongoing monitoring.
. Maintain awareness of evolving Canadian and international AI legislation, regulation, standards and industry practices.
. Contribute privacy, security and governance expertise to CGI AI strategy, GenAI pilots, proofs of concept and production implementations.
Data Governance & Responsible Data Use
. Advise clients on enterprise data governance, data protection and responsible data use frameworks.
. Support development of data classification, handling, retention, access, stewardship and accountability models.
. Assess privacy and security considerations associated with analytics, data platforms, cloud data services, data lakes/lakehouses and AI/ML environments.
. Advise on appropriate use of personal, sensitive and confidential information across development, testing, analytics and AI environments.
. Support development of data governance operating models, policies, standards and controls.
. Work collaboratively with data architects, enterprise architects, privacy specialists, cybersecurity teams and business stakeholders.
. Help clients connect traditional privacy and security governance with emerging data and AI governance requirements.
Consulting & Business Development
. Act as a senior privacy, security, AI and data governance subject matter expert supporting CGI client engagements.
. Participate in client discovery sessions, workshops, assessments and executive briefings.
. Translate regulatory and technical requirements into practical business recommendations and implementation roadmaps.
. Support development of privacy, cybersecurity, AI governance and data governance consulting offerings.
. Contribute to RFP/RFSQ responses, proposals, presentations, estimates and statements of work.
. Participate in solution reviews and provide privacy and security input into proposed CGI architectures and services.
. Support account teams in identifying privacy, cybersecurity, AI governance and data governance opportunities.
. Develop reusable methodologies, templates, assessment tools and thought leadership that strengthen CGI capabilities in these areas.
. Where appropriate, lead small consulting engagements or privacy/security workstreams within larger transformation programs.

Required qualifications to be successful in this role:

. Approximately 8+ years of progressive experience in information security, cybersecurity, privacy, risk management, IT governance or related disciplines, with sufficient experience to operate independently in a senior advisory capacity.
. Demonstrated experience conducting or supporting STRAs, PIAs, security assessments, risk assessments and compliance reviews.
. Strong understanding of information security governance, risk management and security control frameworks.
. Working knowledge of BC FIPPA/FOIPPA and privacy requirements affecting BC public sector organizations.
. Experience applying or working within the BC Government OCIO Information Security Policy (ISP) or comparable government security frameworks.
. Experience supporting security/privacy incidents and associated investigation, assessment, remediation and reporting.
. Experience working with technical teams across application development, infrastructure, cloud, networking and IT operations.
. Strong written and verbal communication skills with the ability to communicate privacy and cybersecurity risk to both technical and executive audiences.
. Demonstrated ability to work across organizational boundaries involving clients, delivery teams, vendors, auditors and senior leadership.
Preferred Qualifications
. Previous privacy/security experience within the Government of British Columbia, a BC Crown corporation, BC health authority or major BC public sector organization.
. Experience working with the BC Government OCIO, Ministry privacy/security offices or comparable government security authorities.
. Experience with healthcare information systems and protection of personal health information.
. Knowledge of HIPAA and healthcare privacy/security practices.
. Experience with AI governance, Responsible AI, Generative AI or AI risk management.
. Experience with data governance, data management or enterprise information governance.
. Experience with cloud security and privacy considerations involving Microsoft Azure, AWS, Google Cloud or SaaS environments.
. Familiarity with frameworks and standards such as ISO/IEC 27001/27002, ISO/IEC 27701, NIST Cybersecurity Framework, NIST AI Risk Management Framework, ISO/IEC 42001, COBIT or similar frameworks.
. Experience supporting public sector procurement, proposals or consulting business development.
Certifications
Candidates should hold one or more recognized privacy, security, risk or governance certifications. A combination of certifications and demonstrated equivalent experience may be considered.
Strongly preferred: CISSP; CISM; CISA; CRISC; IAPP CIPP/C; IAPP CIPM
Additional assets: ISO/IEC 27001 Lead Implementer or Lead Auditor; CCSP; IAPP AIGP; CDMP or comparable data management/data governance certification; Microsoft, AWS or Google Cloud security certifications
Candidate Profile
The ideal candidate is more than a cybersecurity specialist. CGI is looking for someone who can operate effectively at the intersection of privacy, cybersecurity, risk, data and emerging AI technologies.
They should be comfortable spending part of their time providing hands on operational privacy and security leadership for a critical public sector environment and the remainder working as a trusted advisor across multiple clients and CGI teams.
The successful candidate will be able to move comfortably between a technical discussion with architects and cybersecurity specialists, a regulatory discussion with privacy professionals, an executive risk discussion with senior leadership, and a consulting workshop with a client exploring how to safely adopt Generative AI.

#LI-ST3

CGI is required by law in some jurisdictions to include a reasonable estimate of the compensation range for this role. The determination of this range includes various factors including but not limited to skill set level, geographic market, experience and training, and licensure and certifications. Compensation decisions are dependent on the facts and circumstances of each case. A reasonable estimate of the current range in British Columbia is $95,000 $185,000.

Skills:
  • Cloud App Security Broker
  • Cyber Security Strategy
  • IT security governance
  • Security administration
  • Security Architecture


Similar Jobs

More Jobs at CGI

More Education, Government & Non-Profit Jobs

Find similar Senior Privacy, Security & AI Governance Consultant jobs: