Business Analyst (Privacy Foundation & Governance)
Raise
Job Description
Business Analyst (Privacy Foundation & Governance)
- Pay Rate: $66.42/hour, depending on experience
- Contract Length:12 months
- Location: Calgary Alberta
Raise is currently hiring a Business Analyst (Privacy Foundation & Governance) on behalf of our client. They’re expanding their team to meet growing needs, making this a unique opportunity to work with an industry leader.
Note: The primary pay rate is based on T4 classification; however, we will also consider applications from candidates interested in an INC classification, where applicable.
Description
The Privacy Business Analyst in this role will support the design, implementation, and operationalization of our clients enterprise privacy program and governance capabilities.Working closely with the Privacy Officer, Program Manager, and external privacy consultants, this role will help identify and remediate privacy capability gaps, strengthen the handling of personal information, and build robust operating models. You will play a pivotal role in establishingprivacy foundation, scaling synthetic data capabilities, and ensuring compliance across digital, commercial, and operational domains.
Responsibilities
- Privacy Foundation: Support the establishment of WestJet’s privacy office, operating model, and accountability framework to strengthen governance, reduce risk, and improve regulatory compliance.
- Operational Enablement: Assist in standing up the core privacy team framework, reviewing and communicating enterprise privacy policies, and implementing an effective privacy incident escalation process.
- Consent Management: Drive business analysis, workflow mapping, and requirements gathering for the evaluation and RFP process of a centralized Consent Management tool.
- Privacy-Protected Data Initiatives: Help establish enterprise synthetic data capabilities, governance, and standards to minimize privacy risk while scaling testing, software development, analytics, and AI adoption.
- Privacy Assessments: Conduct and support Privacy Impact Assessments (PIAs), Data Subject Access Requests (DSARs), data mapping, and privacy compliance reviews across key business units.
Qualifications
- 5+ years of combined experience in Privacy, Data Protection, Information Governance, Risk Management, Compliance, or Business Analysis.
- Demonstrated hands-on experience supporting enterprise-wide privacy programs, regulatory compliance transformations, or privacy governance implementations.
- Direct experience performing or supporting PIAs, data flow mapping, privacy risk assessments, and compliance audits.
- Experience authoring and operationalizing privacy processes, internal controls, and operating models.
- Professional experience within large, complex, or heavily regulated organizations.
- Nice-to-Have Experience
- Familiarity with consent management platforms, preference centers, or cookie consent solutions.
- Experience building or supporting privacy incident management and breach response workflows.
- Exposure to privacy-enhancing technologies (PETs), such as synthetic data generation, data masking, de-identification, and anonymization.
- Knowledge of broader data governance, AI governance, or responsible AI frameworks.
- Prior experience within the airline, travel, aviation, or financial services sectors.
- Skills & Competencies
- Strong working knowledge of Canadian and international privacy regulations and frameworks, including PIPEDA, GDPR, and provincial equivalents.
- Solid understanding of data protection principles, privacy-by-design, data minimization, retention schedules, and consent management practices.
- Exceptional requirements gathering, process mapping, gap analysis, and stakeholder facilitation skills.
- Proven ability to partner effectively with Legal, Information Security, Data Engineering, IT, and operational business stakeholders.
- Superior written communication skills with a track record of creating executive-ready documentation, recommendations, standard operating procedures (SOPs), and governance materials.
- Education and Certifications
- Post-secondary degree in Business Administration, Information Systems, Law, Computer Science, or a related discipline.
- Certifications (Preferred/Asset): Professional privacy designations such as Certified Information Privacy Professional (CIPP/C, CIPP/E) or equivalent recognized privacy credentials.
We strive to build teams that reflect the diversity of the communities we work in. We encourage all qualified applicants to apply, including people from traditionally underrepresented groups such as women, visible minorities, Indigenous peoples, people identifying as LGBTQ2SI, veterans, and people with visible/nonvisible disabilities.
#J-18808-Ljbffr