Senior Manager, Information Compliance – AI Governance & Privacy at master-TMS | Toronto | Rezi

Senior Manager, Information Compliance – AI Governance & Privacy at master-TMS

Senior Manager, Information Compliance – AI Governance & Privacy

master-TMS · Toronto

4 days ago

Senior Manager, Information Compliance – AI Governance & Privacy

master-TMS · Toronto

5 days ago
Resume preview

Impress employers and recruiters.
Choose from hundreds of resume examples.

Target Resume Now

About the Role

This role sits in the Information Compliance Team and reports into the Head of Information Compliance, with a dotted reporting line to the Chief Compliance Officer (CCO). The team works across AI compliance, information security, privacy, and governance topics to help protect client, company, and personal data while enabling responsible technology adoption. This is a senior individual contributor role for a professional with a hybrid profile: privacy and AI governance expertise, legal/compliance judgment, and strong technical fluency. You will not be expected to be a full-time software engineer, but you must be credible in technical design discussions with data scientists, AI engineers, product owners, cloud/platform teams, IT, security, and client project teams. Your focus will be to ensure that AI tools, solutions, platforms, and products are developed and used responsibly, securely, and in line with statutory requirements, client confidentiality obligations, contractual commitments, and internal policies, standards, and procedures. This is not a policy-only compliance role. We are looking for someone who enjoys getting close to the technology, understanding how systems actually work, and translating requirements into practical controls, implementation guidance, and scalable governance patterns that teams can use.

Responsibilities

  • Embed AI governance and privacy into technology solutions.
  • Help teams build and use AI-enabled tools, products, platforms, and workflows in a compliant, secure, and responsible way from the start.
  • Translate requirements into technical controls.
  • Convert privacy, AI governance, client confidentiality, information security, contractual, and internal policy requirements into actionable technical controls, implementation standards, and security guardrails.
  • Review technical designs and data flows.
  • Assess architecture diagrams, data-flow diagrams, AI workflow designs, vendor/tool documentation, integration patterns, cloud/SaaS configurations, and product requirements to identify risk and recommend controls.
  • Advise on privacy and security control implementation.
  • Provide practical guidance on controls such as identity and access management, role-based access, data classification, encryption, retention and deletion, logging and monitoring, DLP, auditability, human oversight, and secure AI use.
  • Partner with project, data, AI, IT, and security teams.
  • Work directly with client project teams and internal teams to advise on compliant solution design, data use, vendor and tool use, confidentiality safeguards, and risk mitigations.
  • Support AI and privacy governance reviews.
  • Help assess AI use cases, data sources, platforms, vendors, model or tool behavior, prompt and output handling, and solution designs.
  • Identify legal, privacy, confidentiality, information security, and AI governance risks and recommend practical ways to address them.
  • Build scalable governance frameworks.
  • Develop and maintain playbooks, checklists, control libraries, standards, guidance materials, and reusable architecture/control patterns that help teams apply Privacy by Design, Governance by Design, Security by Design, and Responsible AI principles consistently.
  • Promote awareness and responsible adoption.
  • Contribute to training and communication initiatives that help colleagues use AI and data responsibly while protecting client information and confidential data.

Requirements

  • 7+ years of relevant experience in privacy engineering, AI governance, technology compliance, information security, cyber/privacy GRC, data protection, cloud governance, product compliance, legal/compliance operations with technical implementation exposure, or a related field.
  • Demonstrated technical fluency in modern technology environments.
  • Ability to read and challenge architecture diagrams, data-flow diagrams, solution designs, system integration patterns, security/privacy control mappings, and vendor technical documentation.
  • Hands-on or implementation-adjacent experience with technical controls such as identity and access management, role-based access controls, data classification, encryption, logging and monitoring, DLP, retention/deletion, cloud/SaaS governance, secure SDLC, or AI tool governance.
  • Experience translating legal, regulatory, contractual, client confidentiality, or internal policy requirements into technical or operational controls that can be implemented by technology teams.
  • Ability to advise senior stakeholders and influence cross-functional teams without relying on direct reporting authority.
  • Strong analytical judgment and the ability to balance risk, business needs, user experience, and practical implementation.
  • Excellent communication skills, including the ability to explain complex compliance and technology concepts in plain language.
  • Ability to manage multiple priorities independently in a fast-moving, international environment.
  • Professional fluency in English.

Skills

  • Privacy engineering
  • AI governance
  • Technology compliance
  • Information security
  • Cyber/privacy GRC
  • Data protection
  • Cloud governance
  • Product compliance
  • Legal/compliance operations
  • Technical implementation
  • Modern technology environments
  • Architecture diagrams
  • Data-flow diagrams
  • Solution designs
  • System integration patterns
  • Security/privacy control mappings
  • Vendor technical documentation
  • Identity and access management
  • Role-based access controls
  • Data classification
  • Encryption
  • Logging and monitoring
  • DLP
  • Retention/deletion
  • Cloud/SaaS governance
  • Secure SDLC
  • AI tool governance
  • AI governance frameworks
  • Responsible AI
  • Generative AI governance
  • Machine learning governance
  • Model risk management
  • Privacy engineering
  • Security architecture
  • AI lifecycle controls
  • NIST AI RMF
  • NIST Privacy Framework
  • ISO 27001
  • SOC 2
  • CIS Controls
  • OWASP
  • Governance tools
  • Privacy tools
  • GRC tools
  • OneTrust
  • ServiceNow GRC
  • Archer
  • Jira
  • Confluence
  • US privacy laws
  • Canadian privacy principles
  • GDPR concepts
  • Vendor risk
  • Cross-border data considerations
  • Client confidentiality requirements

Location

  • Toronto, Canada

Work Type

  • Hybrid

Experience Level

  • Senior
  • 7+ years

Education Level

  • Degree in Information Technology, Computer Science, Engineering, Information Security, Law, Compliance, or a related field; equivalent practical experience will also be considered.

Salary/Compensations

  • $140,000 to $170,000 CAD per year

Benefits

  • Paid time off
  • 13 paid holidays
  • Medical, dental, and vision coverage
  • Life insurance
  • 401(k) plan
  • RRSP benefits with company matching

About the Company

  • Simon-Kucher is a global consultancy with more than 2,200 employees in 30+ countries. Our sole focus is on unlocking better growth that drives measurable revenue and profit for our clients. As a trusted commercial advisor, we combine deep consulting expertise, growth specialization, and technology to scale impact. We optimize every lever of commercial strategy – product, pricing, innovation, marketing, sales, and digital – based on deep insights into what customers value and are willing to pay for. With over 40 years of experience in monetization, we are regarded as the world’s leading commercial growth and pricing specialist.

Equal Opportunity

  • Simon-Kucher is an Equal Employment Opportunity (“EEO”) employer. Our employment decisions are made without regard to race, color, religion, gender, national origin, age, disability, marital status, veteran or military status, or any other legally protected status.
  • We believe in building a culture that embraces belonging, creating an environment in which our people feel valued, are able to be themselves and feel their contribution matters. If we get that right, great things will happen; people will grow faster, innovate, feel valued, and create better outcomes for everyone – our people, our clients and, of course, our business.