Job Purpose or Objective(s): Provides strategic leadership and oversight of the organization’s privacy and security program to ensure compliance, manage risk, protect information assets, and promote a culture of privacy, security, and accountability. The position provides strategic guidance to executive leadership and oversees the continuous improvement of privacy and security controls, processes, and services to support organizational objectives and regulatory requirements. You will report directly to the Executive Director of Legal.
Monday-Friday, 8:00am-4:30pm
Primary Tasks:
- Directs and manages the day-to-day operations of the Office of Privacy, ensuring effective administration of privacy policies, procedures, standards, and controls across the organization.
- You will oversee the organization's privacy compliance program and ensures continued adherence to applicable federal, state, Tribal, contractual, and regulatory privacy requirements through ongoing monitoring, assessments, and audits. Delivers metrics and executive reporting related to these activities.
- Leads privacy and information protection risk management activities, including risk assessments, compliance reviews, incident investigations, breach response, corrective action planning, and mitigation efforts.
- Serves as the organization's primary advisor on privacy governance and regulatory compliance matters and provides strategic guidance regarding information security governance, risk, and compliance activities.
- You will direct privacy awareness, education, and training programs to promote workforce understanding of privacy responsibilities and foster a culture of privacy, security, and accountability.
- Oversee privacy rights processes, information disclosure practices, data-sharing activities, contractual privacy requirements, business associate agreements, and third-party privacy controls.
- You will collaborate with Information Security, Compliance, Legal, Human Resources, Health Information Management, and operational leadership to ensure alignment of privacy, cybersecurity, data governance, and regulatory compliance initiatives.
- Develops and monitors departmental goals, objectives, budgets, staffing, performance metrics, and strategic initiatives to ensure effective operation and continuous improvement of the privacy and security program.
- Provides regular reports to executive leadership regarding privacy compliance, risk trends, incidents, regulatory changes, program effectiveness, and recommended improvements.
- Other duties may be assigned.
Requirements:
- Bachelor’s degree in business administration, Information Systems, Healthcare Administration, Legal Studies, Public Administration, Cybersecurity, or related field.
- Five (5) years' experience working in privacy, compliance, information governance, risk management, healthcare operations, information security, or a related field.
- Experience conducting privacy risk assessments, compliance reviews, investigations, breach response activities, and corrective action planning.
- Experience developing, implementing, administering, and maintaining privacy policies, procedures, standards, and governance frameworks.
- Demonstrated knowledge of applicable federal, state, Tribal, and industry privacy laws and regulations.
- Demonstrated ability to collaborate across multiple business units and influence organizational decision-making.
- Experience leading enterprise governance, compliance, risk management, or cross-functional organizational initiatives.
- Strong analytical, investigative, communication, and leadership skills