Privacy and Compliance Specialist
Own day-to-day privacy operations and cross-functional compliance initiatives for a health technology company. The role requires 4–7 years of privacy or compliance experience, knowledge of HIPAA and state privacy laws, and expertise in assessments, incident response, and data subject requests.
About the job
Responsibilities
- Manage and maintain the privacy compliance program, including policies, procedures, and documentation.
- Conduct and coordinate privacy impact assessments (PIAs/DPIAs) and data protection assessments for products, features, and vendors.
- Maintain records of processing activities, data inventories, and data flow maps.
- Monitor and operationalize HIPAA, CCPA/CPRA, and other applicable state privacy requirements.
- Implement and support Privacy by Design.
- Support data subject rights requests and privacy incident response workflows.
- Serve as a primary contact for privacy and data inquiries from customers, prospects, and partners.
- Draft and maintain responses to privacy questionnaires, RFPs, security assessments, and due diligence requests.
- Support review and negotiation of Data Processing Agreements and Business Associate Agreements.
- Drive privacy and compliance initiatives from planning through execution, managing timelines, stakeholders, and deliverables.
- Develop and deliver privacy training and awareness programs.
- Build and maintain privacy metrics, dashboards, and leadership reporting.
- Identify opportunities to improve and automate privacy processes and workflows.
Requirements
- 4–7 years of experience in privacy, compliance, data protection, or a related field.
- Working knowledge of HIPAA, CCPA/CPRA, state consumer privacy laws, and health data regulations.
- Demonstrated project management skills and ability to manage multiple workstreams.
- Experience with privacy impact assessments, incident response, or DSAR workflows.
- Strong written and verbal communication skills, with the ability to translate complex privacy requirements into practical guidance.
- Proactive use of AI tools to improve productivity and efficiency.
Compensation
- $100,000–$120,000 annual compensation.
- Benefits are available through the company’s careers program.
Skills
HIPAA, Ccpa/Cpra, Privacy Impact Assessments, Data Protection, Data Subject Rights Requests, Incident Response, Data Processing Agreements, Business Associate Agreements, Records Of Processing Activities, Privacy By Design, Project Management, AI Tools
Similar jobs
Legal jobsSupports the compliance program for a retail forex brokerage by monitoring CFTC and NFA requirements, advising on products, overseeing AML/KYC processes, and coordinating regulatory examinations. Requires a bachelor’s degree and at least five years of relevant financial-services compliance experience.
Leads a high-volume California court filing team, overseeing quality, SLAs, coaching, audits, escalations, hiring, and process improvement. The role requires deep county-level filing expertise, extensive leadership experience, and hands-on familiarity with major eFiling platforms.
Manages day-to-day legal operations across intake, contract lifecycle systems, signatures, documentation, entity maintenance, compliance support, and vendor coordination. The role requires 4–8 years of operational experience, strong process-building skills, and familiarity with legal technology such as DocuSign, Ironclad, and Jira.
Owns compliance monitoring, policy administration, training, regulatory reporting, and remediation processes for a regulated prediction-market exchange and clearinghouse. The role requires 4–7 years of relevant compliance or regulatory operations experience, with CFTC, DCM, or DCO expertise preferred.
Own Legal Tracker and the operational systems supporting an in-house legal function, including matter management, e-billing, invoice compliance, accruals, and outside counsel spend control. Requires 5+ years of legal operations or legal finance experience and strong Legal Tracker expertise.