JOB DESCRIPTION
The Director, Privacy Operations and Governance will have a leadership role in managing Quest Diagnostics’ privacy operations, governance and risk mitigation activities, domestically and internationally. The role will collaborate closely with a broad range of business partners as well as members of the Privacy Office, Compliance, and IT, to effectively manage privacy risk and ensure compliance with applicable privacy laws, U.S. and international. This is a hands-on role with responsibilities including the performance and maintenance of privacy impact assessments, data protection impact assessments, data mapping activities, and responding to client and other third party due-diligence requests.
The ideal candidate will have broad working knowledge of U.S. and international privacy laws, regulations, including HIPAA, HITECH, state privacy laws, and GDPR, as well as international privacy and security standards, including NIST and ISO frameworks. The individual will have demonstrated experience with a privacy program in a multinational corporate setting, preferably in the healthcare or life sciences sector. The position reports to the Executive Director, Privacy Officer.
This is a remote-based position.
JOB RESPONSIBILITIES
The Director, Privacy Operations and Governance will assist in leading Quest Diagnostics’ privacy initiatives and the day-to-day operations of the Privacy Office. Responsibilities include:
- Manage privacy risk in compliance with privacy standards, best practices and applicable law, including HIPAA, US State privacy laws and GDPR.
- Manage and perform privacy impact assessments, data protection impact assessments, transfer impact assessments as required by applicable law.
- Provide governance and operational support relating to data processing activities in compliance with relevant privacy standards, best practices and applicable laws, including but not limited to GDPR Article 30 (Record of Processing Activity).
- Support various business functions in responding to client/third party due-diligence and data privacy questionnaires.
- Analyze metrics and identify trends to help drive continuous improvement in controls.
- Mature processes and serve as privacy subject matter expert on cross-functional governance committees.
- Assisting the Privacy Office team in a variety of projects and initiatives on an as-needed basis.
JOB QUALIFICATIONS
Required Work Experience:
- Strong understanding of privacy best practices in healthcare, including experience advising on best practices and compliance with privacy and data protection regulations, as well as providing guidance on data collection and use, privacy disclosures and transparency, and related issues.
- Experience with design, implementation and maintenance of privacy compliance policies, procedures and programs for a global healthcare company.
- Significant experience conducting privacy impact assessments and implementing scalable processes for a global organization.
- Experience building and maintaining data processing registries and associated data mapping.
- Experience working with privacy management software and automated platforms.
- Experience with privacy governance and document management frameworks.
- Experience with cross-functional risk management frameworks.
Preferred Work Experience:
Knowledge:
- MS Office and other business applications; privacy management software.
Skills:
- Demonstrated ability to translate regulatory requirements into practical, compliant and actionable elements while supporting business strategy.
- Strong problem-solving skills, including the ability to make decisions in the face of ambiguous circumstances and find solutions to complex problems.
- Strong leadership skills.
- Strong organizational skills.
Education
- Bachelor’s Degree B.S. or equivalent experience required (Required)
- Doctorate Degree J.D. a plus (Preferred)
Work Requirements