Position Summary:
The Privacy and Security Manager helps mature SIHB's privacy, governance, risk, and information security practices across the organization. This role supports the protection of PHI, PII, and sensitive organizational information while helping teams translate regulatory and security requirements into practical, sustainable controls.
This position works closely with IT leadership and partners cross-functionally with HIM, Clinical Operations, Data Analytics, HR, Finance, and other departments to embed privacy and security requirements into systems, workflows, vendor relationships, and day-to-day operations.
Organizational Structure/Reporting Relationships:
This position reports to the IT Director and has management responsibility for direct reports.
Job Responsibilities
• Lead and support privacy, information security, compliance, and risk management activities.
• Supervise and develop staff supporting privacy, security, audits, investigations, and incident response.
• Draft, maintain, and operationalize privacy and information security policies, standards, and procedures.
• Support HIPAA privacy and security compliance, including investigations, documentation, breach response, and corrective actions.
• Coordinate risk assessments, audits, remediation plans, and executive-level reporting.
• Partner with IT and department leaders to embed privacy and security requirements into systems, workflows, and organizational changes.
• Provide guidance on appropriate access, data handling, PHI/PII protection, and security risk considerations.
• Support vendor and third-party risk reviews involving access to sensitive data, PHI, or PII.
Requirements
Qualifications & Skills
• Experience in privacy, compliance, governance, risk management, information security, healthcare operations, audit, regulatory compliance, or a related field.
• Experience developing or maintaining policies, procedures, standards, controls, audits, investigations, risk assessments, or other governance-related activities.
• Ability to assess risk, identify gaps, and recommend practical, sustainable solutions.
• Strong analytical thinking, attention to detail, and sound judgment when evaluating complex issues and organizational risks.
• Ability to learn and apply new concepts in privacy, compliance, governance, risk management, and information security.
• Ability to translate regulatory, technical, and operational requirements into clear and actionable guidance.
• Strong written communication, documentation, organizational, and follow-through skills.
• Experience leading projects, initiatives, teams, or staff, with the ability to support employee growth, accountability, and professional development.
• Ability to manage multiple priorities while maintaining accountability and professionalism.
• Healthcare, nonprofit, FQHC, Tribal, or other highly regulated environment experience preferred.
Education
• Bachelor's degree in Healthcare Administration, Compliance, Public Health, Information Systems, Information Technology, or a related field
• (Equivalent experience may substitute for formal education).
• Professional certifications such as CHPS, CHC, HCISPP, CISM, or similar are preferred but not required.
Other Job Requirements
• Transportation: Reliable transportation and the ability to travel to multiple locations as needed.
• Schedule Flexibility: Willingness to work occasional evenings or weekends in support of incident response or organizational needs.
• Background Check: Successful completion of a background check.
• Vaccination: Must comply with organizational vaccination requirements.
Work Environment
• Schedule: 4x10 work schedule (Monday through Friday)
• Shift: 7:00 AM to 6:00 PM daily (with one day off), occasional after-hours or weekend work.
• Onsite Only - no remote work option