Fresenius Medical Care

Sr Privacy Specialist

Fresenius Medical Care$88K — $147K *
Healthcare
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in Cybersecurity, Information Security, Law, Privacy, Healthcare or related field (or equivalent experience).
  • 5+ years of experience in Privacy Operations; leadership experience in a Privacy Incident Response function is preferred.
  • Direct experience interacting with regulators or auditors.
  • Strong knowledge of data protection regulations (HIPAA, GDPR, CCPA, etc.) and privacy principles.
  • Relevant certifications such as CIPP (US/E), CIPM, CIPT, CISSP, or CISM.

Responsibilities

  • Monitor and assess alerts and cases for potential privacy incidents; perform initial triage of incidents involving Personal Data.
  • Lead investigations into privacy incidents, analyzing impacted data and documenting findings per legal requirements.
  • Evaluate breach thresholds and coordinate with Legal on breach notifications and regulatory filings.
  • Participate in incident response efforts to align technical containment with privacy obligations.
  • Maintain incident records and track metrics for reporting to leadership and regulators.
  • Enhance incident response playbooks and conduct training sessions to improve privacy program maturity.
  • Develop and deliver privacy training to promote a culture of data protection.

Benefits

  • Comprehensive benefits package including medical, dental, and vision insurance.
  • 401(k) plan with company match.
  • Paid time off and parental leave available.
  • Potential for performance-based bonuses depending on company and individual performance.
Full Job Description
PRINCIPAL DUTIES AND RESPONSIBILITIES:
• Monitor and assess alerts, cases, and reports for potential privacy incidents (e.g., unauthorized access, data exfiltration, misdirected communications). Perform initial triage to classify incidents involving Personal Data (PII/PHI).
• Lead or support end-to-end investigation of privacy incidents. Analyze impacted data elements, systems, and individuals; determine root cause and scope of exposure. Document incident findings in accordance with legal and compliance requirements.
• Evaluate breach thresholds under regulations (HIPAA, GDPR, state breach laws). Coordinate with Legal on breach notification obligations. Support preparation of regulatory filings and communications to affected individuals.
• Participate in incident response war rooms and crisis management efforts. Ensure alignment between technical containment and privacy obligations.
• Maintain detailed incident records and case documentation. Track incident metrics (e.g., time to detect/respond, incident trends). Provide reporting to leadership, regulators, and audit teams.
• Enhance privacy incident response playbooks and workflows. Conduct tabletop exercises and training sessions. Contribute to privacy program maturity and continuous improvement initiatives.
• Participate in projects collaborating with stakeholders as needed
• Monitor the Privacy Office inbox and provide timely guidance and responses to inquiries.
• Develop and deliver privacy training and awareness initiatives to promote a culture of data protection and compliance.
• Draft and review privacy policies and procedures to ensure alignment with applicable regulations and organizational standards.

PHYSICAL DEMANDS AND WORKING CONDITIONS:
• The physical demands and work environmental characteristics described here are representative of those an employee encounters while performing the essential functions of this job. Reasonable accommodation may be made to enable individuals with disabilities to perform the essential functions.

SUPERVISION:
• Will not be responsible for direct supervision.

EDUCATION:

Minimum
• Bachelor's degree in Cybersecurity, Information Security, Law, Privacy, Healthcare or related field (or equivalent experience).

EXPERIENCE AND REQUIRED SKILLS:
• 5+ years of experience in Privacy Operations. Experience building or leading a Privacy Incident Response function preferred.
• Direct interaction with regulators or auditors, Knowledge of data mapping, data governance, and privacy engineering.
• Handling data breach or privacy incidents
• Strong understanding of: Data protection regulations (HIPAA, GDPR, CCPA, etc.), Privacy principles and data classification, Incident response lifecycle (NIST/SANS framework familiarity)
• Certifications such as:

o CIPP (US/E, or equivalent)

o CIPM / CIPT

o CISSP, CISM, or GIAC (GCIA, GCIH)

o Certified Healthcare Compliance Professional (CHC) or Certified Healthcare Privacy Compliance (CHPC)
• Experience in healthcare or other regulated industries.

The rate of pay for this position will depend on the successful candidate's work location and qualifications, including relevant education, work experience, skills, and competencies.

Annual Rate: $88,000.00 - $147,000.00

Non-Bonus Eligible Positions: include language below.
Benefit Overview: This position offers a comprehensive benefits package including medical, dental, and vision insurance, a 401(k) with company match, paid time off, parental leave.

Bonus Eligible Positions - include language below.
Benefit Overview: This position offers a comprehensive benefits package including medical, dental, and vision insurance, a 401(k) with company match, paid time off, parental leave and potential for performance-based bonuses depending on company and individual performance.

About Fresenius Medical Care

Fresenius Medical Care is a German company specializing in the production of medical supplies, primarily to facilitate or aid renal dialysis. The company is a leading provider of products and services for people with chronic kidney failure. Fresenius Medical Care operates in more than 120 countries and has over 120,000 employees. The company's products and services are used to treat approximately 3.4 million patients worldwide. The company is committed to improving the quality of life of patients with kidney disease and to providing innovative products and services that meet the needs of patients and healthcare professionals.
Learn more about Fresenius Medical Care
Size
122,635 employees
Market Cap
$9.2 billion
Industry
Net Income
$1.1 billion
Founded
1996
Revenue
$17.8 billion
NASDAQ

Similar Jobs

More Jobs at Fresenius Medical Care

More Healthcare Jobs

Find similar Sr Privacy Specialist jobs: