Sr Privacy Specialist
Fresenius Medical Care · Waltham, MA · 4 days ago
Legal$88k–$147k/yrFull-time
About the role
Monitor and assess alerts, cases, and reports for potential privacy incidents (e.g., unauthorized access, data exfiltration, misdirected communications). Perform initial triage, lead or support investigations, and ensure compliance with legal and regulatory requirements.
Responsibilities
- Perform initial triage to classify incidents involving Personal Data (PII/PHI).
- Lead or support end-to-end investigation of privacy incidents, analyzing impacted data elements, systems, and individuals to determine root cause and scope of exposure.
- Document incident findings in accordance with legal and compliance requirements.
- Evaluate breach thresholds under regulations (HIPAA, GDPR, state breach laws) and coordinate with Legal on breach notification obligations.
- Support preparation of regulatory filings and communications to affected individuals.
- Participate in incident response war rooms and crisis management efforts, ensuring alignment between technical containment and privacy obligations.
- Maintain detailed incident records and case documentation, tracking incident metrics (e.g., time to detect/respond, incident trends).
- Provide reporting to leadership, regulators, and audit teams.
- Enhance privacy incident response playbooks and workflows, conducting tabletop exercises and training sessions.
- Contribute to privacy program maturity and continuous improvement initiatives.
- Monitor the Privacy Office inbox and provide timely guidance and responses to inquiries.
- Develop and deliver privacy training and awareness initiatives to promote a culture of data protection and compliance.
- Draft and review privacy policies and procedures to ensure alignment with applicable regulations and organizational standards.
Requirements
- Minimum Bachelor’s degree in Cybersecurity, Information Security, Law, Privacy, Healthcare, or related field (or equivalent experience).
- 5+ years of experience in Privacy Operations.
- Experience building or leading a Privacy Incident Response function preferred.
- Direct interaction with regulators or auditors.
- Knowledge of data mapping, data governance, and privacy engineering.
- Experience handling data breach or privacy incidents.
Skills
- Strong understanding of data protection regulations (HIPAA, GDPR, CCPA, etc.).
- Familiarity with privacy principles and data classification.
- Knowledge of incident response lifecycle (NIST/SANS framework).
- Certifications such as CIPP (US/E), CIPM, CIPT, CISSP, CISM, GIAC (GCIA, GCIH), Certified Healthcare Compliance Professional (CHC), or Certified Healthcare Privacy Compliance (CHPC).
- Experience in healthcare or other regulated industries.
Physical Demands and Working Conditions
The physical demands and work environmental characteristics described here are representative of those an employee encounters while performing the essential functions of this job. Reasonable accommodation may be made to enable individuals with disabilities to perform the essential functions.
Pay
Annual rate: $88,000.00 - $147,000.00, depending on the successful candidate’s work location and qualifications, including relevant education, work experience, skills, and competencies.
Benefits
- Comprehensive benefits package including medical, dental, and vision insurance.
- 401(k) with company match.
- Paid time off and parental leave.
- Potential for performance-based bonuses depending on company and individual performance (for bonus-eligible positions).