Client is mission driven — everything we do is grounded in our higher purpose of caring for seniors. Our decision making is informed by our mission “to create communities where each person feels loved, valued, supported and able to live life to the fullest.” Each business unit and each team member have a unique ability and responsibility to impact the lives of seniors, and we take that responsibility very seriously. We also embody an entrepreneurial spirit that has fueled our growth and continues to drive us forward.
Position Summary
The Director of IT and Privacy leads the client's information technology function and serves as the organization's data privacy and security compliance authority. This role is responsible for the strategic direction, operation, and security of enterprise IT systems, along with the design and oversight of privacy and regulatory compliance programs governing the collection, use, and protection of sensitive data. Given the regulated nature of the business, the Director ensures the organization's technology infrastructure and data handling practices meet applicable requirements under frameworks such as HIPAA, the Sarbanes-Oxley Act (SOX), and other healthcare industry regulations, while enabling the business through reliable, secure, and scalable technology. The Director is ultimately responsible for ensuring team members have reliable, secure, and practical technology that supports business purposes.
Why Work For Cedarhurst
- At Client, our core values guide how we work together and how we care for those we serve. We expect every team member to be passionate, trustworthy, empathetic, positive, respectful, and approachable. Being part of Client means making a meaningful difference every day.
- We believe our team is our greatest strength. That’s why we invest in comprehensive training, as well as opportunities for both personal and professional growth. We’re committed to promoting from within and supporting team members who want to build their careers with us.
- Client offers a competitive benefits package, including medical insurance, life insurance, long-term disability coverage, and a 401(k) plan with company match (after one year of service) for eligible employees.
- Additional Benefits Include:
- Work that makes a difference in the lives of our residents and community
- An on-site gym with brand-new equipment
- A personal trainer offering daily group classes, stretching sessions, and one-on-one training
- Catered lunches twice a week, prepared by our on-site chef
- Monthly team events and more
- Develop and execute the organization's IT strategy, roadmap, and budget in alignment with business goals and growth plans.
- Lead, mentor, and develop the IT team, including infrastructure, help desk, and applications, and manage relationships with outsourced/managed service providers.
- Support the Help Desk Manager in ensuring high-quality, responsive, and accountable support experience for all employees. Monitor help desk performance to identify root causes and improve service.
- Lead enterprise technology rollouts from planning through implementation, adoption, and post-launch optimization. Collaborate with all departments to ensure launches are operationally sound.
- Own the enterprise data privacy program, including policies, procedures, and controls governing the collection, storage, use, and disposal of personal, financial, and protected health information.
- Ensure ongoing compliance with applicable regulatory frameworks, including HIPAA, SOX IT general controls, state and federal privacy laws, as applicable to the business.
- Design, implement, and continuously improve the organization's cybersecurity program, including network security, endpoint protection, identity and access management, and data loss prevention. Mitigate harm from known impermissible uses and disclosures.
- Serve as the organization's primary point of contact for data privacy matters, including responding to regulator inquiries, data subject requests, and privacy impact assessments.
- Lead incident response planning and execution for security incidents and data breaches, including coordination with legal counsel and executive leadership as required.
- Partner with Legal and Finance to support SOX IT controls testing, audit requests, and remediation of findings.
- Manage vendor risk assessments and third-party due diligence for technology vendors handling sensitive or regulated data, including contract review for data protection and privacy terms for IT, website and software. Coordinates and ensures privacy compliance during implementation of all new technologies.
- Oversee enterprise IT infrastructure, including networks, servers, cloud environments, disaster recovery, and business continuity planning.
- Develop, maintain, and enforce IT and privacy policies, standards, and employee training programs, including annual security and privacy awareness training.
- Oversee the access request process, amendment requests, accounting of disclosures, and restrictions
- Evaluate and recommend new technologies, tools, and processes that improve operational efficiency, data governance, and regulatory compliance.
- Prepare and present IT and privacy program updates, risk assessments, and compliance metrics to executive leadership as needed.
- Stay informed on technology trends in senior living, healthcare, hospitality, smart-home technology, artificial intelligence, automation, and resident and patient experience.
- Other duties as assigned
Qualifications, Education And/or Experience
To perform this job successfully, an individual must be able to perform each essential duty satisfactorily. The requirements listed below are representative of the knowledge, skills, and abilities required.
- Bachelor’s degree in information technology, Computer Science, Cybersecurity, or a related field; equivalent experience considered in lieu of degree. A master’s degree is preferred.
- Eight (8) to ten (10)+ years of progressive experience in information technology, with at least four (4) years in a leadership role overseeing both IT operations and data privacy/security compliance.
- Experience leading a help desk or end-user support function is required.
- Demonstrated experience working within a regulated industry (healthcare) and direct familiarity with HIPAA and/or SOX requirements.
- Strong working knowledge of privacy frameworks and regulations, including state and federal data privacy laws.
- Experience leading incident response, vendor risk management, and audit/regulatory examination processes.
- Proven ability to manage teams, budgets, and cross-functional projects, and to communicate technical and regulatory concepts to non-technical executives and staff.
- Experience with the senior living, construction, home health, hospice, and/or pharmacy industries is a plus.