Sr Privacy Specialist

Fresenius Medical Care

Waltham (MA)

On-site

USD 88,000 - 147,000

Full time

5 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Medical, dental, vision insurance
401(k) with company match
Paid time off
Parental leave
Bonus potential based on performance

Job summary

Fresenius Medical Care seeks an experienced privacy operations professional to oversee incident response, regulatory coordination, and program improvement. You will analyze data exposures, manage investigations, and ensure alignment with HIPAA, GDPR, and other privacy laws.

The role emphasizes collaboration with Legal, Security, and Compliance teams, and requires driving training, policy review, and incident documentation to maturity the privacy program.

Qualifications

  • 5+ years of experience in Privacy Operations. Preference for leading Privacy Incident Response.
  • Direct interaction with regulators or auditors; data mapping and governance knowledge.
  • Handling data breach or privacy incidents.
  • Strong understanding of HIPAA, GDPR, CCPA, privacy principles, data classification, and NIST/SANS lifecycle.
  • Certifications such as CIPP, CIPM/CIPT, CISSP/CISM or GIAC, CHC/CHPC.
  • Experience in healthcare or other regulated industries.

Responsibilities

  • Monitor and assess alerts, cases, and reports for potential privacy incidents.
  • Lead or support end-to-end investigation of privacy incidents.
  • Evaluate breach thresholds; coordinate with Legal on notifications; support regulatory filings.
  • Participate in incident response war rooms and crisis management efforts.
  • Maintain incident records and metrics; report to leadership and auditors.
  • Enhance incident response playbooks and conduct tabletop exercises.
  • Collaborate on privacy projects with stakeholders as needed.
  • Monitor the Privacy Office inbox and provide timely guidance.
  • Develop and deliver privacy training and awareness initiatives.
  • Draft and review privacy policies and procedures for compliance.

Skills

Privacy Operations
Regulatory Experience
Data Mapping
Incident Response
Healthcare Privacy
NIST/SANS familiarity

Education

Bachelor’s degree in Cybersecurity, Information Security, Law, Privacy, Healthcare or related field

Job description

PRINCIPAL DUTIES AND RESPONSIBILITIES:
  • Monitor and assess alerts, cases, and reports for potential privacy incidents (e.g., unauthorized access, data exfiltration, misdirected communications). Perform initial triage to classify incidents involving Personal Data (PII/PHI).
  • Lead or support end-to-end investigation of privacy incidents. Analyze impacted data elements, systems, and individuals; determine root cause and scope of exposure. Document incident findings in accordance with legal and compliance requirements.
  • Evaluate breach thresholds under regulations (HIPAA, GDPR, state breach laws). Coordinate with Legal on breach notification obligations. Support preparation of regulatory filings and communications to affected individuals.
  • Participate in incident response war rooms and crisis management efforts. Ensure alignment between technical containment and privacy obligations.
  • Maintain detailed incident records and case documentation. Track incident metrics (e.g., time to detect/respond, incident trends). Provide reporting to leadership, regulators, and audit teams.
  • Enhance privacy incident response playbooks and workflows. Conduct tabletop exercises and training sessions. Contribute to privacy program maturity and continuous improvement initiatives.
  • Participate in projects collaborating with stakeholders as needed
  • Monitor the Privacy Office inbox and provide timely guidance and responses to inquiries.
  • Develop and deliver privacy training and awareness initiatives to promote a culture of data protection and compliance.
  • Draft and review privacy policies and procedures to ensure alignment with applicable regulations and organizational standards.
PHYSICAL DEMANDS AND WORKING CONDITIONS:
  • The physical demands and work environmental characteristics described here are representative of those an employee encounters while performing the essential functions of this job. Reasonable accommodation may be made to enable individuals with disabilities to perform the essential functions.
SUPERVISION:
  • Will not be responsible for direct supervision.
EDUCATION:
  • Minimum
  • Bachelor’s degree in Cybersecurity, Information Security, Law, Privacy, Healthcare or related field (or equivalent experience).
EXPERIENCE AND REQUIRED SKILLS:
  • 5+ years of experience in Privacy Operations. Experience building or leading a Privacy Incident Response function preferred.
  • Direct interaction with regulators or auditors, Knowledge of data mapping, data governance, and privacy engineering.
  • Handling data breach or privacy incidents
  • Strong understanding of: Data protection regulations (HIPAA, GDPR, CCPA, etc.), Privacy principles and data classification, Incident response lifecycle (NIST/SANS framework familiarity)
  • Certifications such as:
    • CIPP (US/E, or equivalent)
    • CIPM / CIPT
    • CISSP, CISM, or GIAC (GCIA, GCIH)
    • Certified Healthcare Compliance Professional (CHC) or Certified Healthcare Privacy Compliance (CHPC)
  • Experience in healthcare or other regulated industries.

The rate of pay for this position will depend on the successful candidate’s work location and qualifications, including relevant education, work experience, skills, and competencies.

Annual Rate: $88,000.00 - $147,000.00

Non-Bonus Eligible Positions: include language below.

Benefit Overview: This position offers a comprehensive benefits package including medical, dental, and vision insurance, a 401(k) with company match, paid time off, parental leave.

Bonus Eligible Positions – include language below.

Benefit Overview: This position offers a comprehensive benefits package including medical, dental, and vision insurance, a 401(k) with company match, paid time off, parental leave and potential for performance-based bonuses depending on company and individual performance.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Privacy Analyst
Senior Privacy Analyst

Baylor Genetics • United States

On-site
USD 70,000 - 100,000
Data Privacy Analyst
Data Privacy Analyst

Compunnel Inc. • United States

On-site
USD 90,000 - 130,000
Senior Privacy Analyst
Senior Privacy Analyst

adventhealth • New Mexico

On-site
USD 55,000 - 102,000
Medical, Dental, Vision Insurance
Paid Time Off from Day One
403-B Retirement Plan
+5
Senior Data Privacy & Governance Analyst
Senior Data Privacy & Governance Analyst

Alliant Insurance Services • Greenwood Village (CO)

On-site
USD 120,000 - 180,000
Senior Data Privacy & Governance Analyst
Senior Data Privacy & Governance Analyst

Alliant Insurance Services • Kentucky

On-site
USD 110,000 - 165,000
Senior Data Privacy & Governance Analyst
Senior Data Privacy & Governance Analyst

Alliant Insurance Services • Farmington (CT)

On-site
USD 120,000 - 150,000
Senior Data Privacy & Governance Analyst
Senior Data Privacy & Governance Analyst

Alliant Insurance Services • Columbus (OH)

On-site
USD 110,000 - 170,000
Senior Data Privacy & Governance Analyst
Senior Data Privacy & Governance Analyst

Alliant Insurance Services • Miami (FL)

On-site
USD 120,000 - 165,000
Privacy Specialist Lead
Privacy Specialist Lead

IMAGINEEER LLC • Arlington (VA)

On-site
USD 120,000 - 180,000
401(k) matching
Competitive salary
Health insurance
+1
Senior Data Privacy & Governance Analyst
Senior Data Privacy & Governance Analyst

Alliant Insurance Services • Chicago (IL)

On-site
USD 120,000 - 180,000