Position Overview The Director, Security and Privacy leads HCUS’s enterprise security & privacy programs. This role advises executive leadership on the security posture of the organization, including HCUS products, Cloud Services, HCUS business systems, and customer-facing technologies that process or store PHI. The Director requires a strong understanding of organizational, product, cloud, and customer security, as well as the ability to communicate effectively with technical teams, business leaders, regulators, auditors, legal counsel, and customers’ C-suite executives. The Director works closely with HLUS Security and coordinates the activities of groups spanning all HCUS business units, and the Product Security Incident Response Team across HCUS, HLUS, and FTYO. The Director provides guidance on information on security agreements, customer security requirements, regulatory obligations, and risk-management decisions. This role also plans and coordinates company resources to support compliance with HIPAA, SOC 2, applicable state and federal cybersecurity and privacy laws, and other relevant regulatory and contractual frameworks. As the official HCUS HIPAA Privacy Officer and HIPAA Security Officer, the Director oversees the development, implementation, and continuous improvement of policies, procedures, safeguards, incident-response processes, and compliance activities designed to protect PHI and other sensitive information. The role places equal emphasis on executing assigned responsibilities and coordinating with departments across the company, including HLUS and FTYO, to promote a consistent, integrated, risk-based approach to security and privacy. Through cross-functional collaboration, the Director supports the achievement of the organization’s short- and long-term security, privacy, and business objectives. Company Overview At FUJIFILM Healthcare Americas Corporation, we’re on a mission to innovate for a healthier world, and we need passionate, driven people like you to help us get there. Our cutting-edge healthcare solutions span diagnostic imaging, enterprise imaging, endoscopic and surgical imaging, as well as in-vitro diagnostics. But we don’t stop at healthcare; our Non-Destructive Testing (NDT) team harnesses advanced radiography solutions to keep transportation infrastructure, aerospace, and oil and gas assets safe and running smoothly. Ready to innovate, collaborate, and make a difference? Join us and bring your big ideas to life while working in a dynamic, flexible environment that fuels your creativity and drive. Our headquarters is in Lexington, Massachusetts, an inspiring healthcare research hub in a historic town. Fujifilm is globally headquartered in Tokyo with over 70,000 employees across four key business segments of healthcare, electronics, business innovation, and imaging. We are guided and united by our Group Purpose of “giving our world more smiles.” Visit: https://www.fujifilm.com/us/en/about/region/careers Job Description Duties and responsibilities Privacy & Security Leadership Serve as the organization’s designated HIPAA Security Officer and HIPAA Privacy Officer. Develop, implement, maintain, and enforce the company’s information security, privacy, and program. Establish and maintain a governance framework that supports compliance with HIPAA, HITECH, SOC 2, applicable state privacy laws, breach-notification requirements, contractual obligations, and other relevant healthcare and security standards. Advise executive leadership on security, privacy, technology, and operational risks. Present meaningful security, privacy, audit, and risk metrics to executive leadership and other stakeholders. Maintain awareness of changes in healthcare privacy, cybersecurity, and regulatory requirements, translating those changes into actionable organizational improvements. Policies, Procedures, and Program Management Own the development, review, approval, implementation, and periodic revision of HCUS security and privacy policies, standards, procedures, and supporting documentation. Ensure policies address administrative, physical, and technical safeguards appropriate to HCUS’s systems, workforce, operations, and risk profile. Maintain required HIPAA documentation, including risk analyses, risk management plans, policies, training records, incident documentation, access reviews, vendor assessments, and compliance evidence. Lead periodic program assessments and continuous improvement initiatives to measure and improve security and privacy maturity. Risk Management and Security Assessments Lead HCUS-wide security and privacy risk assessments, including HIPAA Security Rule risk analysis and periodic reassessments. Identify, document, prioritize, and track remediation of security, privacy, operational, technical, and third-party risks. Partner with Engineering, Product Management, HLUS Shared IT Services, Legal, and TAC teams to ensure security and privacy are incorporated into system design, software development, deployment, and operational processes. Oversee vulnerability management, penetration testing, security testing, configuration reviews, access control reviews, and remediation tracking. Ensure security controls are proportionate to HCUS’s risk profile and the sensitivity of PHI and other confidential information. SOC 2, Audit, and Regulatory Readiness Lead the HCUS’s SOC 2 program, including scoping, control design, evidence collection, readiness activities, auditor coordination, remediation management, and annual attestation efforts. Coordinate internal and external audits, customer assessments, security questionnaires, and regulatory inquiries. Maintain audit-ready evidence demonstrating operation of security and privacy controls. Monitor compliance with contractual commitments, Business Associate Agreements (BAAs), customer security requirements, and data protection obligations. Partner with internal teams and external advisors to address audit findings, corrective action plans, and compliance gaps. Incident Response and Breach Management Continuously develop, maintain, test, and improve the HCUS’s security incident response and breach-response plans. Lead or coordinate response activities for suspected or confirmed security incidents, privacy incidents, and PHI breaches. Ensure incidents are appropriately investigated, documented, contained, remediated, and reviewed. Coordinate with leadership, legal counsel, technical teams, customers, insurers, and other stakeholders as appropriate during significant incidents. Support breach-risk assessment and notification decision-making in accordance with HIPAA, state law, contractual requirements, and company policy. Conduct post-incident reviews and ensure corrective actions are assigned, tracked, and completed. Technical Security Oversight Partner with technical leadership to oversee the security architecture and safeguards protecting cloud environments, applications, endpoints, networks, identities, integrations, and data. Support implementation and operation of controls such as identity and access management, multi-factor authentication, encryption, logging and monitoring, secure configuration management, vulnerability management, backup and recovery, and business continuity capabilities. Promote secure software development lifecycle practices, including security requirements, code review, dependency management, security testing, threat modeling, and release controls. Ensure appropriate protections for medical imaging data, DICOM workflows, integrations, APIs, interoperability platforms, and connected customer environments. Vendor, Customer, and Third-Party Risk Management Establish and oversee a third-party risk management program for vendors, subcontractors, cloud service providers, and other business partners that may access, process, transmit, or store PHI or other sensitive data. Review security and privacy due diligence materials, including SOC reports, penetration testing summaries, certifications, data protection terms, and business continuity documentation. Ensure appropriate contractual safeguards, including BAAs and security requirements, are in place before third-party access to PHI or sensitive systems is granted. Support customer due diligence requests, security reviews, and discussions with customer information security, privacy, procurement, and compliance teams. Workforce Education and Culture Develop and administer security and privacy awareness training for all HCUS members. Ensure role-based training is provided to employees and contractors with specialized responsibilities or access to PHI, production systems, or sensitive information. Foster a culture of security, privacy, accountability, and timely incident reporting across HCUS. Qualifications Bachelor’s degree in Information Security, Cybersecurity, Information Technology, Healthcare Administration, Privacy, Risk Management, or a related field; equivalent experience may be considered. 7+ years of progressive experience in information security, privacy, compliance, risk management, healthcare technology, or related discipline. 3+ years of experience leading or managing security, privacy, compliance, or governance programs. Demonstrated experience with HIPAA Privacy Rule, HIPAA Security Rule, HITECH Act requirements, and healthcare breach response. Experience leading SOC 2 readiness, audits, control implementation, and evidence management. Experience conducting risk assessments, developing risk treatment plans, and managing remediation activities. Experience developing and maintaining incident response, business continuity, and disaster recovery processes. Strong knowledge of common security frameworks and standards, such as NIST Cybersecurity Framework, NIST SP 800-53, NIST SP 800-66, CIS Controls, ISO 27001, and SOC 2 Trust Services Criteria. Familiarity with cloud security, SaaS application security, identity and access management, encryption, logging/monitoring, secure software development practices, and vendor risk management. Ability to communicate complex security, privacy, and regulatory concepts effectively to technical teams, customers, executives, and non-technical workforce members. Strong judgment, organizational skills, attention to detail, and ability to manage sensitive and confidential matters. Preferred requirements Experience in a healthcare SaaS, medical imaging, health IT, clinical informatics, PACS, RIS, DICOM, interoperability, or medical device-adjacent environment Certifications such as CISSP, CISM, CISA, CRISC, HCISPP, CHPC, CHC, CHSP, CIPM, CIPP/US, or equivalent. Experience with HITRUST, ISO 27001, PCI DSS, FDA cybersecurity considerations, or state healthcare privacy regulations. Experience managing customer security assessments and enterprise healthcare customer requirements. Experience with cloud environments such as AWS, Microsoft Azure, or Google Cloud Platform. Familiarity with security operations, SIEM/logging platforms, endpoint protection, vulnerability scanning, and cloud security posture management tools. Physical requirements The position requires the ability to perform the following physical demands and/or have the listed capabilities: The ability to sit up 75-100% of applicable work The ability to use your hands and fingers to feel and manipulate items, including keyboards, up to 100% of applicable work time. The ability to stand, talk, and hear for 75% of applicable work The ability to lift and carry up to ten pounds up to 20% of applicable work Close Vision: The ability to see clearly at twenty inches or less. Travel Occasional (up to 25%) travel may be required based on business Salary and Benefits $134,406.00 to $186,696.00 Medical, Dental, Vision Life Insurance 401K Paid Time Off * In the event that COVID-19 vaccine mandates issued by the federal government, or by state or local government become effective and enforceable, the Company will require that the successful candidate hired for positions covered under relevant government vaccine mandate(s) be fully vaccinated against COVID-19, absent being granted an accommodation due to medical or sincerely held religious belief or other legally required exemption. Applicants to positions where vendor credentialing or other similar requirements exist to enter facilities will be required to comply with the credentialing requirements of the facilities, including complying with vaccine requirements. For all positions, the Company encourages vaccination against COVID-19 and requires that the successful candidate hired be willing to test for the COVID-19 virus periodically and wear a face covering indoors as required, absent being granted an accommodation due to medical or sincerely held religious belief or other legally required exemption. EEO Information Fujifilm is committed to providing equal opportunities in hiring, promotion and advancement, compensation, benefits, and training regardless of nationality, age, gender, sexual orientation or gender identity, race, ethnicity, religion, political creed, ideology, national, or social origin, disability, veteran status, etc. ADA Information If you require reasonable accommodation in completing this application, interviewing, completing any pre-employment testing, or otherwise participating in the employee selection process, please direct your inquiries to our HR Department ([email protected] or (330) 425-1313).
Support Solutions Engineer (L5) - Security, Privacy and Assurance
Netflix
Support Solutions Engineer (L5) - Security, Privacy and Assurance
Netflix
Software Engineer II – AI Engineer (w/ skills in AI Data Privacy, Security & Governance Specialty)
Roberthalf
Head of Security & Privacy Engineering
interface.ai
Data Privacy & Security Analyst
Health Care District of Palm Beach County
Corporate Counsel (Product, Privacy, Cybersecurity, AI and Technology Compliance)
Nabancard