Director, Security & Privacy (HIPAA Privacy & Security, HITECH Act requirements)
$134.41k - $186.7kFull-time
FUJIFILM Biotechnologies
Position Overview The Director, Security and Privacy leads HCUS's enterprise security & privacy programs. This role advises executive leadership on the security posture of the organization, including HCUS products, Cloud Services, HCUS business systems, and customer-facing technologies that process or store PHI. The Director requires a strong understanding of organizational, product, cloud, and customer security, as well as the ability to communicate effectively with technical teams, business leaders, regulators, auditors, legal counsel, and customers' C-suite executives. The Director works closely with HLUS Security and coordinates the activities of groups spanning all HCUS business units, and the Product Security Incident Response Team across HCUS, HLUS, and FTYO. The Director provides guidance on information on security agreements, customer security requirements, regulatory obligations, and risk-management decisions. This role also plans and coordinates company resources to support compliance with HIPAA, SOC 2, applicable state and federal cybersecurity and privacy laws, and other relevant regulatory and contractual frameworks. As the official HCUS HIPAA Privacy Officer and HIPAA Security Officer, the Director oversees the development, implementation, and continuous improvement of policies, procedures, safeguards, incident-response processes, and compliance activities designed to protect PHI and other sensitive information. The role places equal emphasis on executing assigned responsibilities and coordinating with departments across the company, including HLUS and FTYO, to promote a consistent, integrated, risk-based approach to security and privacy. Through cross-functional collaboration, the Director supports the achievement of the organization's short- and long-term security, privacy, and business objectives. Company Overview At FUJIFILM Healthcare Americas Corporation, we're on a mission to innovate for a healthier world, and we need passionate, driven people like you to help us get there. Our cutting-edge healthcare solutions span diagnostic imaging, enterprise imaging, endoscopic and surgical imaging, as well as in-vitro diagnostics. But we don't stop at healthcare; our Non-Destructive Testing (NDT) team harnesses advanced radiography solutions to keep transportation infrastructure, aerospace, and oil and gas assets safe and running smoothly. Ready to innovate, collaborate, and make a difference? Join us and bring your big ideas to life while working in a dynamic, flexible environment that fuels your creativity and drive. Our headquarters is in Lexington, Massachusetts, an inspiring healthcare research hub in a historic town.
Fujifilm is globally headquartered in Tokyo with over 70,000 employees across four key business segments of healthcare, electronics, business innovation, and imaging. We are guided and united by our Group Purpose of "giving our world more smiles." Visit: Job Description Duties and responsibilities Privacy & Security Leadership
Applicants to positions where vendor credentialing or other similar requirements exist to enter facilities will be required to comply with the credentialing requirements of the facilities, including complying with vaccine requirements.
For all positions, the Company encourages vaccination against COVID-19 and requires that the successful candidate hired be willing to test for the COVID-19 virus periodically and wear a face covering indoors as required, absent being granted an accommodation due to medical or sincerely held religious belief or other legally required exemption. EEO Information Fujifilm is committed to providing equal opportunities in hiring, promotion and advancement, compensation, benefits, and training regardless of nationality, age, gender, sexual orientation or gender identity, race, ethnicity, religion, political creed, ideology, national, or social origin, disability, veteran status, etc. ADA Information If you require reasonable accommodation in completing this application, interviewing, completing any pre-employment testing, or otherwise participating in the employee selection process, please direct your inquiries to our HR Department (View email address on hirelifescience.com or View phone number on hirelifescience.com).
Fujifilm is globally headquartered in Tokyo with over 70,000 employees across four key business segments of healthcare, electronics, business innovation, and imaging. We are guided and united by our Group Purpose of "giving our world more smiles." Visit: Job Description Duties and responsibilities Privacy & Security Leadership
- Serve as the organization's designated HIPAA Security Officer and HIPAA Privacy Officer.
- Develop, implement, maintain, and enforce the company's information security, privacy, and program.
- Establish and maintain a governance framework that supports compliance with HIPAA, HITECH, SOC 2, applicable state privacy laws, breach-notification requirements, contractual obligations, and other relevant healthcare and security standards.
- Advise executive leadership on security, privacy, technology, and operational risks.
- Present meaningful security, privacy, audit, and risk metrics to executive leadership and other stakeholders.
- Maintain awareness of changes in healthcare privacy, cybersecurity, and regulatory requirements, translating those changes into actionable organizational improvements.
- Own the development, review, approval, implementation, and periodic revision of HCUS security and privacy policies, standards, procedures, and supporting documentation.
- Ensure policies address administrative, physical, and technical safeguards appropriate to HCUS's systems, workforce, operations, and risk profile.
- Maintain required HIPAA documentation, including risk analyses, risk management plans, policies, training records, incident documentation, access reviews, vendor assessments, and compliance evidence.
- Lead periodic program assessments and continuous improvement initiatives to measure and improve security and privacy maturity.
- Lead HCUS-wide security and privacy risk assessments, including HIPAA Security Rule risk analysis and periodic reassessments.
- Identify, document, prioritize, and track remediation of security, privacy, operational, technical, and third-party risks.
- Partner with Engineering, Product Management, HLUS Shared IT Services, Legal, and TAC teams to ensure security and privacy are incorporated into system design, software development, deployment, and operational processes.
- Oversee vulnerability management, penetration testing, security testing, configuration reviews, access control reviews, and remediation tracking.
- Ensure security controls are proportionate to HCUS's risk profile and the sensitivity of PHI and other confidential information.
- Lead the HCUS's SOC 2 program, including scoping, control design, evidence collection, readiness activities, auditor coordination, remediation management, and annual attestation efforts.
- Coordinate internal and external audits, customer assessments, security questionnaires, and regulatory inquiries.
- Maintain audit-ready evidence demonstrating operation of security and privacy controls.
- Monitor compliance with contractual commitments, Business Associate Agreements (BAAs), customer security requirements, and data protection obligations.
- Partner with internal teams and external advisors to address audit findings, corrective action plans, and compliance gaps.
- Continuously develop, maintain, test, and improve the HCUS's security incident response and breach-response plans.
- Lead or coordinate response activities for suspected or confirmed security incidents, privacy incidents, and PHI breaches.
- Ensure incidents are appropriately investigated, documented, contained, remediated, and reviewed.
- Coordinate with leadership, legal counsel, technical teams, customers, insurers, and other stakeholders as appropriate during significant incidents.
- Support breach-risk assessment and notification decision-making in accordance with HIPAA, state law, contractual requirements, and company policy.
- Conduct post-incident reviews and ensure corrective actions are assigned, tracked, and completed.
- Partner with technical leadership to oversee the security architecture and safeguards protecting cloud environments, applications, endpoints, networks, identities, integrations, and data.
- Support implementation and operation of controls such as identity and access management, multi-factor authentication, encryption, logging and monitoring, secure configuration management, vulnerability management, backup and recovery, and business continuity capabilities.
- Promote secure software development lifecycle practices, including security requirements, code review, dependency management, security testing, threat modeling, and release controls.
- Ensure appropriate protections for medical imaging data, DICOM workflows, integrations, APIs, interoperability platforms, and connected customer environments.
- Establish and oversee a third-party risk management program for vendors, subcontractors, cloud service providers, and other business partners that may access, process, transmit, or store PHI or other sensitive data.
- Review security and privacy due diligence materials, including SOC reports, penetration testing summaries, certifications, data protection terms, and business continuity documentation.
- Ensure appropriate contractual safeguards, including BAAs and security requirements, are in place before third-party access to PHI or sensitive systems is granted.
- Support customer due diligence requests, security reviews, and discussions with customer information security, privacy, procurement, and compliance teams.
- Develop and administer security and privacy awareness training for all HCUS members.
- Ensure role-based training is provided to employees and contractors with specialized responsibilities or access to PHI, production systems, or sensitive information.
- Foster a culture of security, privacy, accountability, and timely incident reporting across HCUS.
- Comply with all applicable U.S. Food and Drug Administration (U.S. FDA) medical device regulatory requirements, applicable ISO 13485 standard requirements and all other applicable laws, regulations and standards.
- Bachelor's degree in Information Security, Cybersecurity, Information Technology, Healthcare Administration, Privacy, Risk Management, or a related field; equivalent experience may be considered.
- 7+ years of progressive experience in information security, privacy, compliance, risk management, healthcare technology, or related discipline.
- 3+ years of experience leading or managing security, privacy, compliance, or governance programs.
- Demonstrated experience with HIPAA Privacy Rule, HIPAA Security Rule, HITECH Act requirements, and healthcare breach response.
- Experience leading SOC 2 readiness, audits, control implementation, and evidence management.
- Experience conducting risk assessments, developing risk treatment plans, and managing remediation activities.
- Experience developing and maintaining incident response, business continuity, and disaster recovery processes.
- Strong knowledge of common security frameworks and standards, such as NIST Cybersecurity Framework, NIST SP 800-53, NIST SP 800-66, CIS Controls, ISO 27001, and SOC 2 Trust Services Criteria.
- Familiarity with cloud security, SaaS application security, identity and access management, encryption, logging/monitoring, secure software development practices, and vendor risk management.
- Ability to communicate complex security, privacy, and regulatory concepts effectively to technical teams, customers, executives, and non-technical workforce members.
- Strong judgment, organizational skills, attention to detail, and ability to manage sensitive and confidential matters.
- Experience in a healthcare SaaS, medical imaging, health IT, clinical informatics, PACS, RIS, DICOM, interoperability, or medical device-adjacent environment
- Certifications such as CISSP, CISM, CISA, CRISC, HCISPP, CHPC, CHC, CHSP, CIPM, CIPP/US, or equivalent.
- Experience with HITRUST, ISO 27001, PCI DSS, FDA cybersecurity considerations, or state healthcare privacy regulations.
- Experience managing customer security assessments and enterprise healthcare customer requirements.
- Experience with cloud environments such as AWS, Microsoft Azure, or Google Cloud Platform.
- Familiarity with security operations, SIEM/logging platforms, endpoint protection, vulnerability scanning, and cloud security posture management tools.
- The ability to sit up 75-100% of applicable work
- The ability to use your hands and fingers to feel and manipulate items, including keyboards, up to 100% of applicable work time.
- The ability to stand, talk, and hear for 75% of applicable work
- The ability to lift and carry up to ten pounds up to 20% of applicable work
- Close Vision: The ability to see clearly at twenty inches or less.
- Occasional (up to 25%) travel may be required based on business
- $134,406.00 to $186,696.00
- Medical, Dental, Vision
- Life Insurance
- 401K
- Paid Time Off
Applicants to positions where vendor credentialing or other similar requirements exist to enter facilities will be required to comply with the credentialing requirements of the facilities, including complying with vaccine requirements.
For all positions, the Company encourages vaccination against COVID-19 and requires that the successful candidate hired be willing to test for the COVID-19 virus periodically and wear a face covering indoors as required, absent being granted an accommodation due to medical or sincerely held religious belief or other legally required exemption. EEO Information Fujifilm is committed to providing equal opportunities in hiring, promotion and advancement, compensation, benefits, and training regardless of nationality, age, gender, sexual orientation or gender identity, race, ethnicity, religion, political creed, ideology, national, or social origin, disability, veteran status, etc. ADA Information If you require reasonable accommodation in completing this application, interviewing, completing any pre-employment testing, or otherwise participating in the employee selection process, please direct your inquiries to our HR Department (View email address on hirelifescience.com or View phone number on hirelifescience.com).
Vacancy posted 9 days ago
Similar jobs that could be interesting for youBased on the Director, Security & Privacy (HIPAA Privacy & Security, HITECH Act requirements) in Remote vacancy
$134.41k - $186.7k
...Position Overview The Director, Security and Privacy leads HCUS's... ...PHI. The Director requires a strong understanding... ...support compliance with HIPAA, SOC 2, applicable state... ...with HIPAA, HITECH, SOC 2, applicable state... ...Security Rule, HITECH Act requirements, and healthcare...SuggestedFull timeTemporary workFor contractorsFor subcontractorLocal areaFlexible hours$148k - $274.2k
...Position Purpose Lead the Privacy & Security Enterprise Engagement Officers... ...so they know all controls, requirements, relevant regulations, and participate... ...and laws/regulations (e.g., HIPAA, CMS/MARS‑E/ARC‑AMPE, NCQA,... ...the California Fair Chance Act. #J-18808-Ljbffr Centene...SuggestedFull timeContract workPart timeWork at officeRemote workFlexible hours$120k - $160k
Senior Legal Operations & Privacy Specialist Department:... ...Bethesda, MD will be required. To ensure we remain compliant... ...e.g., GDPR, CCPA/CPRA, HIPAA, and emerging US state... ...Regulatory Monitoring: Act as the legal team's... ...trends, and security standards to ensure the...SuggestedFull timeContract workLocal areaRemote workShift work- Centene Corp. in Missouri is seeking a Director for Privacy & Security Enterprise Engagement. This key role involves leading the enterprise engagement team, driving compliance with privacy and security regulations, and building partnerships across various stakeholders....SuggestedRemote jobFlexible hours
$115k - $135k
...We're looking for a Security Operations Manager who... ...activities supporting HIPAA, HITECH, and other healthcare regulatory requirements. This position partners... ...teams on security and privacy matters. Participate... ...training Consistently act in compliance with LUX...Suggested$98.8k - $172k
Data Protection & Privacy Operation Specialist - USDS Data Protection... ...USDS Privacy and Integrated Security team is responsible for overseeing... ...a hybrid work schedule that requires employees to work in the... ...and the California Fair Chance Act. Our company believes that criminal...16 hoursFull timeTemporary workFixed term contractWork at officeLocal areaRemote work3 days per week$186.64k - $292.69k
...committed to providing secure and reliable services for... ...partners. As the Director, Security Operations and... ...Cybersecurity, IT, Legal, Privacy, Communications, Engineering... ...United States and not require sponsorship for... ...customer experience think and act in ways that put our...Full timeWork at officeRemote workWorldwideNight shift$113.4k - $138.89k
...Secret clearance)Drug Test: Required for external applicant(s... ...to strengthen U.S. security and promote global stability... ...Assessments Director and internal stakeholders... ...submit a request. California Privacy NoticeThe California Consumer Privacy Act (CCPA) grants privacy rights...Full timeFor contractorsWork at officeWork from homeRelocationFlexible hours1 day per week$244k - $390.58k
...in our products. The Senior Director, Product Security leads all aspects of the... ...every stage and remediation as required. The Senior Director will... ...executionForward looking and acting; must understand and... ...assistance.Applicant and Candidate Privacy NoticeStates Not Eligible...Contract workWork at officeLocal areaRemote work2 days per week- ...Director, Information Security Agfa HealthCare, a division of the Agfa-Gevaert Group... ...with global security and privacy standards across cloud and... ...patient safety priorities. Act as a trusted advisor to... ..., and standards supporting HIPAA, FDA 21 CFR Part 11, ISO 27...Remote work
$159.3k - $273.2k
...Enterprise Information Security (EIS) team at... ...acquisitions. The Senior Director of Data Security is the... ...Architecture, Cyber Defense, Privacy, Legal, Compliance,... ....C. area, you will be required to work in the office... ...including NIST, ISO, HITRUST, HIPAA, GDPR, CCPA, and...Minimum wageFull timeWork experience placementWork at officeLocal areaRemote workShift work$130k - $180k
...shape a brighter way forward. Director, Health, Safety, Security & Environment - JLLWhat... ...JLL, client and statutory requirements. There may be periodic... ...role you're pursuing.JLL Privacy NoticeJones Lang LaSalle (... ...the Arizona Civil Rights Act, criminal convictions are...Full timeLocal area- ...board, state and federal requirements. We are passionate about our... ...DescriptionThe Director of (Cyber) Security Architecture and Engineering... ...product, infrastructure, privacy, risk, compliance, legal,... ...Controls, SOC 2, PCI DSS, HIPAA, or other applicable requirements...Live inWork at officeWork from homeFlexible hours
$134.4k - $219.2k
...Senior Manager Legal Data Privacy Operations Regeneron is seeking an experienced and forward-thinking Senior Manager Legal Data... ...initiatives in alignment with organizational objectives and regulatory requirements. Managing vendor relationships by overseeing the execution...Work at office$209k - $293k
...helping organizations secure and recover from connected... ...ImpactWe are seeking a Director of Product Management... ...Management. The Director will act as the operational... ...player-coach role that requires deep engagement with... ...from time to time. Data Privacy Notice for Job Candidates...Full time$150k - $175k
...Job Title: Director - Security Location: USA / EST time zone... ...frameworks. The Director will act as Cyncly's senior... ...security risk, data privacy, and cyber resilience,... ..., and the Board as required, including participation... ...experience with PCI DSS or HIPAA is a plus....Permanent employmentFull timeContract workLocal areaImmediate startRemote workFlexible hours$113.4k - $138.89k
...technology to strengthen U.S. security and promote global stability... ...Strategic Deterrence (SD) Directorate. This position requires full-time on-site presence due... ...a request. California Privacy Notice The California Consumer Privacy Act (CCPA) grants privacy rights...Full timeFor contractorsRelocation packageFlexible hours- Join to apply for the Director, Product Security (Remote) role at Jobright.ai 2 days... ...efforts. • You'll act as a subject matter expert,... ...ensure adherence to regulatory requirements and industry best practices... ...Risk and Compliance (Data Privacy & Regulatory Compliance) Director...Remote jobFull time
$185k - $296k
...collaboration, join us!Figma's Security team is growing, and we're... ...response programsPartner with Legal, Privacy, and Communications teams to... ...-impact eventsWhile it's not required, it's an added plus if you... ...of the Washington Minimum Wage Act and related regulations. Exempt...Minimum wageFull timeLocal areaRemote workFlexible hours- ...overseeing enterprise security operations and providing... ...over site security directors and leads throughout the... ...and regulatory requirements. Ensure system-wide adherence... ...standards, such as HIPAA, OSHA, and Joint Commission... ...of the Rehabilitation Act of 1973, the Vietnam...Full timeLocal areaRemote work
$194.04k - $273.94k
...digital experiences quickly, securely, and reliably by... ...volume of applicants. Director, Product Marketing –... ...Analyst Relations, and act as a cross-functional evangelist... ...: This position will require you to be available... ...in accordance with our Privacy Policy. Please see our...Full timeWork at officeLocal areaRemote workFlexible hoursShift work$107k - $125k
...be occasional circumstances requiring accommodation and are happy to... ...experienced, forward-thinking Security Manager to lead our West... ...earns cross-departmental trust; act as the primary escalation point... ...process, please see our Privacy Notice for U.S. Applicants.If...Full timeWork at officeRemote workWorldwideFlexible hoursShift work$210k - $250k
About the Role:PubMatic is seeking a Director of Information Security to lead and evolve our global... ...in partnership with compliance and privacy teams, and third-party security programs... ...leaders to balance security, regulatory requirements, employee productivity, and business...Work at officeRemote work$108k - $148k
...role supports Gartner's growing Security Operations team. You will... ...ideas are brought forth and acted upon, whether they come from... ...driving security projects from requirements gathering to completion Ability... .... Gartner Applicant Privacy Link: For efficient navigation...ApprenticeshipImmediate startWork from homeWorldwideFlexible hours- ...Position: Executive Director,... ...Assignment Level: Area Security Technology... ...college or university required Master's degree... ...Knowledge of data privacy requirements including... ...Rights and Privacy Act (FERPA) Children'... ...Accountability Act (HIPAA), when applicable...Full timeContract workWork at officeLocal areaAfternoon shift
$171k - $214k
...Corporate TechnologyMaybe you came up through security - incident response, GRC, compliance... ...essential functions of this position require consistent attendance, availability, and... ...the words frantic ferret and crepuscular in your submission.California Consumer Privacy ActWork at officeRemote workFlexible hoursShift work$152k
...roleWe are looking for a Product Security Manager to lead a team... ...within a flexible POD model, requiring you and your team to move fluidly... ...Ordinance, NYC Fair Chance Act, and the LA City Fair Chance... ...application process, please see the Chime Applicant Privacy Notice.Full timeWork at officeLocal areaRemote workFlexible hoursShift work$107.5k - $204.5k
.... Person, or Immigration Status Requirements:Active and transferable U.S. government issued security clearance is required prior to start... ...503 of the Rehabilitation Act and the Vietnam Era Veterans’ Readjustment Assistance Act. Privacy Policy and Terms:Click on this link...Temporary workWork experience placementRemote workFlexible hours$201.4k - $260k
...United Airlines. Our Aviation Security team helps uphold the regulatory and policy standards required to run a safe and successful airline... ...The Managing Director of Global Aviation Security and... ...for responsible AI use, data privacy, and security The base pay...Hourly payRemote workWorldwideNight shift- ...with HIM policies, regulatory requirements, and customer service... ...experience (lead, senior, or acting supervisor acceptable) ~ Experience... ...with Cures Act and HIPAA Privacy Rules Experience with OnBase... ...Infrastructure & Cloud Solutions, Cyber Security Services, etc. We make...Contract workWork at officeRemote work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Director, Security & Privacy (HIPAA Privacy & Security, HITECH Act requirements). Be the first to apply!
Related searches
- physical security manager Remote
- product security manager Remote
- program manager with security clearance Remote
- security operations manager Remote
- corporate security manager Remote
- director information security Remote
- security manager Remote
- security engineering manager Remote
- security systems manager Remote
- director global security Remote



