Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Director, Chief Privacy Official & Privacy Counsel

Blue Shield of California

Description This role will act as the Company's Chief Privacy Official and Privacy Counsel ("CPO"). BSC's Privacy Office is part of the Corporate Integrity and Compliance Department ("Compliance") within the BSC Law Department. This position reports to the Vice President, Chief Risk and Compliance Officer and manages four Privacy Specialists. The BSC Privacy Office, under the CPO's direction, owns the development and maintenance of the Company's Privacy Program and ensures compliance with applicable privacy and privacy-related consumer protection laws across the enterprise, including all business units, products and services. The Privacy Program includes the implementation and maintenance of proper preventive, detective and remedial controls, the execution of relevant policies and procedures, training and educating the workforce, implementing an effective communications program, ensuring effective testing, auditing, monitoring, tracking and reporting, remediating control deficiencies, and data breach response and management. The Privacy program encompasses all privacy-related subject matter areas, including, for example, data protection, marketing privacy, privacy breach incident response, Business Associate contracting and oversight, online privacy, as well as customer, employee, broker, and provider privacy. The CPO works closely with other Compliance teams while partnering with key operational stakeholders including IT Security and Internal Audit. The CPO will be responsible for the provision of privacy legal counsel to the company and all of its business and operational units, as well as other in‑house BSC attorneys. The CPO will lead and coordinate privacy/data breach response activities, liaise with internal and external resources, represent BSC's interests before state and federal privacy enforcement agencies, and address privacy inquiries from BSC customers and business partners. The CPO will be required to work collaboratively with other Compliance teams and to support the Vice President, Chief Risk and Compliance Officer with various initiatives including preparation of Audit Committee reports. Specific Responsibilities Include Lead all aspects of BSC's Privacy program across the enterprise, including all business units, products and services. Chair, engage, and facilitate meetings of the Privacy Council, the governance body for the Privacy Program. Lead team of Privacy professionals to ensure robust and effective preventive, detective and remedial privacy controls throughout the Company's operations. Conduct annual strategic planning for Privacy program needs and objectives. Maintain clear, effective, and legally compliant privacy policies and procedures. Implement and execute effective training, communications and awareness programs to properly educate employees and business partners regarding privacy legal requirements and responsibilities. Implement and execute effective testing, auditing, monitoring, tracking and reporting procedures to ensure the success of the program, as measured by regular assessments and metric‑based analysis. Conduct privacy investigations, including data security breaches and other privacy matters. Prepare comprehensive investigation summary reports. Ensure proper corrective action and remedial measures are taken once investigations are completed. Counsel and advise the business units regarding new and existing initiatives, products and services. Support the business on implementing and executing such guidance. Ensure compliant marketing campaigns and information sharing and disclosure practices, including social media and other forms of emerging technologies and Internet‑based communications vehicles. Ensure proper remediation regarding identified privacy control deficiencies. Ensure proper vendor and third‑party oversight, including negotiation and maintenance of all required contractual and operational controls (e.g., Business Associate Agreements). Build and maintain effective relationships with all relevant internal and external stakeholders, including federal, state and local regulatory entities, the Blue Cross Blue Shield Association (BCBSA), IT, IT Security, Marketing, Human Resources, Employee Relations, Legal, and Internal Audit, among others. Compile clear, accurate and timely reports for senior management and the Board, as needed. This includes the proper investigation and inquiry reporting, tracking, closure metrics and accompanying analyses (e.g. trend and pattern identifications). Work with and respond to regulators and law enforcement, as needed. Candidate Profile & Requirements Senior leader and strategic thinker with extensive health care privacy and compliance experience. Keeps how to build, lead and sustain an effective Privacy Program aimed to prevent, detect and remediate actual and potential privacy risks. Extensive privacy and compliance investigations experience, including the ability to lead cross‑organizational and complex investigations from start to finish. Strong political acumen to partner and collaborate with, and influence, all relevant stakeholders, both internal and external, including executive management. Strong communication and relationship-, coalition- and consensus‑building skills required. Strong independent judgment, critical and analytical thinking, and problem‑solving skills required. Strong moral compass and high integrity required. Must do the right thing, even when it means doing the difficult thing. Knowledge and Skills Extensive health care privacy and compliance expertise and experience. Ability to independently and self‑sufficiently lead the function with minimal supervision and direction. Strong verbal, written, and oral communication skills. Strong ability to influence at all levels of the organization, including executive management, the Board, Audit Committee, workforce members, regulators, local, state and federal officials, customers, partners and vendors. Strong ability to synthesize vast amounts of complex data, and clearly and concisely articulate the relevant points without getting lost in the weeds. Proven ability to multi‑task, thrive and deliver in a highly regulated, demanding, entrepreneurial, and constantly changing corporate environment. Demonstrated ability to regularly re‑prioritize risks, objectives and action plans based on an evolving corporate and regulatory landscape. Ability to deal well with ambiguity and complex situations. Ability to lead a team through growth and change. Ability to set a clear vision for the department and to successfully execute on the vision. Experience in building programs, process improvements and/or re‑engineering. Strong leadership, people management and mentoring skills. Qualifications Required Education/Experience Bachelor's degree and J.D. from an ABA accredited U.S. law school, current admission to the bar of at least one U.S. state, eligibility for CA in‑house counsel licensure required. Minimum 10 years legal practice experience, health care privacy experience required, in‑house counsel experience strongly preferred. Personnel and privacy program management experience required. Strong breach management/response experience required. CIPP/US Certification from the IAPP (or willingness to obtain same) preferred. Experience Minimum of 10 years of health care privacy experience with increasingly progressive responsibility. Prior in‑house privacy compliance and legal experience required. Chief Privacy Officer experience preferred, but not required. Functional subject matter expertise in HIPAA, HITECH, CAN‑SPAM, TCPA, PCI DSS, security breach notification laws, privacy‑related marketing and advertising laws, and other applicable laws and regulations required. Proven ability to effectively and timely manage multiple initiatives and cross‑departmental projects. Substantive experience dealing with health care regulators, law and regulatory enforcement agencies. Demonstrated leadership, ability to drive results and engage senior leaders, and ability to influence cross‑organizational stakeholders and decision makers with different operational responsibilities. Proven track record of building consensus, forging coalitions and leveraging professional relationships to achieve strategic objectives and to create an effective "culture of compliance." Preferred Experience & Skills Extensive corporate investigations experience preferred. Strong familiarity with health plan systems and applications preferred. Strong program and project management experience preferred. Knowledge of California privacy laws and regulations preferred. #J-18808-Ljbffr Blue Shield of California

Vacancy posted 3 days ago
Similar jobs that could be interesting for youBased on the Director, Chief Privacy Official & Privacy Counsel in San Francisco, CA vacancy
  • $211.37k - $253.64k

     ...may close early due to the volume of applicants. Senior Privacy and Regulatory Counsel We are looking for a Senior Privacy and Regulatory Counsel...  ...applying. All job applications must be submitted through our official careers site at We will never request sensitive... 
    Suggested
    Work at office
    Local area
    Flexible hours

    Fastly

    San Francisco, CA
    2 days ago
  • $220k - $260k

     ...neighborhood at nextdoor.com . Meet Your Future Neighbors The Counsel team is a close-knit and collaborative team that supports the entire...  ...This role is based in San Francisco. The Impact You’ll Make As Privacy and Regulatory Compliance Counsel, you’ll be responsible for... 
    Suggested
    Work at office
    Local area
    Work from home
    Flexible hours

    Nextdoor

    San Francisco, CA
    2 days ago
  •  ...Job Overview A law firm seeks a Privacy Counsel in San Francisco, CA. This role involves working closely with the Legal Risk Management team to address privacy-related issues across all business functions. The Privacy Counsel will enhance privacy policies, ensure compliance... 
    Suggested

    BCG Attorney Search

    San Francisco, CA
    4 days ago
  • $185k - $317k

     ...world. If you're excited to shape the future of design and collaboration, join us! We're looking for an attorney with expertise in privacy law and AI governance to join Figma's Legal team. In this role, you\'ll collaborate with Product, Engineering, Policy, and Commercial... 
    Suggested
    Full time
    Remote work
    Work from home
    Shift work

    Figma

    San Francisco, CA
    4 days ago
  •  ...Senior Attorney to join its in-house legal team. The role involves advising on corporate transactions, employment matters, and data privacy, ensuring legal compliance across multiple jurisdictions. As a trusted business partner, you will handle a broad range of legal... 
    Suggested

    Blue Bottle Coffee Inc

    San Francisco, CA
    3 days ago
  • Fastly is seeking a Senior Privacy and Regulatory Counsel to ensure compliance with privacy laws and regulations. The individual will lead the global privacy program, engaging with stakeholders across the organization. Candidates should possess a JD and over 8 years of... 

    Fastly

    San Francisco, CA
    2 days ago
  • BCG Attorney Search is seeking a Privacy Counsel in San Francisco, CA, to work closely with the Legal Risk Management team. This role focuses on addressing privacy issues, enhancing policies, ensuring compliance with U.S. and international privacy laws, and mitigating data... 

    BCG Attorney Search

    San Francisco, CA
    5 days ago
  • $108 - $118 per hour

    Paragon Legal is seeking a Regulatory and Compliance Attorney in San Francisco, CA, to support product regulatory compliance and privacy matters. This role is responsible for advising cross-functional teams on compliance strategies, monitoring legislation, and aiding with... 
    Hourly pay
    Part time

    Paragon Legal

    San Francisco, CA
    4 days ago
  •  ...institutions globally, solidifying our role in protecting the world’s critical infrastructure and securing our way of life. Senior Counsel - Privacy, Product, and AI At OPSWAT, we’re on a mission to protect the world’s most critical infrastructure—from nuclear facilities and... 
    Contract work
    Local area
    Remote work

    OPSWAT

    San Francisco, CA
    1 day ago
  • $185k - $317k

    Figma is seeking an attorney with expertise in privacy law to join its Legal team in San Francisco. The attorney will advise on privacy compliance, AI governance, and collaborate with teams to facilitate Figma's responsible growth. The ideal candidate has a J.D. and at... 

    Figma

    San Francisco, CA
    5 days ago
  •  ...looking for a high-agency operator to join us as our Senior Privacy & AI Counsel . Reporting to the General Counsel, you'll be the day-to-...  ...relationship directly, and you have presented to the Board of Directors and are the company's named lead for privacy and AI risk at... 
    Full time
    Temporary work
    For subcontractor
    Shift work

    Abby Care

    San Francisco, CA
    3 days ago
  • Nextdoor is looking for a Privacy and Regulatory Compliance Counsel in San Francisco. This role focuses on analyzing current laws affecting the Nextdoor platform and developing compliance strategies. You’ll prepare risk assessments, advise on data governance, and work cross... 

    Nextdoor

    San Francisco, CA
    5 days ago
  • $264.8k - $331k

    Scale AI is seeking an experienced Associate General Counsel for Product and Privacy in San Francisco. This role requires a minimum of 9 years of legal experience, particularly in technology and privacy. You'll manage legal risks in product development, collaborate with... 

    Scale AI

    San Francisco, CA
    3 days ago
  • Neuralink is hiring an Associate General Counsel to oversee their privacy and compliance program. This role involves managing sensitive data and ensuring compliance with various regulations, including HIPAA and GDPR. The ideal candidate will have extensive experience in... 

    Neuralink

    San Francisco, CA
    3 days ago
  • $303.2k - $360k

     ...Department Overview UC Legal - Office of General Counsel is located in Oakland, California, and is...  ...Position Summary Reporting to the Systemwide Chief Health Counsel and Deputy General Counsel, Health Affairs, Privacy and Data Protection, the Special Counsel advises... 
    Work at office
    Local area
    2 days per week

    University of California Office of the President

    San Francisco, CA
    5 days ago
  • CHYM is looking for a Director, Associate General Counsel in San Francisco to lead the Privacy & Security team. This role requires advising on privacy laws, managing compliance programs, and developing training while working cross-functionally with various departments.... 

    CHYM

    San Francisco, CA
    1 day ago
  • $365k - $390k

     ...Shaw Pittman LLP is seeking a qualified legal professional in San Francisco focusing on data protection and compliance with various privacy laws. This partner track position requires problem-solving skills, a JD from an accredited law school, and a minimum of 5-6 years'... 

    Pillsbury Winthrop Shaw Pittman LLP

    San Francisco, CA
    4 days ago
  • Abby Care in San Francisco is seeking a Senior Privacy & AI Counsel to lead their privacy and AI governance programs. This role is vital as the company navigates the evolving regulatory environment and enhances its AI initiatives. The ideal candidate will have at least... 
    Full time

    Abby Care

    San Francisco, CA
    3 days ago
  • $179k - $241k

     ...global group of lawyers and legal professionals operating across multiple disciplines. As we continue to expand, we are looking for a privacy lawyer to join our growing legal team. You will play a key role, working directly with our Head of Privacy, in maintaining and... 

    Dormont Manufacturing Co

    San Francisco, CA
    5 days ago
  • Axiom is seeking a Data Privacy & Cybersecurity Lawyer in San Francisco to provide legal advice on compliance and privacy policies. The ideal candidate will have over 4 years of experience in the data privacy field, must possess an active bar license, and have substantive... 
    Flexible hours

    Axiom

    San Francisco, CA
    5 days ago
  •  ...LLP is seeking a junior to mid-level associate for their Data Privacy group in San Francisco. The role offers early responsibility,...  ...Candidates should have strong experience in privacy and product counseling, familiarity with regulations including CCPA and GDPR, and... 

    Gunderson Dettmer Stough Villeneuve Franklin & Hachigian LLP

    San Francisco, CA
    5 days ago
  • OPSWAT is seeking a Senior Counsel to oversee privacy and compliance strategies while ensuring alignment with product development and security teams. This role offers opportunities for leadership in a fast-paced environment, focusing on major cybersecurity challenges.... 
    Remote job
    Flexible hours

    OPSWAT

    San Francisco, CA
    1 day ago
  • $185k - $317k

    byebyeoffice is seeking a Privacy Counsel to join their Legal team in San Francisco. This full-time role is remote-first and requires expertise in privacy law and AI governance. You'll collaborate with various teams to support legal compliance across Figma's platform, ensuring... 
    Remote job
    Full time

    byebyeoffice

    San Francisco, CA
    5 days ago
  • Stripe’s Product Legal team seeks a senior product counsel to advise cross‑functional partners on regulatory, privacy and compliance issues for Stripe Terminal and related products. You will collaborate with engineering, partnerships, marketing and legal colleagues to... 
    Remote job

    Stripe

    San Francisco, CA
    2 days ago
  • Clay is seeking a Product Counsel to lead privacy strategy for our product portfolio in San Francisco. The role requires partnering with product, engineering, sales, and compliance to ensure privacy by design while enabling sustainable growth. Ideal candidates bring 5-7... 

    Clay

    San Francisco, CA
    3 days ago
  • $217k - $315k

     ...law firm. Experience advising on global privacy and data protection laws. Preferred...  ...mitigating risk. As an Associate Regulatory Counsel in Privacy, you will join a Global team...  ...approval by the Alphabet Inc. board of directors or its delegate, the terms of the relevant... 
    Temporary work
    Fixed term contract

    Google Inc.

    San Francisco, CA
    4 days ago
  • Crusoe Energy Systems is seeking a Product & Privacy Counsel to support its Cloud business in San Francisco. You will partner with product management and engineering teams, advising on product development and privacy regulations. Ideal candidates will hold a J.D. and have... 

    Crusoe Energy Systems

    San Francisco, CA
    3 days ago
  • $300 per month

     ...us at Crusoe. About This Role Crusoe seeks a technology enthusiast and pragmatic legal advisor to serve as Product & Privacy Counsel at the director level, embedded within the Crusoe Cloud business. You will serve as a trusted partner to our Product Management and Cloud... 
    Temporary work

    Crusoe Energy Systems

    San Francisco, CA
    3 days ago
  • Google is seeking an Associate Regulatory Counsel in Privacy to join a global team that guides privacy law interpretation and regulatory engagement. You will partner with Compliance, Product, and Engineering to assess and mitigate risk while communicating our stance to... 

    Google

    San Francisco, CA
    1 day ago
  • Google is seeking an Associate Regulatory Counsel in Privacy to join a global team that advises on privacy law in the evolving technology landscape. You will interpret laws, mitigate regulatory risk, and partner with cross-functional teams across the company to ensure... 

    Google Inc.

    San Francisco, CA
    4 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Director, Chief Privacy Official & Privacy Counsel. Be the first to apply!