Be a key part of the Capital Rx Privacy Office and work closely with the Legal, Compliance, Information Technology Security & Compliance (ITSC), and AI Development teams.
Identify potential gaps, analyze processes and controls, and implement improvements, including software/technology solutions, to help ensure compliance with regulations and best practices while emphasizing opportunities for greater efficiency and automation.
Develop new, and enhance existing, privacy policies, procedures, and training.
Keep current with privacy legislation/regulations and industry trends; analyze and report requirements and impacts on privacy programs, privacy notices, product and service offerings, and business operations.
Work with business units across the company on the technical implementation of privacy compliance including data mapping, privacy impact assessments, and rights requests, and support ongoing operations of these efforts from the Privacy side.
Coordinate with business units regarding data breach and security incident response.
Participate in regular Privacy, Compliance, and ITSC focused internal and externals audits, questionnaires, and vendor assessments.
Support special projects as needed for the Privacy Office.
Responsible for adherence to the Capital Rx Code of Conduct including reporting of noncompliance.
Requirements
Bachelor’s degree or industry-related experience.
2+ years of hands-on experience working in data / information privacy, with a preference for experience supporting a corporate privacy / data protection program.
Demonstrated high-level understanding of current data protection and privacy legislation, with an emphasis on HIPAA, as well as CCPA/CPRA and other state frameworks.
Experience conducting ongoing privacy compliance and monitoring activities.
Strong project management skills, with the ability to effectively prioritize and manage multiple privacy initiatives.
Excellent communication and interpersonal skills, with the ability to collaborate and influence stakeholders at all levels of the organization.
Passion to continuously develop and expand skills and knowledge base in data privacy.