06 Oct
|
Innovaccer
|
Noida
Role & responsibilities
- Support and Operationalize Global Compliance Programs: Implement assigned elements of the annual compliance plan, drafting and updating policies, procedures, playbooks, and controls for handling Protected Health Information (PHI) and personal data.
- Drive Privacy Operations & Privacy-by-Design: Partner with Product, Engineering, Analytics, and Security teams to conduct Privacy Impact Assessments (PIAs/DPIAs) and embed privacy controls into AI/ML models and product lifecycles.
- Conduct Audits & Reviews: Plan and execute risk-based audits and monitoring on Business Associate Agreement (BAA) compliance, third-party data handling, and access controls.
- Review Contractual Privacy Terms: Perform privacy due diligence and review data protection terms, including BAAs and Data Processing Addenda (DPAs), in customer and vendor agreements.
- Manage Incident Response & Regulatory Monitoring: Lead or support privacy incident investigations, perform risk/notification analyses, and track changes in healthcare compliance, AI, and cybersecurity regulations to update operational workflows.
- Enable Teams & Report Progress: Deliver role-based privacy and compliance training for employees/contractors and maintain risk registers, metrics, and evidence repositories for management reporting.
Preferred candidate profile
- Knowledge: Strong working knowledge of global privacy laws and security frameworks including US HIPAA/HITECH, India DPDP Act 2023/Rules 2025, EU GDPR, KSA PDPL, UAE Data Protection Law, as well as ISO 27001/27701, SOC 2, HITRUST, and NIST frameworks. Understanding of SaaS/cloud environments, healthcare interoperability, and AI/ML data privacy.
- Ability: Competence to translate complex regulatory requirements into clear controls, perform PIAs/DPIAs, conduct audits and investigations, review contractual privacy terms (BAAs/DPAs), and communicate risk-calibrated, business-forward advice to technical and non-technical stakeholders.
- Credentials/Experience:
- Bachelors degree in law, business, compliance, information systems, computer science, cybersecurity, public policy, or a related field.
- At least 5 years of relevant experience in compliance, privacy, data protection, or healthcare regulatory management.
- At least 3 years of experience within a technology, SaaS, cloud computing, healthcare, life sciences, or regulated setting.
- Preferred: Recognized privacy/security certifications (e.g., CIPP/US, CIPP/E, CIPM, CIPT) or an advanced degree.
📌 Senior Associate Compliance & Privacy (Noida)
🏢 Innovaccer
📍 Noida