Director, Privacy – North America

GROW WITH US:

Tandem Diabetes Care creates new possibilities for people living with diabetes, their loved ones, and their healthcare providers through a positively different experience. We’d love for you to team up with us to “innovate every day,” put “people first,” and take a “no-shortcuts” approach that has propelled us to become a leader in the diabetes technology industry.

STAY AWESOME:

Tandem Diabetes Care is proud to manufacture and sell the t:slim X2 insulin pump with Control-IQ technology. We’re also so much more than that. Our company’s human-centered approach to design, development, and support delivers innovative products and services for people who use insulin. Since many of our own team members live with type 1 diabetes, or have a loved one impacted by diabetes, the work is personal, and we are committed to the cause. Learn more attandemdiabetes.com.

A DAY IN THE LIFE:

The Director, Privacy – North America will report to our Senior Vice President & General Counsel and will be an integral part of a cross-functional team that works to ensure our business’ compliance with applicable North American data privacy laws and regulations. The position supports an increasing demand for both legal and operational advice and guidance regarding North American privacy and security matters. The Director, Privacy – North America will deliver pragmatic solutions for privacy compliance in day-to-day operations, as well as product development and design, and will continuously advance Tandem’s overall data protection and privacy program. This role will work closely with other departments within the company to advise on a wide range of privacy and security issues implicated in the development, commercialization, and ongoing support of diverse customer types using our diabetes technology products that range from hardware with embedded software, to a suite of connected digital health products.

YOU’RE AWESOME AT:

Privacy Program Development, Direction and Operation

  • Directs, develops, guides and continuously improves effective privacy compliance program to meet regulatory, legal and company privacy obligations.
  • Develops, maintains and executes on Privacy Roadmap to mature privacy program
  • Conducts privacy and data protection impact assessments of programs, systems, products, and services.
  • Oversees processes for reviewing and responding to individuals’ data-related requests.
  • Partners with Cyber Security and Information Technology to establish metrics measuring effectiveness of compliance initiatives and controls; tracks and reports on compliance issues to senior leadership.
  • Develops and maintains practical incident response playbooks and manages the company’s response to any privacy/security incidents in conjunction with the Cyber Security team.
  • Directs the company’s response to customer complaints about privacy, and investigates and prepares responses to any privacy/security incidents.
  • Consults with external resources to assess, measure, and manage risk.
  • Supervises, guides, and/or works closely with Privacy and Legal team members.
  • Proactively supports new and evolving business models, technologies and growth strategies, including development of new products.
  • Partners with the Privacy team members in the International markets to ensure Tandem has a consistent approach to implementing privacy globally.
  • Establishes strong working relationships with key leaders in the business, and plays a lead role in raising awareness of privacy issues and communicating the strategic priorities for personal data protection.
  • Represents North America on project teams related to privacy compliance in scope. Advises the Chief Privacy Officer and other members of the Leadership Team of external industry developments, recommends potential responses, policy changes, and solutions.
  • Advises Tandem on Privacy incidents and helps determines strategy for communicating with individuals whose data is involved and/or interacts with North American data protection and/or enforcement authorities, as appropriate.

Privacy by Design – Direction

  • Develops standards and guidance for Tandem to support building privacy into the product life cycle.
  • Identifies and assesses global privacy and security requirements of commercial product offerings, including medical devices and all related software, cloud services, mobile apps, web applications, and portals accessible by end users, healthcare providers, and distribution partners.
  • Develops standard procedures to ensure data privacy compliance requirements are addressed throughout product and information lifecycles.
  • Interacts with business partners, healthcare organizations, health insurers, and service providers regarding data privacy and data protection related matters.
  • Contributes to the analysis and associated content development for the company’s partnership and collaboration efforts.

Laws and Regulations – Compliance

  • Maintains awareness of emerging laws, regulations, enforcement activity, and trends and developments in industry best practices related to data privacy in North America.
  • Communicates legal and regulatory privacy requirements to business partners.
  • Creates and delivers regular communications and trainings to key functional areas in order to ensure awareness of U.S. federal, U.S. state, and Canadian data protection and privacy requirements, as well as internal processes and practices.
  • Develops deep understanding of company processes and partners with members of legal, information technology, cyber security, research & development, commercial and HR to identify and mitigate privacy compliance risks.

General Department Administration & Agreements

  • Assists with reviewing, drafting and/or negotiating privacy-related agreements, including Business Associate Agreements, Data Processing Agreements, Standard Contractual Clauses, HIPAA marketing authorizations, and various consents.
  • Assists with reviewing, drafting and/or negotiating data protection, privacy and cyber security terms within general company contracts.
  • Assists in evaluating available cyber insurance products
  • Works closely with corporate paralegal, Privacy Program Manager and other internal customers to develop and improve internal processes that will support the overall growth and scaling of the Privacy department.
  • Functions independently and delivers results with minimum supervision.
  • Maintains the confidentiality of Legal Department communications and documentation.
  • Ensures work is performed in compliance with company policies including Privacy/HIPAA and other regulatory, legal, and safety requirements.

EXTRA AWESOME:

  • Bachelor’s degree (B.A/B.S.) in related field or combination of equivalent education and applicable work experience.
  • A minimum of 10 years of privacy and/or compliance experience, with minimum 5 of those years involving the practical privacy compliance aspects related to personal health information (e.g., conducting privacy assessments, drafting privacy notices and/or external privacy collateral, advising on privacy-by-design, developing internal policies and procedures, etc.) in North America.
  • Demonstrated leadership in Privacy compliance.
  • Experience creating and implementing a privacy compliance program.
  • Experience in the MedTech, Life Sciences and/or Healthcare industries.
  • A proven track record of success in an environment that demands a sound understanding of the need to balance complex legal/regulatory/public policy issues within the structural and operational realities is required.
  • Juris doctorate, with a license to practice in the state of California.
  • Security, Privacy or Audit Certifications, such as CISSP, CIPP, CISA, CISM; CIPP strongly preferred.
  • Experience working for a HIPAA Covered Entity.
  • In-depth knowledge of data protection and privacy laws, including HIPAA, PIPEDA, CCPA (and other similar state laws), domestic and Canadian breach notification laws, and additional regionally applicable laws and regulations.
  • Knowledge of, and working experience with, appropriate responses to privacy breach events, including interactions with relevant federal and state authorities.
  • Experience reviewing, drafting, and negotiating:
    • information security and privacy provisions in agreements
    • privacy and data transfer or processing agreements
    • network access, disaster recovery and other related technology agreements
  • Demonstrated privacy, compliance or other form of operational experience translating legal and regulatory requirements into a comprehensive privacy program that utilizes practical processes and practices for global systems, services and operations; demonstrated experience leading and maturing such a program.
  • Experience advising clients with heavy direct-to-consumer contact through multiple channels of communication (phone, email, text, web).
  • Understanding of risks facing a global medical device company.
  • Ability to identify privacy compliance issues and resolve them through both internal and external research.
  • Ability to operate independently and develop and implement strategies to maximize the efficiency and effectiveness of the global legal function.
  • High level of integrity supported by sound judgment and ethics.
  • Effective verbal and written communication and presentation styles to interact with diverse audiences, including outside attorneys, senior management and business associates.
  • Technical understanding of IT infrastructure, web-based software and mobile Apps and ability to work with IT, cyber security, and engineering teams in applying privacy-by-design principles.
  • Understanding of business and privacy sensitivities of healthcare organizations.
  • Ability to handle complex matters, across multiple simultaneous initiatives that require discretion, confidentiality and prioritization.
  • Demonstrated experience in a leadership-level (Director or above) privacy position, at a large health care company.
  • Strong, direct people management experience.
  • Strong focus on business partnering and solutioning and ability to operate effectively in a matrix structure is required.

WHAT’S IN IT FOR YOU?

In addition to innovative technology, we have a culture that fosters the idea that the happiest people are the most productive people. Not only do we hire forward-thinking achievers to join our workforce; we reward, develop, and retain them too. Just one of the many reasons of how we #StayAwesome! To learn more about our culture and benefits please visit https://www.tandemdiabetes.com/careers.

BE YOU, WITH US!

Tandem is firmly committed to being an equal opportunity employer and maintaining a diverse and inclusive environment. We value and embrace that every single one of us brings value to the table. But sometimes we forget that when we don’t meet 100% of a job description’s criteria – maybe you’re feeling that way right now? We encourage you to apply anyway. Because we want you to be you, with us.

COMPENSATION & BENEFITS:

The starting base pay range for this position is $210,000 – $240,000 annually. Base pay will vary based on job-related knowledge, skills, experience and may also fluctuate depending on candidate’s location and the overall job market. In addition to base pay, Tandem offers a competitive compensation package that includes bonus, equity, and a robust benefits package.

Tandem offers health care benefits such as medical, dental, vision, health savings accounts and flexible saving accounts. You’ll also receive 10 paid holidays per year, a minimum of 20 days of paid time off (starting in year 1) and have access to a 401k plan with company match. Learn more about Tandem’s benefits here!

REFERRALS:

We love a good referral! If you know someone that would be a great fit for this position, please share!

If you are applying for this job and live in California, please read Tandem’s CCPA Notice: https://www.tandemdiabetes.com/careers/california-consumer-privacy-act-notice-for-job-applicants.

#LI-DW1

Job Category
Job Type
Salary
Country
City
Career Level
Company
JOB SOURCE