Director, Security & Privacy (HIPAA Privacy & Security, HITECH Act requirements)

Fujifilm

Apply Now
United States
$134,406 - $186,696 / year
full-time
director
Posted August 13, 2026
via himalayas

About This Role

Position Overview The Director, Security and Privacy leads HCUS s enterprise security & privacy programs. This role advises executive leadership on the security posture of the organization, including HCUS products, Cloud Services, HCUS business systems, and customer-facing technologies that process or store PHI. The Director requires a strong understanding of organizational, product, cloud, and customer security, as well as the ability to communicate effectively with technical teams, business leaders, regulators, auditors, legal counsel, and customers C-suite executives. The Director works closely with HLUS Security and coordinates the activities of groups spanning all HCUS business units, and the Product Security Incident Response Team across HCUS, HLUS, and FTYO. The Director provides guidance on information on security agreements, customer security requirements, regulatory obligations, and risk-management decisions. This role also plans and coordinates company resources to support compliance with HIPAA, SOC 2, applicable state and federal cybersecurity and privacy laws, and other relevant regulatory and contractual frameworks. As the official HCUS HIPAA Privacy Officer and HIPAA Security Officer, the Director oversees the development, implementation, and continuous improvement of policies, procedures, safeguards, incident-response processes, and compliance activities designed to protect PHI and other sensitive information. The role places equal emphasis on executing assigned responsibilities and coordinating with departments across the company, including HLUS and FTYO, to promote a consistent, integrated, risk-based approach to security and privacy. Through cross-functional collaboration, the Director supports the achievement of the organization s short- and long-term security, privacy, and business objectives. Company Overview At FUJIFILM Healthcare Americas Corporation, we re on a mission to innovate for a healthier world, and we need passionate, driven people like you to help us get there. Our cutting-edge healthcare solutions span diagnostic imaging, enterprise imaging, endoscopic and surgical imaging, as well as in-vitro diagnostics. But we don t stop at healthcare; our Non-Destructive Testing (NDT) team harnesses advanced radiography solutions to keep transportation infrastructure, aerospace, and oil and gas assets safe and running smoothly. Ready to innovate, collaborate, and make a difference? Join us and bring your big ideas to life while working in a dynamic, flexible environment that fuels your creativity and drive. Our headquarters is in Lexington, Massachusetts, an inspiring healthcare research hub in a historic town. Fujifilm is globally headquartered in Tokyo with over 70,000 employees across four key business segments of healthcare, electronics, business innovation, and imaging. We are guided and united by our Group Purpose of giving our world more smiles. Visit: Job Description Duties and responsibilities Privacy & Security Leadership • Serve as the organization s designated HIPAA Security Officer and HIPAA Privacy Officer. • Develop, implement, maintain, and enforce the company s information security, privacy, and program. • Establish and maintain a governance framework that supports compliance with HIPAA, HITECH, SOC 2, applicable state privacy laws, breach-notification requirements, contractual obligations, and other relevant healthcare and security standards. • Advise executive leadership on security, privacy, technology, and operational risks. • Present meaningful security, privacy, audit, and risk metrics to executive leadership and other stakeholders. • Maintain awareness of changes in healthcare privacy, cybersecurity, and regulatory requirements, translating those changes into actionable organizational improvements. Policies, Procedures, and Program Management • Own the development, review, approval, implementation, and periodic revision of HCUS security and privacy policies, standards, procedures, and supporting documentation. • Ensure policies address administrative, physical, and technical safeguards appropriate to HCUS s systems, workforce, operations, and risk profile. • Maintain required HIPAA documentation, including risk analyses, risk management plans, policies, training records, incident documentation, access reviews, vendor assessments, and compliance evidence. • Lead periodic program assessments and continuous improvement initiatives to measure and improve security and privacy maturity. Risk Management and Security Assessments • Lead HCUS-wide security and privacy risk assessments, including HIPAA Security Rule risk analysis and periodic reassessments. • Identify, document, prioritize, and track remediation of security, privacy, operational, technical, and third-party risks. • Partner with Engineering, Product Management, HLUS Shared IT Services, Legal, and TAC teams to ensure security and privacy are incorporated into system design, soft...

Ready to Apply?

Click the button below to visit the company's application page.

Apply for this Position