Job description
Why Join Omnicell?
Omnicell is building out its privacy program alongside a fast-moving product and innovation pipeline, and we are looking for a Senior Analyst, Privacy to join our Legal Department as the dedicated privacy advisor to our Product, Innovation, and R&D teams.
You will embed privacy-by-design principles throughout the product lifecycle, lead privacy impact assessments across the innovation pipeline, and advise on what data can responsibly be used for research, prototyping, and analytics, including secondary uses of Protected Health Information. You will also partner with Product and Commercial to shape the privacy strategy that takes new offerings to market.
This role translates evolving data protection requirements into clear, launch-ready guidance, so that Omnicell can innovate at speed while maintaining compliance with applicable global, federal, and state privacy laws.
What You’ll Do (Key Responsibilities)
As a Senior Analyst, Privacy, you will:
Primary Impact – Let Omnicell innovate at speed by making privacy a design input rather than a launch obstacle, so that new products, features, and research initiatives reach the market with data practices that customers, regulators, and patients can trust.
Privacy by design – Operationalize privacy-by-design and privacy-by-default principles in product requirements, data architecture, and feature design, and review product specifications, user flows, and data schemas to identify and resolve privacy considerations early
Data strategy advisory – Advise on data minimization, purpose limitation, retention, and de-identification strategies for new products and features
Technical privacy controls – Partner with engineering on technical privacy controls, including consent management, access controls, and data segregation
Impact assessments – Lead privacy impact assessments (PIAs) and data protection impact assessments (DPIAs) for new products, services, features, research initiatives, and development tools across Omnicell’s innovation pipeline, and determine when a new product, system, vendor, or data initiative requires an assessment or additional safeguards before launch
Risk evaluation and residual risk – Identify and evaluate the collection, use, and flow of personal and health information in proposed offerings, recommend practical and prioritized mitigations, and document residual risk for business stakeholders
Data mapping and records – Map and document data flows for products and innovation projects, contributing to the enterprise data inventory and records of processing activities (RoPA)
Research and innovation data enablement – Advise on permissible uses of data for research, prototyping, analytics, and product development, including secondary uses of Protected Health Information, and evaluate and structure R&D data sourcing approaches such as de-identification, limited data sets, synthetic data, and aggregation
Contractual data rights – Assess data rights and usage limitations under customer agreements and Business Associate Agreements (BAAs) as they relate to innovation and development initiatives
Third-party diligence – Perform privacy due diligence on third-party tools, data sources, APIs, and development vendors proposed for use by the product and R&D teams
Emerging technology advisory – Review and advise on the privacy implications of new products, features, technologies, and data uses, including AI/ML-enabled features, analytics, and connected-device offerings
Scalable methodology – Build and maintain repeatable assessment methodologies, intake processes, templates, and playbooks that scale with the pace of innovation
Training and enablement – Deliver targeted privacy training for product, engineering, and R&D personnel on privacy-by-design and responsible data use
Cross-functional alignment – Partner with cross-functional teams to align privacy strategy with commercial and compliance objectives
Who You Are (Qualifications & Skills)
Minimum Qualifications
One or more IAPP certifications, such as CIPP/US, CIPM, or CIPT
6+ years of progressive experience in privacy or data protection, including at least 3 years supporting a healthcare, medical device, digital health, or health technology company
Demonstrated experience conducting privacy impact assessments and data protection impact assessments for new products, systems, or initiatives, along with data mapping and records of processing activities
Deep, hands-on knowledge of the HIPAA Privacy Rule, Security Rule, and Breach Notification Rule, including Business Associate compliance
Working command of U.S. state privacy laws such as CCPA/CPRA, emerging global frameworks, and adjacent cybersecurity regulatory requirements, and how they apply to product development and go-to-market activities
Familiarity with the privacy considerations of AI/ML-enabled and cloud-connected products, including data minimization, consent, and data classification
Hands-on experience translating privacy requirements into practical, development-ready guidance
A commercial, product-minded orientation, with the ability to balance privacy risk against business objectives and enable responsible speed-to-market
A track record of partnering with cross-functional teams, including product, engineering, legal, security, and compliance, with the ability to influence without authority
Strong analytical and writing skills, with the ability to translate complex technical and legal concepts into actionable guidance for any audience
The ability to work independently, set priorities, and manage multiple assessments and timelines in a fast-paced environment, communicating them clearly to stakeholders
Strong initiative and a genuine appetite for learning, effective interpersonal and problem-solving skills, and a highly organized approach with sharp attention to detail
Preferred Qualifications
Bachelor’s degree in information technology, health informatics, business, legal studies, or a related field, or equivalent experience
Advanced degree or J.D.
Additional privacy certifications, such as CIPP/E or CHC
Experience supporting product launches, go-to-market processes, or stage-gate and launch review programs
Familiarity with privacy management platforms, such as OneTrust or Securiti, and with privacy-by-design in the product development lifecycle
Familiarity with FDA medical device regulatory requirements and their intersection with data privacy
Experience advising on AI/ML privacy and governance issues
Experience supporting global or cross-regional privacy programs, including GDPR
Work Conditions
Flexibility in working hours as needed
Some travel, ~10%
Base Compensation: $12,000.00 to $156,000.00
(Actual compensation is subject to variation due to such factors as location, education, experience, and skillset. We offer a comprehensive benefits package, including medical, dental and vision plans covering eligible US employees and dependents, voluntary wellness and employee assistance programs, life insurance, disability, retirement plans with matching, and paid time off.)
Originally posted on Himalayas
Who can apply
Eligible countries: United States. Accepted UTC offsets: UTC-10, UTC-9, UTC-8, UTC-7, UTC-6, UTC-5, UTC+14. Review the full description for employer-specific work authorization, residency and schedule requirements.