Acadia Healthcare-posted 2 months ago
Franklin, TN
5,001-10,000 employees
Ambulatory Health Care Services

We are seeking a Data Protection & Risk Specialist to join our team in Franklin, TN. The first 90 days in this role will be fully in-person to ensure comprehensive onboarding and training. After the initial period, the position will transition to a hybrid model, with 2 days remote and 3 days in the office each week. The Data Protection & Risk Specialist will play a critical role in safeguarding Acadia's sensitive information by serving as the subject matter expert for data classification, data loss prevention (DLP), and insider risk management. This role is responsible for designing, implementing, and optimizing Acadia's data protection framework to ensure data is properly tagged, secured, and governed throughout its lifecycle. The Specialist will partner with IT, compliance, privacy, and business units to reduce risks associated with data misuse, strengthen regulatory compliance, and embed best practices in data protection and risk management across the organization.

  • Act as Acadia's subject matter expert for data classification, labeling, and protection practices.
  • Develop and enforce policies, standards, and procedures to ensure sensitive data is safeguarded consistently.
  • Implement and optimize insider risk detection and prevention capabilities.
  • Define monitoring use cases, incident response processes, and mitigation strategies.
  • Configure, tune, and maintain DLP technologies to reduce the risk of data leakage.
  • Collaborate with business units to ensure DLP controls align with operational needs and compliance requirements.
  • Support enterprise risk assessments related to data protection and insider threats.
  • Document risks, propose mitigations, and ensure alignment with NIST, ISO, HIPAA, and other governance frameworks.
  • Ensure Acadia's data protection practices comply with HIPAA, 42 CFR Part 2, SOX, PCI, GDPR, and other relevant regulations.
  • Participate in audits, assessments, and compliance reviews.
  • Work closely with IT, compliance, and business leaders to embed data protection into operations and projects.
  • Provide expertise during security reviews and incident investigations.
  • Support development of training programs and awareness campaigns to strengthen organizational culture around data protection and responsible data use.
  • Stay informed on evolving insider threats, regulatory changes, and emerging technologies.
  • Recommend enhancements to data protection and risk management strategies.
  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Risk Management, or related field; or equivalent work experience.
  • Minimum 4-6 years in cybersecurity, with 3+ years focused on data protection, insider risk, or DLP.
  • Broader experience in governance, risk management, and compliance preferred.
  • Strong knowledge of data classification frameworks, DLP tools, and insider risk programs.
  • Familiarity with Microsoft Purview, insider risk management solutions, and data tagging technologies preferred.
  • Deep understanding of healthcare regulations (HIPAA, 42 CFR Part 2) and familiarity with frameworks such as NIST, ISO, and CIS.
  • Skilled in explaining data protection and risk concepts to both technical and non-technical audiences.
  • Ability to manage cross-functional security initiatives, prioritize competing tasks, and deliver on time.
  • High level of discretion, collaboration, and problem-solving abilities; proactive and detail-oriented.
  • Committed to staying current on emerging cyber risks, technologies, and best practices in data protection.
  • CISSP, CISM, CRISC, CIPP, Microsoft Certified: Information Protection Administrator, GIAC DLP Engineer (GDLPE), HCISPP, or equivalent certifications.
  • Equal employment opportunities to all applicants for employment regardless of an individual's characteristics protected by applicable state, federal and local laws.
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service