Search Remote Jobs

Senior Director, Data Privacy

Job not on LinkedIn

πŸ•’ 5 days ago

Apply Now
Find Similar Remote Jobs

πŸ“Š Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of SAVARA

SAVARA

11 - 50 employees

Founded 2018

🧬 Biotechnology

πŸ’Š Pharmaceuticals

Biotechnology β€’ Pharmaceuticals

Savara is a clinical-stage biopharmaceutical company focused on developing treatments for rare respiratory diseases, principally autoimmune pulmonary alveolar proteinosis (aPAP). Their lead product candidate, MOLBREEVI (molgramostim inhalation solution), is an inhaled recombinant GM-CSF currently in Phase 3 development for aPAP; the company maintains clinical programs, medical affairs, patient resources, and investor relations activities related to advancing this therapy. Savara conducts clinical trials, engages with investigators and patient advocacy organizations, and provides information on diagnostics, expanded access, and regulatory status.

πŸ“‹ Description

β€’ Own and mature Savara's global privacy program, serving as the primary in-house legal advisor on GDPR, UK GDPR, and applicable U.S. federal and state privacy laws, and as the escalation point for privacy questions raised by any function β€’ Oversee and conduct enterprise-wide Data Protection Impact Assessments (DPIAs), partner with the external Data Protection Officer to build and maintain Records of Processing Activities (ROPAs) across all functional areas, and support audits and regulatory requests β€’ Draft, implement, and periodically refresh Savara's core privacy policies and procedures, ensuring internal consistency (e.g., aligned breach-notification timelines) and alignment with current law β€’ Own the end-to-end data subject/consumer rights program (access, rectification, erasure, restriction, portability, opt-out, and 'limit the use of sensitive personal information' requests), including intake channels, identity verification, statutory deadline tracking, and coordination with processors and vendors β€’ Build and maintain a vendor privacy compliance program: a central vendor register, a risk-based due diligence and questionnaire process, and a Data Processing Agreement (and, where applicable, Business Associate Agreement) portfolio with all critical and non-critical processors, prioritizing vendors that process special-category or patient data β€’ Review and negotiate privacy and data protection terms in contracts, including data processing agreements (DPAs), clinical trial agreements, master services agreements, vendor agreements, standard contractual clauses (SCCs), and related provisions, and ensure consistent and appropriate privacy language across all contractual forms and third-party engagements β€’ Evaluate and document controller, joint-controller, and processor relationships across Savara's business (HR employer-of-record arrangements, clinical trial sites and CROs, patient advocacy and expanded access partners, and commercial media/analytics partners) and put in place Article 26-compliant joint-controller arrangements where needed β€’ Map Savara's cross-border data transfer flows and implement appropriate transfer mechanisms (Standard Contractual Clauses, UK IDTA/Addendum, or successor mechanisms), including Transfer Impact Assessments and supplementary measures where required, and lead remediation of any legacy or outdated transfer documentation β€’ Serve as the business owner for Savara's incident and breach response program, ensuring a single, internally consistent breach-notification procedure that meets GDPR/UK GDPR, HIPAA, FTC, and applicable state-law timelines, and personally leading or co-leading breach investigations and regulator/notification decisions β€’ Advise Clinical Operations and Pharmacovigilance on privacy aspects of sponsored trials, expanded access/named-patient programs, and safety data flows, including legal basis, informed consent form privacy language, investigator and site-staff transparency notices, and vendor/CRO data flows β€’ Advise Commercial, Marketing, and Patient Services on privacy-by-design for HCP and patient-facing digital properties, hub and patient-support programs, CRM/analytics platforms, and any real-world-data or de-identification initiatives, including cookie consent, ad-tech governance, and state consumer health data laws β€’ Own Savara's readiness for HCP transfers-of-value reporting (Sunshine Act/Open Payments) from a privacy perspective, working with Finance, Compliance, and Commercial to ensure appropriate notices and data-handling practices are in place ahead of go-live β€’ Design and roll out a role-based data protection training and awareness program for all employees and contractors aligned with compliance initiatives, with tailored modules as needed, and track completion β€’ Coordinate with IT/the Managed Service Provider on privacy-relevant security controls (access management, encryption, data classification, and vendor contracts) to ensure technical and organizational measures are documented and defensible β€’ Track and advise on emerging and evolving privacy obligations relevant to Savara's operations, including new U.S. state privacy laws, evolving FTC and state enforcement priorities, and cross-border transfer developments, and periodically refresh Savara's data protection gap analysis and the associated remediation roadmap β€’ Prepare periodic privacy program metrics and status updates (open data subject requests, breach notifications, vendor compliance status, training completion, DPIA/ROPA coverage) for the Chief Legal Officer and, as appropriate, the Audit Committee of the Board of Directors β€’ Promote a culture of privacy, ethics, and accountability across all geographies β€’ Manage contractors, vendors, and/or outside counsel engaged to support the privacy program β€’ Other duties and projects as assigned.

🎯 Requirements

β€’ Juris Doctor (JD) from an accredited law school β€’ Admission to a state bar and active license to practice law β€’ Minimum of 8 years of relevant legal experience, with substantial hands-on experience building or operating a privacy program, preferably in-house at a life sciences, pharmaceutical, or biotechnology company, or in a law firm or consultancy advising such companies β€’ Deep working knowledge of GDPR and UK GDPR, including practical experience with Records of Processing Activities, DPIAs, cross-border transfer mechanisms, and data subject rights programs β€’ Strong working knowledge of the U.S. privacy landscape applicable to biopharmaceutical companies, including HIPAA, the FTC Act and Health Breach Notification Rule, and state comprehensive and consumer-health privacy laws (e.g., CCPA/CPRA, Washington MHMDA, Connecticut CTDPA, Nevada SB 370) β€’ Familiarity with clinical trial and pharmacovigilance data flows and applicable regulatory frameworks (ICH-GCP, EU Clinical Trials Regulation, FDA regulations), and with life sciences transparency reporting (Sunshine Act/Open Payments) β€’ Privacy certification(s) such as CIPP/E and/or CIPP/US strongly preferred β€’ Demonstrated ability to translate legal requirements into practical, risk-based operational programs and to drive cross-functional remediation work to completion, rather than only identifying gaps β€’ Excellent verbal and written communication skills, with the ability to communicate clearly and persuasively with both technical and non-technical stakeholders and with professionals outside the organization β€’ Strong project-management skills, with the ability to build and drive a multi-year remediation roadmap and to prioritize across competing demands β€’ Proactive, self-directed, and comfortable operating with a high degree of ownership and minimal supervision in a lean, fast-moving organization β€’ Excellent professional judgment, high level of integrity and trustworthiness, and the ability to build collaborative working relationships across all levels of the organization β€’ Adaptable and able to pivot to meet changing business needs as Savara transitions from clinical-stage to commercial-stage operations.

πŸ–οΈ Benefits

β€’ Highly competitive medical, dental, and vision coverage β€’ Flexible Spending Accounts for health care and dependent care expenses β€’ Paid time off and paid holidays, including Dec 24-Jan 1 β€’ Paid parental leave β€’ 401k with highly competitive match β€’ Life, AD&D, STD and LTD insurance coverage

Apply Now

Similar Jobs

πŸ•’ 6 days ago

MNF Global - Legal Recruiter

1 - 10

🎯 Recruiter

βš–οΈ Legal

🀝 B2B

Seeking a Patent Attorney or Patent Agent with semiconductor experience for top-tier law firm. Role involves client interaction, patent application drafting, and USPTO responses.

πŸ•’ 6 days ago

Allstate

10,000+ employees

πŸ’Ό Consulting

πŸ“¦ Logistics

πŸ›‘οΈ Insurance

Claims Adjuster for the Allstate Corporation investigating complex auto claims. Managing coverage, liability, and mentoring junior employees in a fast‑paced environment.

πŸ•’ 6 days ago

Modern Family Law

51 - 200

πŸ’Ό Consulting

πŸ₯ Healthcare

βš–οΈ Legal

Legal Knowledge Engineer working on AI-native legal service delivery systems at Modern Family Law. Collaborating with attorneys to translate legal expertise into AI-enabled frameworks.

πŸ•’ 6 days ago

Modern Family Law

51 - 200

πŸ’Ό Consulting

πŸ₯ Healthcare

βš–οΈ Legal

Legal Knowledge Engineer at Modern Family Law designing AI-native legal systems. Collaborating with teams to transform legal expertise into scalable AI-enabled frameworks.

πŸ•’ 6 days ago

Modern Family Law

51 - 200

πŸ’Ό Consulting

πŸ₯ Healthcare

βš–οΈ Legal

Legal Knowledge Engineer at Modern Family Law designing AI-native legal service delivery systems. Collaborating with attorneys and product teams to integrate legal workflows into AI frameworks.