Public Health Institute
Oakland, California
Director of Software Development for Oncology Data Platform Posting Number: 2144 Closing Date: Until Filled Location: Remote, USA The Public Health Institute (PHI) is an independent, nonprofit organization dedicated to promoting health, well-being, and quality of life for people throughout California, across the nation and around the world. As one of the largest and most comprehensive public health organizations in the nation, we are at the forefront of research and innovations to improve the efficacy of public health statewide, nationally, and internationally. PHI was distinguished as one of the top 50 "Best Non-Profit Organizations to Work For" by the Non-Profit Times in a national search. POSITION SUMMARY C/NET Solutions CNExT Cancer Registry software is used by Cancer Registrars for meeting mandated cancer reporting as well as analysis of the cancer population at their medical center. Together with our Cancer Alert System, efficiency in identifying and reporting of cancer is realized. We meet HIPAA and security regulations and allow remote access. All C/NET Solutions software can be run in mixed technology environments where the highest standards in database security or remote access are required. The Director of Software Development for Oncology Data Platform (Director) will spearhead the strategic transformation of our software offerings, leading the design and development of our next-generation cloud-based oncology data platform (Project Aither / CNExT Cloud) that will replace our legacy system. This critical position combines product vision, technical leadership, and change management to guide our team through this significant transition while delivering innovative, AI-embedded solutions that help researchers and clinicians advance cancer treatment through data-driven insights. Additionally, this position will manage the ongoing development, implementation, and support of our current hospital registry software (CNExT) and cancer case ascertainment (CAS) product. The Director will ensure that our existing products are updated at least annually as we provide continued support to our legacy product. This position will report to the Program Director. This is a remote, regular full-time position with a work schedule of 40 hours per week. The incumbent must be able to work during core business hours for the Pacific Time zone and occasionally work more than 40 hours a week and on weekends. Candidates in the United States (all Time Zones) are welcome to apply. Full salary range for this position: $123,149 to $188,879 per year. The typical hiring range for this position is from $123,149 (minimum) to $156,014 (midpoint), based on 100% FTE. The starting salary is determined using a variety of factors, such as the candidate's knowledge, skills, and experience, as well as internal equity consideration and budget availability. Employment Type: Full Time ESSENTIAL DUTIES & RESPONSIBILITIES include the following: Lead development of next-generation product (Project Aither - CNExT Cloud) Serve as the technical and strategic lead for Project Aither, C/NET Solutions' initiative to build CNExT Cloud - a next-generation, AI-embedded, cloud-native SaaS cancer registry platform that will replace the current legacy on-premises system. The Director is responsible for translating the product vision into a structured engineer executable plan and driving delivery through a 24-month phased development plan. Product Strategy & Roadmap Own and execute the end-to-end product strategy for CNExT Cloud, covering both back-end and front-end development. Define and maintain the product execution roadmap, sprint plan, and feature backlog informed by competitive gap analysis, SME validation, and SME & customer inputs. Drive requirements gathering by engaging internal subject matter experts, cancer registrar users, and external stakeholders to validate feature priorities and document workflows before sprint planning begins. Protect and carry forward CNExT's competitive strengths, including SmartHelp, User-Defined Fields, CAS efficiency gains, and MP/H decision support into the new platform. Cloud Architecture & Technical Leadership Architect and oversee the development of a cloud-native, multi-tenant SaaS platform built on containerized microservices (Azure/AWS/GCP), with Kubernetes orchestration, CI/CD pipeline, and full DevOps fabric. Lead the design and implementation of a browser-based React SPA replacing the legacy Windows client, with WCAG 2.1 AA accessibility, role-based dashboards, and modern UX. Oversee the building of a FHIR R4 / HL7 API Gateway to enable EHR connectivity, real-time ADT and lab result feeds, and EHR writeback, eliminating the need for manual data imports. Ensure multi-tenant data isolation, self-serve onboarding, SSO configuration, per-tenant billing, and RBAC are built to enterprise standards from the outset. Lead Architecture Decision Records (ADRs) through formal approval with PHI InfoSec, ensuring HIPAA controls, AES-256 encryption, audit logging, and RBAC design are verified prior to development. AI & Machine Learning Capabilities Lead integration of AI auto-abstraction capabilities using NLP and large language model (LLM) engines to pre-populate NAACCR fields from pathology reports and clinical notes, with a human-in-the-loop registrar review and approval workflow. Oversee development of an ML-powered smart case-finding engine that scans ADT feeds, lab results, and pathology data with >90% confidence to surface cases registrars might otherwise miss. Manage strategic technology vendor evaluations and partnerships (e.g., EHR API connectivity, clinical NLP providers) to accelerate platform capability without building from scratch. Manage AI data partnership initiatives - such as the City of Hope collaboration, including data governance, IRB compliance, de-identification protocols, and AI training pipeline setup. Regulatory Compliance & Quality Ensure CNExT Cloud maintains full compliance with NAACCR v23+, CoC accreditation requirements, SEER, AJCC 8th Edition, NPCR, and all-50-state reporting standards. Establish coding standards, best practices, CI/CD pipelines, and automated testing workflows aligned to the new platform architecture. Conduct code reviews and provide technical guidance to a team of 3-5 programmer analysts, ensuring high-quality deliverables at each phase milestone. Change Management & Stakeholder Engagement Create and execute change management strategies to guide the programming team and broader organization through the transition from the legacy on-premises product to a cloud SaaS model. Serve as the primary technical liaison between programming teams, executive stakeholders, and external partners throughout the project lifecycle. Manage project timelines and resource allocation across all development phases, ensuring milestone delivery and proactive risk management. Provide regular communication and transparency to C/NET staff on Project Aither status, decisions, and next steps through structured staff update forums. Manage all CNET and CAS application planning, analysis, design, implementation, and documentation (testing and technical) effort Analyze annual changes to NAACCR volume II data sets and state collection requirements to design and execute updates to CNET software products. Supervise the programming staff as they implement new program code and customize the CNET applications with appropriate prioritization of resources. Ensure all testing instructions and technical documentation are maintained and updated according to industry best practices. Assist whenever necessary by personally performing programming tasks at any level. Lead the Change Control meeting series and ad hoc planning processes to determine the content and timing of releases. Work with both the Special Projects and Support teams to analyze and design both user- and technology-directed changes to CAS. Supervise the programming staff as they perform further analysis and design of meeting those requirements; implement new program code and customize the CAS application as necessary. Manage second-level help desk support assistance Assist, or assign resources to assist, with support issues escalated through the help desk escalation process. Answer, or direct resources to answer, product questions as needed without regard to the underlying issues' escalation status. Maintain communication with Support manager to effectively coordinate effort. Additional Responsibilities Actively participate in management, advisory, and user processes and meetings to determine the current and future direction of the C/Net Solutions program. Act as mentor to programming staff and ensure that programming staff are fairly treated, assignments given are diverse and challenging, and opportunities for growth are presented. Perform other duties as assigned. QUALIFICATIONS To perform this job successfully, an individual must be able to perform each essential duty satisfactorily. The requirements listed below are representative of the knowledge, skill, and/or ability required. Minimum Qualifications 7 years of related experience in the Health Information Technology field, including at least 3 years as a manager . click apply for full job details
Director of Software Development for Oncology Data Platform Posting Number: 2144 Closing Date: Until Filled Location: Remote, USA The Public Health Institute (PHI) is an independent, nonprofit organization dedicated to promoting health, well-being, and quality of life for people throughout California, across the nation and around the world. As one of the largest and most comprehensive public health organizations in the nation, we are at the forefront of research and innovations to improve the efficacy of public health statewide, nationally, and internationally. PHI was distinguished as one of the top 50 "Best Non-Profit Organizations to Work For" by the Non-Profit Times in a national search. POSITION SUMMARY C/NET Solutions CNExT Cancer Registry software is used by Cancer Registrars for meeting mandated cancer reporting as well as analysis of the cancer population at their medical center. Together with our Cancer Alert System, efficiency in identifying and reporting of cancer is realized. We meet HIPAA and security regulations and allow remote access. All C/NET Solutions software can be run in mixed technology environments where the highest standards in database security or remote access are required. The Director of Software Development for Oncology Data Platform (Director) will spearhead the strategic transformation of our software offerings, leading the design and development of our next-generation cloud-based oncology data platform (Project Aither / CNExT Cloud) that will replace our legacy system. This critical position combines product vision, technical leadership, and change management to guide our team through this significant transition while delivering innovative, AI-embedded solutions that help researchers and clinicians advance cancer treatment through data-driven insights. Additionally, this position will manage the ongoing development, implementation, and support of our current hospital registry software (CNExT) and cancer case ascertainment (CAS) product. The Director will ensure that our existing products are updated at least annually as we provide continued support to our legacy product. This position will report to the Program Director. This is a remote, regular full-time position with a work schedule of 40 hours per week. The incumbent must be able to work during core business hours for the Pacific Time zone and occasionally work more than 40 hours a week and on weekends. Candidates in the United States (all Time Zones) are welcome to apply. Full salary range for this position: $123,149 to $188,879 per year. The typical hiring range for this position is from $123,149 (minimum) to $156,014 (midpoint), based on 100% FTE. The starting salary is determined using a variety of factors, such as the candidate's knowledge, skills, and experience, as well as internal equity consideration and budget availability. Employment Type: Full Time ESSENTIAL DUTIES & RESPONSIBILITIES include the following: Lead development of next-generation product (Project Aither - CNExT Cloud) Serve as the technical and strategic lead for Project Aither, C/NET Solutions' initiative to build CNExT Cloud - a next-generation, AI-embedded, cloud-native SaaS cancer registry platform that will replace the current legacy on-premises system. The Director is responsible for translating the product vision into a structured engineer executable plan and driving delivery through a 24-month phased development plan. Product Strategy & Roadmap Own and execute the end-to-end product strategy for CNExT Cloud, covering both back-end and front-end development. Define and maintain the product execution roadmap, sprint plan, and feature backlog informed by competitive gap analysis, SME validation, and SME & customer inputs. Drive requirements gathering by engaging internal subject matter experts, cancer registrar users, and external stakeholders to validate feature priorities and document workflows before sprint planning begins. Protect and carry forward CNExT's competitive strengths, including SmartHelp, User-Defined Fields, CAS efficiency gains, and MP/H decision support into the new platform. Cloud Architecture & Technical Leadership Architect and oversee the development of a cloud-native, multi-tenant SaaS platform built on containerized microservices (Azure/AWS/GCP), with Kubernetes orchestration, CI/CD pipeline, and full DevOps fabric. Lead the design and implementation of a browser-based React SPA replacing the legacy Windows client, with WCAG 2.1 AA accessibility, role-based dashboards, and modern UX. Oversee the building of a FHIR R4 / HL7 API Gateway to enable EHR connectivity, real-time ADT and lab result feeds, and EHR writeback, eliminating the need for manual data imports. Ensure multi-tenant data isolation, self-serve onboarding, SSO configuration, per-tenant billing, and RBAC are built to enterprise standards from the outset. Lead Architecture Decision Records (ADRs) through formal approval with PHI InfoSec, ensuring HIPAA controls, AES-256 encryption, audit logging, and RBAC design are verified prior to development. AI & Machine Learning Capabilities Lead integration of AI auto-abstraction capabilities using NLP and large language model (LLM) engines to pre-populate NAACCR fields from pathology reports and clinical notes, with a human-in-the-loop registrar review and approval workflow. Oversee development of an ML-powered smart case-finding engine that scans ADT feeds, lab results, and pathology data with >90% confidence to surface cases registrars might otherwise miss. Manage strategic technology vendor evaluations and partnerships (e.g., EHR API connectivity, clinical NLP providers) to accelerate platform capability without building from scratch. Manage AI data partnership initiatives - such as the City of Hope collaboration, including data governance, IRB compliance, de-identification protocols, and AI training pipeline setup. Regulatory Compliance & Quality Ensure CNExT Cloud maintains full compliance with NAACCR v23+, CoC accreditation requirements, SEER, AJCC 8th Edition, NPCR, and all-50-state reporting standards. Establish coding standards, best practices, CI/CD pipelines, and automated testing workflows aligned to the new platform architecture. Conduct code reviews and provide technical guidance to a team of 3-5 programmer analysts, ensuring high-quality deliverables at each phase milestone. Change Management & Stakeholder Engagement Create and execute change management strategies to guide the programming team and broader organization through the transition from the legacy on-premises product to a cloud SaaS model. Serve as the primary technical liaison between programming teams, executive stakeholders, and external partners throughout the project lifecycle. Manage project timelines and resource allocation across all development phases, ensuring milestone delivery and proactive risk management. Provide regular communication and transparency to C/NET staff on Project Aither status, decisions, and next steps through structured staff update forums. Manage all CNET and CAS application planning, analysis, design, implementation, and documentation (testing and technical) effort Analyze annual changes to NAACCR volume II data sets and state collection requirements to design and execute updates to CNET software products. Supervise the programming staff as they implement new program code and customize the CNET applications with appropriate prioritization of resources. Ensure all testing instructions and technical documentation are maintained and updated according to industry best practices. Assist whenever necessary by personally performing programming tasks at any level. Lead the Change Control meeting series and ad hoc planning processes to determine the content and timing of releases. Work with both the Special Projects and Support teams to analyze and design both user- and technology-directed changes to CAS. Supervise the programming staff as they perform further analysis and design of meeting those requirements; implement new program code and customize the CAS application as necessary. Manage second-level help desk support assistance Assist, or assign resources to assist, with support issues escalated through the help desk escalation process. Answer, or direct resources to answer, product questions as needed without regard to the underlying issues' escalation status. Maintain communication with Support manager to effectively coordinate effort. Additional Responsibilities Actively participate in management, advisory, and user processes and meetings to determine the current and future direction of the C/Net Solutions program. Act as mentor to programming staff and ensure that programming staff are fairly treated, assignments given are diverse and challenging, and opportunities for growth are presented. Perform other duties as assigned. QUALIFICATIONS To perform this job successfully, an individual must be able to perform each essential duty satisfactorily. The requirements listed below are representative of the knowledge, skill, and/or ability required. Minimum Qualifications 7 years of related experience in the Health Information Technology field, including at least 3 years as a manager . click apply for full job details
A.O. Smith
Nashville, Tennessee
Company / Location Information A.O. Smith is a global leader applying innovative technologies and energy-efficient solutions to products manufactured and marketed worldwide. The company is one of the world's leading manufacturers of residential and commercial water heating equipment and boilers, as well as a manufacturer of water treatment products for residential and light commercial applications. A. O. Smith is headquartered in Milwaukee, Wisconsin, with approximately 12,000 employees at operations in the United States, Canada, China, India, Mexico, the Netherlands, and the United Kingdom. Please Note : At this time, we are unable to provide visa sponsorship for this role. Candidates must be authorized to work in the United States without sponsorship now or in the future. Primary Function As a Senior Manager, IT Regulatory Compliance, you will be a member of the Business Technology Solutions (IT) leadership team, reporting directly to the CISO. The team is responsible for proactively planning and executing focused strategies to establish and maintain operational, financial, and regulatory controls globally. The Senior Manager, IT Regulatory Compliance leads the company's second-line oversight of technology risk, controls, and regulatory compliance. This role has primary accountability for SOX IT compliance (ITGCs/ITACs/SoD), global IT control standardization/governance, and enterprise alignment with industry cybersecurity frameworks (e.g., NIST, COSO). In addition, this position helps shape and drive the technology and security aspects of global privacy and data protection compliance programs (e.g., GDPR, India's DPDP Act, China's PIPL, CCPA/CPRA, and other applicable regional regulations), partnering closely with Legal/Privacy, Information Security, IT, Finance/Controllership, Internal Audit, and global business leaders. Success in the role means ensuring technology and data risks are appropriately identified, controlled, and monitored across the enterprise-covering ERP platforms (SAP), supporting financial applications, infrastructure, hosted/cloud environments, third parties, and new system implementations-while enabling compliant handling of personal data. As Senior Manager, you will set the vision and roadmap for scalable controls and governance, drive audit and regulatory readiness, and act as a thought leader who influences stakeholders and delivers measurable program outcomes. Responsibilities SPECIFIC DUTIES/ACCOUNTABILITIES Thought Leadership and Executive Influence - Serve as a visible thought leader for technology risk and regulatory compliance, translating evolving requirements into practical strategy, roadmaps, and decisions. Communicate risk posture, control health, key issues, and program outcomes to the CISO and senior leadership with clear, business-focused insights. Program Governance, Metrics, and Continuous Improvement - Promote a culture of accountability, transparency, and continuous improvement. Define and monitor program KPIs/KRIs (e.g., control effectiveness, remediation aging, regulatory obligations tracking), identify trends and emerging risks, and drive control optimization and automation initiatives. Lead 2nd-Line SOX IT Compliance Oversight - Own governance and oversight of SOX, ensuring compliance with ICFR requirements and consistent execution across ERPs and supporting technologies (e.g., ITGCs, ITACs, SoD), including control design standards, evidence quality, and remediation governance. Establish and Maintain Global Technology and Privacy Control Standards - Design, standardize, and maintain global control frameworks and evidence standards spanning IT controls (SOX/ICFR) and technology-enabled privacy requirements (e.g., access, logging, encryption, retention/deletion, third-party controls) to drive consistency, scalability, and audit/regulatory readiness across regions and systems. Align Controls with Leading Frameworks and Regulatory Requirements - Partner closely with Information Security and Legal/Privacy leadership to ensure alignment with applicable frameworks and regulations (e.g., NIST, COSO, ISO 27001/27701 as applicable, GDPR, India DPDP, China PIPL, CCPA/CPRA), and translate obligations into clear, testable control requirements. Security-by-Design Oversight across SDLC and Implementations - Provide 2nd line oversight across SDLC phases and major system implementations ensuring controls are designed and executed to appropriately mitigate risk, procedures are executed in alignment with internal policies, and security and privacy requirements are appropriately embedded. Serve as Primary Audit and Regulatory Liaison (Technology Controls) - Serve as a key technology risk and compliance contact for Internal Audit, external auditors, and (as applicable) regulatory inquiries related to technology controls and technology-enabled privacy requirements. Partner with Internal Audit to ensure audits and SOX procedures are planned, performed, and executed timely. Support consistent effective control execution and provide ongoing training to foster an effective environment and enhance efficiency. Drive Issue Management and Remediation - Assess control deficiencies and compliance findings, govern and drive the identification, root cause analysis, risk acceptance/escalation, and remediation action plan development by partnering with control owners and operations teams. Global Regulatory Compliance Enablement (Privacy and Technology) - Partner with Legal/Privacy, PMOs, IT Infrastructure, Security and IT leadership to drive compliance with internal policies, technology standards, and applicable privacy regulations. Enable consistent operational execution of privacy requirements through governance mechanisms (e.g., records of processing support, data retention/deletion controls, DSAR enablement inputs, vendor/third-party privacy risk oversight, and incident/breach response coordination inputs), and develop assurance procedures to validate ongoing compliance. Qualifications Bachelor's degree in Business Administration, Management Information Systems, Computer Science, Cybersecurity, Accounting or a related field; MS or MBA is preferred. CISA or the ability to obtain within a year is required; additional professional certifications are preferred, such as CISM, CISSP, CIA, CPA, and privacy certifications (e.g., IAPP CIPP/E, CIPP/US, CIPM) 8-12+ years of progressive experience in technology risk, IT audit, IT compliance, technology controls, and/or privacy risk and regulatory compliance within complex, global organizations (public accounting and/or global manufacturing preferred) Deep expertise in COSO and NIST frameworks (and familiarity with privacy/security standards such as ISO 27001/27701 and common privacy control concepts), including performing audit procedures against standards or assessing and implementing controls Strong knowledge of IT general and automated controls, ICFR concepts, and control design/testing, plus the ability to translate privacy regulatory obligations (e.g., GDPR, DPDP, PIPL, CCPA/CPRA) into practical, testable technology and process controls Prior experience with SAP (ECC, BW, GRC, ECP, S/4HANA) and understanding configuration and best practices Demonstrated experience supporting or overseeing SDLC activities and system implementations Experience evaluating third-party service providers SOC reports Experience with control automation, continuous controls monitoring, and continuous improvement Proven ability to operate effectively in a global, matrixed organization Effective and impactful executive-level communication and presentation skills; able to influence outcomes and drive decisions across IT, Security, Legal/Privacy, Finance, and the business Strong judgment and risk prioritization capabilities Ability to influence without authority Pragmatic, business-oriented approach to compliance Continuous improvement mindset ADDITIONAL QUALIFICIATIONS: Exposure to hosted environments, cloud platforms, and experience assessing cloud migration risks (including privacy, residency, and third-party data processing considerations) is a plus Exposure to GRC applications, IAM solutions and Audit tools is preferred Experience building or operating elements of a privacy compliance program (e.g., privacy risk assessments/DPIAs, records of processing, vendor/third-party risk, data retention/deletion governance, and support for DSAR processes) is a plus Proven management experience leading high-performing teams with global responsibilities Experience presenting to executive leadership and audit committees is a plus We Offer Competitive compensation package and comprehensive benefits plans which include medical and dental insurance, company-sponsored life insurance, retirement security savings plan, short- and long-term disability programs and tuition assistance. ADA Statement & EEO Statement In developing this job description care was taken to include all competencies needed to successfully perform in this position. However, for Americans with Disabilities Act (ADA) purposes, the essential functions of the job may or may not have been described for purposes of ADA reasonable accommodation. All reasonable accommodation requests will be reviewed and evaluated on a case-by-case basis. . click apply for full job details
Company / Location Information A.O. Smith is a global leader applying innovative technologies and energy-efficient solutions to products manufactured and marketed worldwide. The company is one of the world's leading manufacturers of residential and commercial water heating equipment and boilers, as well as a manufacturer of water treatment products for residential and light commercial applications. A. O. Smith is headquartered in Milwaukee, Wisconsin, with approximately 12,000 employees at operations in the United States, Canada, China, India, Mexico, the Netherlands, and the United Kingdom. Please Note : At this time, we are unable to provide visa sponsorship for this role. Candidates must be authorized to work in the United States without sponsorship now or in the future. Primary Function As a Senior Manager, IT Regulatory Compliance, you will be a member of the Business Technology Solutions (IT) leadership team, reporting directly to the CISO. The team is responsible for proactively planning and executing focused strategies to establish and maintain operational, financial, and regulatory controls globally. The Senior Manager, IT Regulatory Compliance leads the company's second-line oversight of technology risk, controls, and regulatory compliance. This role has primary accountability for SOX IT compliance (ITGCs/ITACs/SoD), global IT control standardization/governance, and enterprise alignment with industry cybersecurity frameworks (e.g., NIST, COSO). In addition, this position helps shape and drive the technology and security aspects of global privacy and data protection compliance programs (e.g., GDPR, India's DPDP Act, China's PIPL, CCPA/CPRA, and other applicable regional regulations), partnering closely with Legal/Privacy, Information Security, IT, Finance/Controllership, Internal Audit, and global business leaders. Success in the role means ensuring technology and data risks are appropriately identified, controlled, and monitored across the enterprise-covering ERP platforms (SAP), supporting financial applications, infrastructure, hosted/cloud environments, third parties, and new system implementations-while enabling compliant handling of personal data. As Senior Manager, you will set the vision and roadmap for scalable controls and governance, drive audit and regulatory readiness, and act as a thought leader who influences stakeholders and delivers measurable program outcomes. Responsibilities SPECIFIC DUTIES/ACCOUNTABILITIES Thought Leadership and Executive Influence - Serve as a visible thought leader for technology risk and regulatory compliance, translating evolving requirements into practical strategy, roadmaps, and decisions. Communicate risk posture, control health, key issues, and program outcomes to the CISO and senior leadership with clear, business-focused insights. Program Governance, Metrics, and Continuous Improvement - Promote a culture of accountability, transparency, and continuous improvement. Define and monitor program KPIs/KRIs (e.g., control effectiveness, remediation aging, regulatory obligations tracking), identify trends and emerging risks, and drive control optimization and automation initiatives. Lead 2nd-Line SOX IT Compliance Oversight - Own governance and oversight of SOX, ensuring compliance with ICFR requirements and consistent execution across ERPs and supporting technologies (e.g., ITGCs, ITACs, SoD), including control design standards, evidence quality, and remediation governance. Establish and Maintain Global Technology and Privacy Control Standards - Design, standardize, and maintain global control frameworks and evidence standards spanning IT controls (SOX/ICFR) and technology-enabled privacy requirements (e.g., access, logging, encryption, retention/deletion, third-party controls) to drive consistency, scalability, and audit/regulatory readiness across regions and systems. Align Controls with Leading Frameworks and Regulatory Requirements - Partner closely with Information Security and Legal/Privacy leadership to ensure alignment with applicable frameworks and regulations (e.g., NIST, COSO, ISO 27001/27701 as applicable, GDPR, India DPDP, China PIPL, CCPA/CPRA), and translate obligations into clear, testable control requirements. Security-by-Design Oversight across SDLC and Implementations - Provide 2nd line oversight across SDLC phases and major system implementations ensuring controls are designed and executed to appropriately mitigate risk, procedures are executed in alignment with internal policies, and security and privacy requirements are appropriately embedded. Serve as Primary Audit and Regulatory Liaison (Technology Controls) - Serve as a key technology risk and compliance contact for Internal Audit, external auditors, and (as applicable) regulatory inquiries related to technology controls and technology-enabled privacy requirements. Partner with Internal Audit to ensure audits and SOX procedures are planned, performed, and executed timely. Support consistent effective control execution and provide ongoing training to foster an effective environment and enhance efficiency. Drive Issue Management and Remediation - Assess control deficiencies and compliance findings, govern and drive the identification, root cause analysis, risk acceptance/escalation, and remediation action plan development by partnering with control owners and operations teams. Global Regulatory Compliance Enablement (Privacy and Technology) - Partner with Legal/Privacy, PMOs, IT Infrastructure, Security and IT leadership to drive compliance with internal policies, technology standards, and applicable privacy regulations. Enable consistent operational execution of privacy requirements through governance mechanisms (e.g., records of processing support, data retention/deletion controls, DSAR enablement inputs, vendor/third-party privacy risk oversight, and incident/breach response coordination inputs), and develop assurance procedures to validate ongoing compliance. Qualifications Bachelor's degree in Business Administration, Management Information Systems, Computer Science, Cybersecurity, Accounting or a related field; MS or MBA is preferred. CISA or the ability to obtain within a year is required; additional professional certifications are preferred, such as CISM, CISSP, CIA, CPA, and privacy certifications (e.g., IAPP CIPP/E, CIPP/US, CIPM) 8-12+ years of progressive experience in technology risk, IT audit, IT compliance, technology controls, and/or privacy risk and regulatory compliance within complex, global organizations (public accounting and/or global manufacturing preferred) Deep expertise in COSO and NIST frameworks (and familiarity with privacy/security standards such as ISO 27001/27701 and common privacy control concepts), including performing audit procedures against standards or assessing and implementing controls Strong knowledge of IT general and automated controls, ICFR concepts, and control design/testing, plus the ability to translate privacy regulatory obligations (e.g., GDPR, DPDP, PIPL, CCPA/CPRA) into practical, testable technology and process controls Prior experience with SAP (ECC, BW, GRC, ECP, S/4HANA) and understanding configuration and best practices Demonstrated experience supporting or overseeing SDLC activities and system implementations Experience evaluating third-party service providers SOC reports Experience with control automation, continuous controls monitoring, and continuous improvement Proven ability to operate effectively in a global, matrixed organization Effective and impactful executive-level communication and presentation skills; able to influence outcomes and drive decisions across IT, Security, Legal/Privacy, Finance, and the business Strong judgment and risk prioritization capabilities Ability to influence without authority Pragmatic, business-oriented approach to compliance Continuous improvement mindset ADDITIONAL QUALIFICIATIONS: Exposure to hosted environments, cloud platforms, and experience assessing cloud migration risks (including privacy, residency, and third-party data processing considerations) is a plus Exposure to GRC applications, IAM solutions and Audit tools is preferred Experience building or operating elements of a privacy compliance program (e.g., privacy risk assessments/DPIAs, records of processing, vendor/third-party risk, data retention/deletion governance, and support for DSAR processes) is a plus Proven management experience leading high-performing teams with global responsibilities Experience presenting to executive leadership and audit committees is a plus We Offer Competitive compensation package and comprehensive benefits plans which include medical and dental insurance, company-sponsored life insurance, retirement security savings plan, short- and long-term disability programs and tuition assistance. ADA Statement & EEO Statement In developing this job description care was taken to include all competencies needed to successfully perform in this position. However, for Americans with Disabilities Act (ADA) purposes, the essential functions of the job may or may not have been described for purposes of ADA reasonable accommodation. All reasonable accommodation requests will be reviewed and evaluated on a case-by-case basis. . click apply for full job details