Consulting and technology- enabled by cloud, guided by data, fueled by apps, and secured by design.
L3 SOC Analyst, Incident Response Analyst
Location
Costa Rica
Posted
2 days ago
Salary
0
Seniority
Senior
Job Description
L3 SOC Analyst, Incident Response Analyst
ProArch
**About ProArch:** At ProArch, we partner with businesses around the world to turn big ideas into better outcomes through IT services that span cybersecurity, cloud, data, AI, and app development. We’re 400+ team members strong across 3 countries (we call ourselves ProArchians)—and here’s what connects us all: - A love for solving real business problems - A belief in doing what’s right **What’s it like to work here?** - You’ll keep growing. You’ll work alongside domain experts who love to share what they know. - You’ll be supported, heard, and trusted to make an impact. - You’ll take on projects that touch industries, communities, and lives. - You’ll have the time to focus on what matters most in your life outside of work. At ProArch, you’ll be part of teams that design and deliver technology solutions solving real business challenges for our clients. With services spanning AI, Data, Application Development, Cybersecurity, Cloud & Infrastructure, and Industry Solutions, your work may involve building intelligent applications, securing business‑critical systems, or supporting cloud migrations and infrastructure modernization. Every role here contributes to shaping outcomes for global clients and driving meaningful impact. You’ll collaborate with experts across data, AI, engineering, cloud, cybersecurity, and infrastructure—solving complex problems with creativity, precision, and purpose. You’ll join a culture rooted in technology, curiosity, and continuous learning. A place where we move fast, trust you to make an impact, encourage innovation, and support your growth. **About Position:** At ProArch, a leader in IT security consulting with presence in the US, UK, and India, we are looking for a skilled L3 SOC Analyst / Incident Response Analyst to join our Security Operations Center (SOC) team. In this critical role, you will be responsible for advanced incident detection, investigation, and response to complex cybersecurity threats. Leveraging your extensive experience and expertise, you will lead incident response activities, perform deep-dive analysis, and coordinate with cross-functional teams to mitigate risks and strengthen our security posture. If you thrive in a dynamic, fast-paced environment and are passionate about defending organizations against sophisticated cyber threats, this position is ideal for you.Role Summary ProArch are seeking a highly skilled and technically strong L3 SOC Analyst / Incident Response Analyst to operate within a Managed Security Services Provider (MSSP) environment, supporting multiple customer environments across diverse industries. **This role is heavily focused on:** - Incident Response - Threat Investigation - Detection Engineering - DFIR Operations - SOC Automation - Threat Hunting - Security Platform Engineering - Response Workflow Optimization The ideal candidate combines strong incident response expertise, deep Microsoft security platform knowledge, hands-on detection engineering capability, and SOC automation experience within a fast-paced MSSP environment. This is not a traditional alert-monitoring SOC Analyst role. The position requires strong investigative, analytical, and response-oriented cybersecurity capabilities. **Key Responsibilities** **1. Incident Response & Threat Investigation** • Lead and support advanced security incident investigations across multiple customer environments **Perform:** - Threat triage and validation - IOC analysis and threat correlation - Endpoint and identity investigations - Email security investigations - Cloud security incident analysis - Root cause analysis **Investigate and respond to:** - Account compromise incidents - Business Email Compromise (BEC) - Malware and ransomware activity - Privilege escalation - Lateral movement activity - Suspicious cloud and identity-based attacks - Advanced phishing and social engineering campaigns - Coordinate containment, remediation, and recovery activities with customer and internal teams - Support high-severity incident escalation handling and response coordination - Provide detailed investigation findings, timelines, impact assessments, and response recommendations - Conduct proactive threat hunting and threat validation activities where required - Support digital forensics and evidence collection activities when applicable **2. Detection Engineering & SIEM Operations** Design, develop, and maintain advanced detection rules across: - Microsoft Sentinel - Microsoft Defender XDR Develop and optimize: - KQL queries - Analytics rules - Correlation logic - Detection use cases **Perform:** - Detection tuning - False positive reduction - Behavioral baselining - Threat-based detection improvements - Build and maintain reusable detection content and query libraries - Support proactive detection engineering initiatives aligned with emerging threats and attacker techniques - Leverage threat intelligence and MITRE ATT&CK mapping to improve detection coverage **3. SOC Automation & SOAR Engineering** Design and implement SOC automation workflows using: - Microsoft Sentinel Playbooks - Logic Apps - SOAR platforms - API-driven integrations **Build workflows for:** - Alert enrichment - Incident routing - Automated containment actions - Threat intelligence enrichment - Ticket synchronization - Investigation acceleration - Develop scalable automation frameworks to improve SOC operational efficiency - Support continuous optimization of SOC workflows and automation coverage - Create automation standards and reusable workflow templates across customer environments **4. Microsoft Security Platform Operations** **Provide hands-on operational support, investigation, tuning, administration, and engineering for:** - Microsoft Defender for Endpoint (MDE) - Microsoft Defender XDR - Microsoft Defender for Identity (MDI) - Microsoft Defender for Office 365 (MDO) - Microsoft Defender for Cloud Apps (MDCA) - Microsoft Purview - Microsoft Identity Protection / Entra ID - Microsoft Sentinel **5. AI Security & Modern Threat Operations** Support detection and response activities related to: - AI-orchestrated attacks - Identity-based attacks - Cloud-native threats - Advanced phishing and social engineering campaigns - Leverage AI-assisted SOC operations and automation capabilities where applicable - Support modern detection strategies aligned with evolving attacker techniques - Evaluate opportunities to integrate AI-driven efficiencies into detection, investigation, and response workflows **6. Client & Operational Support** - Participate in customer incident discussions and escalation calls when required - Support onboarding of new customer environments and security integrations - **Maintain:** - Investigation playbooks - SOPs - Workflow documentation - Operational runbooks - Detection documentation **Collaborate closely with:** - SOC Operations - Security Engineering - Vendors - Consulting teams - Customer stakeholders - Support operational improvement initiatives across SOC and DFIR functions
Job Requirements
- Required Qualifications
- Education**
- Bachelor’s Degree / Graduation in: Computer Science/Information Technology/Cybersecurity or related technical field is mandatory
- Relevant cybersecurity and automation-focused certifications will be considered an added advantage.
- Experience**
- 6-9 years of overall cybersecurity experience
- Strong hands-on experience in:**
- Incident Response
- Threat Investigation
- SOC Operations
- Detection Engineering
- DFIR activities
- Prior Incident Response Analyst experience is highly preferred
- Experience working within MSSP environments preferred
- Experience supporting or collaborating with US-based teams/vendors preferred
- Proven hands-on experience with SOAR platforms in enterprise or MSSP environments
- Strong experience designing and implementing SOC automation workflows from scratch
- Experience supporting enterprise Security Operations Center (SOC) environments
- Experience with detection engineering and SIEM rule development
- Required Technical Skills**
- Security Platforms & Technologies
- Strong hands-on experience with:**
- Microsoft Defender for Endpoint (MDE)
- Microsoft Defender XDR
- Microsoft Defender for Identity (MDI)
- Microsoft Defender for Office 365 (MDO)
- Microsoft Defender for Cloud Apps (MDCA)
- Microsoft Purview
- Microsoft Identity Protection / Entra ID
- CrowdStrike Falcon
- Threat Intelligence platforms
- Microsoft Sentinel (Mandatory)
- Defender XDR SIEM operations (Mandatory)
- Graph API
- Datto Autotask or equivalent ticketing systems
- Email security solutions
- Endpoint Detection & Response (EDR) platforms
- Identity and authentication platforms
- Cloud security technologies
- Detection Engineering & Automation
- Strong experience creating:**
- Detection rules
- Analytics rules
- KQL queries
- Detection tuning and fine-tuning
- Experience with:**
- SOC workflow design
- SOC automation
- SOAR engineering
- API integrations
- Workflow orchestration
- Understanding of:**
- MITRE ATT&CK
- Threat detection methodologies
- Threat hunting methodologies
- AI-driven attack techniques
- AI use cases in SOC operations
- Scripting & Technical Skills**
- Preferred experience with:
- PowerShell
- Python
- REST APIs
- Logic Apps
- KQL (Mandatory)
- Preferred Certifications**
- Microsoft SC-200
- Microsoft SC-401
- Microsoft AZ-500
- Microsoft SC-900
- Microsoft SC-100
- CISSP
- Security Automation / SOAR Automation / SOAR Certifications
- Soft Skills & Work Style**
- Strong verbal and written communication skills with the ability to work effectively across technical and non-technical teams
- Excellent collaboration and stakeholder coordination skills across SOC Operations, Engineering, Consulting, Vendors, and Leadership teams
- Strong documentation and technical writing capabilities for investigations, workflows, SOPs, and operational procedures
- Ability to work independently in a remote-first, multicultural, and fast-paced MSSP environment
- Self-driven, proactive, and highly organized with strong ownership and accountability
- Strong analytical, troubleshooting, and problem-solving skills
- Comfortable managing multiple projects, priorities, and operational initiatives simultaneously
- Team-oriented mindset with the ability to operate effectively as an individual contributor
- Professional communication and coordination skills for working with US-based teams and vendors
- Adaptable and flexible to evolving operational and business requirements
- Working Model**
- Rotational Shift (US Business Hours or After Hours)
- Remote-first operational model
- Participation in on-call escalation rotation for critical incidents when required
Related Guides
Related Categories
Related Job Pages
More Security Operations Jobs
• Helping to develop architectural requirements and corresponding engineering processes and technologies to support Collibra’s cloud-native platform • Design and tune cloud-native detection rules and threat models for AWS GuardDuty, Microsoft Defender for Cloud, and GCP Security Command Center • Conduct continuous vulnerability assessments of cloud workloads, container images, and serverless functions • Develop, continuously improve, and ensure compliance with controls built for the cloud-native platform • Partner with engineering teams to prioritize and drive remediation of cloud security findings • Plan, organize, and manage multiple responsibilities from various stakeholders and sometimes competing requests to achieve desired objectives • Maintain and update CloudFlare WAF rules to work with the Collibra product. • Evaluate and deploy cloud workload protection platforms (CWPP) and container security tooling • Assist with technical response efforts for cloud security incidents, perform forensic analysis, and contribute to root-cause investigation • Write production-quality code in Python, Golang/Go, or similar languages to build internal security tooling and automation • Integrate security tooling into developer workflows to reduce friction while improving security outcomes • After hours on-call support may occasionally be required
L3 SOC Analyst / Incident Response Analyst
ProArchConsulting and technology- enabled by cloud, guided by data, fueled by apps, and secured by design.
Role Description At ProArch, a leader in IT security consulting with presence in the US, UK, and India, we are looking for a skilled L3 SOC Analyst / Incident Response Analyst to join our Security Operations Center (SOC) team. In this critical role, you will be responsible for advanced incident detection, investigation, and response to complex cybersecurity threats. Leveraging your extensive experience and expertise, you will lead incident response activities, perform deep-dive analysis, and coordinate with cross-functional teams to mitigate risks and strengthen our security posture. This role is heavily focused on: - Incident Response - Threat Investigation - Detection Engineering - DFIR Operations - SOC Automation - Threat Hunting - Security Platform Engineering - Response Workflow Optimization The ideal candidate combines strong incident response expertise, deep Microsoft security platform knowledge, hands-on detection engineering capability, and SOC automation experience within a fast-paced MSSP environment. This is not a traditional alert-monitoring SOC Analyst role. The position requires strong investigative, analytical, and response-oriented cybersecurity capabilities. Key Responsibilities - Incident Response & Threat Investigation - Lead and support advanced security incident investigations across multiple customer environments - Perform: - Threat triage and validation - IOC analysis and threat correlation - Endpoint and identity investigations - Email security investigations - Cloud security incident analysis - Root cause analysis - Investigate and respond to: - Account compromise incidents - Business Email Compromise (BEC) - Malware and ransomware activity - Privilege escalation - Lateral movement activity - Suspicious cloud and identity-based attacks - Advanced phishing and social engineering campaigns - Coordinate containment, remediation, and recovery activities with customer and internal teams - Support high-severity incident escalation handling and response coordination - Provide detailed investigation findings, timelines, impact assessments, and response recommendations - Conduct proactive threat hunting and threat validation activities where required - Support digital forensics and evidence collection activities when applicable - Detection Engineering & SIEM Operations - Design, develop, and maintain advanced detection rules across: - Microsoft Sentinel - Microsoft Defender XDR - Develop and optimize: - KQL queries - Analytics rules - Correlation logic - Detection use cases - Perform: - Detection tuning - False positive reduction - Behavioral baselining - Threat-based detection improvements - Build and maintain reusable detection content and query libraries - Support proactive detection engineering initiatives aligned with emerging threats and attacker techniques - Leverage threat intelligence and MITRE ATT&CK mapping to improve detection coverage - SOC Automation & SOAR Engineering - Design and implement SOC automation workflows using: - Microsoft Sentinel Playbooks - Logic Apps - SOAR platforms - API-driven integrations - Build workflows for: - Alert enrichment - Incident routing - Automated containment actions - Threat intelligence enrichment - Ticket synchronization - Investigation acceleration - Develop scalable automation frameworks to improve SOC operational efficiency - Support continuous optimization of SOC workflows and automation coverage - Create automation standards and reusable workflow templates across customer environments - Microsoft Security Platform Operations - Provide hands-on operational support, investigation, tuning, administration, and engineering for: - Microsoft Defender for Endpoint (MDE) - Microsoft Defender XDR - Microsoft Defender for Identity (MDI) - Microsoft Defender for Office 365 (MDO) - Microsoft Defender for Cloud Apps (MDCA) - Microsoft Purview - Microsoft Identity Protection / Entra ID - Microsoft Sentinel - Additional technologies include: - CrowdStrike Falcon - Threat Intelligence platforms - Email security solutions - Endpoint Detection & Response (EDR) platforms - Identity and authentication platforms - Cloud security solutions - Ticketing platforms (Datto Autotask preferred) - AI Security & Modern Threat Operations - Support detection and response activities related to: - AI-orchestrated attacks - Identity-based attacks - Cloud-native threats - Advanced phishing and social engineering campaigns - Leverage AI-assisted SOC operations and automation capabilities where applicable - Support modern detection strategies aligned with evolving attacker techniques - Evaluate opportunities to integrate AI-driven efficiencies into detection, investigation, and response workflows - Client & Operational Support - Participate in customer incident discussions and escalation calls when required - Support onboarding of new customer environments and security integrations - Maintain: - Investigation playbooks - SOPs - Workflow documentation - Operational runbooks - Detection documentation - Collaborate closely with: - SOC Operations - Security Engineering - Vendors - Consulting teams - Customer stakeholders - Support operational improvement initiatives across SOC and DFIR functions Qualifications - Bachelor’s Degree / Graduation in: Computer Science/Information Technology/Cybersecurity or related technical field is mandatory - Relevant cybersecurity and automation-focused certifications will be considered an added advantage. - 6-9 years of overall cybersecurity experience - Strong hands-on experience in: - Incident Response - Threat Investigation - SOC Operations - Detection Engineering - DFIR activities - Prior Incident Response Analyst experience is highly preferred - Experience working within MSSP environments preferred - Experience supporting or collaborating with US-based teams/vendors preferred - Proven hands-on experience with SOAR platforms in enterprise or MSSP environments - Strong experience designing and implementing SOC automation workflows from scratch - Experience supporting enterprise Security Operations Center (SOC) environments - Experience with detection engineering and SIEM rule development Requirements - Strong hands-on experience with: - Microsoft Defender for Endpoint (MDE) - Microsoft Defender XDR - Microsoft Defender for Identity (MDI) - Microsoft Defender for Office 365 (MDO) - Microsoft Defender for Cloud Apps (MDCA) - Microsoft Purview - Microsoft Identity Protection / Entra ID - CrowdStrike Falcon - Threat Intelligence platforms - Microsoft Sentinel (Mandatory) - Defender XDR SIEM operations (Mandatory) - Graph API - Datto Autotask or equivalent ticketing systems - Email security solutions - Endpoint Detection & Response (EDR) platforms - Identity and authentication platforms - Cloud security technologies - Strong experience creating: - Detection rules - Analytics rules - KQL queries - Detection tuning and fine-tuning - Experience with: - SOC workflow design - SOC automation - SOAR engineering - API integrations - Workflow orchestration - Understanding of: - MITRE ATT&CK - Threat detection methodologies - Threat hunting methodologies - AI-driven attack techniques - AI use cases in SOC operations - Preferred experience with: - PowerShell - Python - REST APIs - Logic Apps - KQL (Mandatory) Preferred Certifications - Microsoft SC-200 - Microsoft SC-401 - Microsoft AZ-500 - Microsoft SC-900 - Microsoft SC-100 - CISSP - Security Automation / SOAR Automation / SOAR Certifications Soft Skills & Work Style - Strong verbal and written communication skills with the ability to work effectively across technical and non-technical teams - Excellent collaboration and stakeholder coordination skills across SOC Operations, Engineering, Consulting, Vendors, and Leadership teams - Strong documentation and technical writing capabilities for investigations, workflows, SOPs, and operational procedures - Ability to work independently in a remote-first, multicultural, and fast-paced MSSP environment - Self-driven, proactive, and highly organized with strong ownership and accountability - Strong analytical, troubleshooting, and problem-solving skills - Comfortable managing multiple projects, priorities, and operational initiatives simultaneously - Team-oriented mindset with the ability to operate effectively as an individual contributor - Professional communication and coordination skills for working with US-based teams and vendors - Adaptable and flexible to evolving operational and business requirements Working Model - Rotational Shift (US Business Hours or After Hours) - Remote-first operational model - Participation in on-call escalation rotation for critical incidents when required What Success Looks Like - High-quality incident investigations and response handling - Improved detection fidelity and reduced false positives - Increased SOC automation coverage and operational efficiency - Faster containment and response coordination - Consistent and high-quality incident response across customer environments - Strong collaboration across SOC, Engineering, and Customer teams - Continuous improvement of detection, automation, and DFIR capabilities
Security Operations Engineer II
StubHubStubHub is a web and mobile platform that enables fans around the world to buy and sell tickets for live events. Its global ticket marketplace includes over 10
Title: Security Operations Engineer II Location: New York, New York, United States Job Description: StubHub is on a mission to redefine the live event experience on a global scale. Whether someone is looking to attend their first event or their hundredth, we’re here to delight them all the way from the moment they start looking for a ticket until they step through the gate. The same goes for our sellers. From fans selling a single ticket to the promoters of a worldwide stadium tour, we want StubHub to be the safest, most convenient way to offer a ticket to the millions of fans who browse our platform around the world. The Security Operations team owns incident response, threat detection, SIEM engineering, log management, and third-party security risk forming the frontline defense for StubHub's global operations. As a Security Operations Engineer you will bring deep hands-on experience in incident response and threat detection. You will help extend the existing tooling, automation, and detection infrastructure that enables the team to operate at scale. This is not a purely operational role; we are looking for an engineer who writes production-quality code to solve security problems, architects detection pipelines, and help mature StubHub’s SOC-less approach to Detection & Response. You will work closely with Cloud and Infrastructure Security, Identity Engineering, and cross-functional stakeholders. Your work will directly shape how StubHub detects, responds to, and learns from threats. Location: Hybrid (3 days in office/2 days remote) – New York, NY or Century City, CA What You'll Do: What You've Done: - Incident Response - Lead and coordinate security incident response end-to-end: detection, triage, containment, eradication, recovery, and post-incident review - Develop and maintain incident response playbooks - Drive root cause analysis and translate findings into durable improvements to detection and prevention capabilities - Act as an escalation point for complex or high-severity incidents across the organization - Threat Detection - Design, build, and tune detection rules, event correlation logic, and behavioral analytics across cloud, endpoint, network, and application data sources - Assist in maintaining a threat model for StubHub's environment and mapping detection coverage to the MITRE ATT&CK framework - Proactively hunt for threats and indicators of compromise across the environment - Collaborate with red team and pen test partners to validate detection coverage and identify gaps - SIEM & Log Engineering - Continually improve SIEM capabilities including data ingestion pipelines, normalization, enrichment, and alerting workflows - Own log collection strategy: define what gets collected, at what fidelity, and for how long across cloud providers, SaaS applications, endpoints, and internal services - Write and maintain parsers, ETL pipelines, and data transformation logic to ensure high-quality signal in the SIEM - Own and operate security tooling where needed (SIEM, SOAR, EDR, etc.) - Security Automation & Tooling - Write internal software in Python, Go, or similar to automate detection, response, enrichment, and reporting workflows - Build integrations between security tools, internal APIs, and third-party services to accelerate analyst workflows and reduce mean time to respond - Develop dashboards, metrics, and reporting to communicate operational health and coverage to security leadership - Contribute to shared security infrastructure and internal libraries used across the security engineering organization - Third-Party Security - Support the third-party security program by evaluating vendor security posture, reviewing assessments, and triaging risk findings - Build or maintain tooling to automate third-party risk intake, tracking, and reporting - Collaborate with Legal, Procurement, and Engineering to ensure third-party risks are identified and remediated appropriately - 3+ years of experience in security engineering, security operations, or a related discipline - Demonstrated, hands-on experience leading incident response efforts, including complex, multi-system investigations - Strong threat detection engineering experience: writing detection rules, tuning alerts, building correlation logic, and reducing false positive rates at scale - Proficiency in at least one programming or scripting language (Python strongly preferred; Go, Ruby, or Bash also relevant) — you regularly write code to solve security problems, not just configure tools - Deep familiarity with SIEM platforms (e.g., Splunk, ELK, Chronicle, Panther, or similar) including query languages and datra data onboarding. - Experience with cloud environments (AWS, GCP, or Azure) and the associated log sources, threat models, and detection strategies - Strong understanding of attacker tactics, techniques, and procedures (TTPs); experience mapping detections to MITRE ATT&CK - Excellent written and verbal communication skills; able to convey technical risk clearly to non-technical stakeholders Preferred Experience: Experience operating in a SOC environment, either in-house or as part of an MSSP Familiarity with SOAR platforms and automation-driven response workflows Experience with threat intelligence platforms and operationalizing threat feeds into detection pipelines Prior involvement in third-party or vendor security risk programs Experience at high-growth technology companies or marketplaces where scale and velocity present unique security challenges Familiarity with data engineering concepts — streaming pipelines, schema design, log normalization — applied to security contexts Relevant certifications (GCIH, GCIA, GCFE, OSCP, or equivalent) are a plus, but not required What We Offer: - Accelerated Growth Environment: An environment designed for swift skill and knowledge enhancement, where you have the autonomy to lead experiments and tests on a massive scale. - Top Tier Compensation Package: Competitive base, equity, and upside that tracks with your impact. - Flexible Time Off: Enjoy unlimited Flex Time Off, giving you the flexibility to manage your schedule and take time to recharge as needed. - Comprehensive Benefits Package: Prioritize your well-being with a comprehensive benefits package, featuring 401k, and premium Health, Vision, and Dental Insurance options. The anticipated gross base pay range is below for this role. Actual compensation will vary depending on factors such as a candidate’s qualifications, skills, experience, and competencies. Base annual salary is one component of StubHub’s total compensation and competitive benefits package, which includes equity, 401(k), paid time off, paid parental leave, and comprehensive health benefits. Salary Range $165,000—$200,000 USD About Us StubHub is the world’s leading marketplace to buy and sell tickets to any live event, anywhere. Through StubHub in North America and viagogo, our international platform, we service customers in 195 countries in 33 languages and 49 available currencies. With more than 300 million tickets available annually on our platform to events around the world -- from sports to music, comedy to dance, festivals to theater -- StubHub offers the safest, most convenient way to buy or sell tickets to the most memorable live experiences. Come join our team for a front-row seat to the action. For California Residents: California Job Applicant Privacy Notice found here We are an equal opportunity employer and value diversity on our team. We do not discriminate on the basis of race, color, religion, sex, national origin, gender, sexual orientation, age, disability, veteran status, or any other legally protected status.
Senior Privacy Specialist Cyber Security and Privacy Operations
Fresenius Medical CareCreating a future worth living. For patients. Worldwide. Every day.
Role Description - Monitor and assess alerts, cases, and reports for potential privacy incidents (e.g., unauthorized access, data exfiltration, misdirected communications). - Perform initial triage to classify incidents involving Personal Data (PII/PHI). - Lead or support end-to-end investigation of privacy incidents. - Analyze impacted data elements, systems, and individuals; determine root cause and scope of exposure. - Document incident findings in accordance with legal and compliance requirements. - Evaluate breach thresholds under regulations (HIPAA, GDPR, state breach laws). - Coordinate with Legal on breach notification obligations. - Support preparation of regulatory filings and communications to affected individuals. - Participate in incident response war rooms and crisis management efforts. - Ensure alignment between technical containment and privacy obligations. - Maintain detailed incident records and case documentation. - Track incident metrics (e.g., time to detect/respond, incident trends). - Provide reporting to leadership, regulators, and audit teams. - Enhance privacy incident response playbooks and workflows. - Conduct tabletop exercises and training sessions. - Contribute to privacy program maturity and continuous improvement initiatives. - Participate in projects collaborating with stakeholders as needed. - Monitor the Privacy Office inbox and provide timely guidance and responses to inquiries. - Develop and deliver privacy training and awareness initiatives to promote a culture of data protection and compliance. - Draft and review privacy policies and procedures to ensure alignment with applicable regulations and organizational standards. Qualifications - Bachelor’s degree in Cybersecurity, Information Security, Law, Privacy, Healthcare or related field (or equivalent experience). Requirements - 5+ years of experience in Privacy Operations. - Experience building or leading a Privacy Incident Response function preferred. - Direct interaction with regulators or auditors. - Knowledge of data mapping, data governance, and privacy engineering. - Handling data breach or privacy incidents. - Strong understanding of data protection regulations (HIPAA, GDPR, CCPA, etc.). - Familiarity with privacy principles and data classification. - Understanding of the incident response lifecycle (NIST/SANS framework familiarity). - Certifications such as: - CIPP (US/E, or equivalent) - CIPM / CIPT - CISSP, CISM, or GIAC (GCIA, GCIH) - Certified Healthcare Compliance Professional (CHC) or Certified Healthcare Privacy Compliance (CHPC) - Experience in healthcare or other regulated industries. Benefits - Comprehensive benefits package including medical, dental, and vision insurance. - 401(k) with company match. - Paid time off. - Parental leave. Company Description Fresenius Medical Care is an equal opportunity employer and does not discriminate on the basis of race, color, religion, sexual orientation, gender identity, parental status, national origin, age, disability, military service, or other non-merit-based factors.



