Senior Managing Counsel, Privacy & Cybersecurity; Americas
Job Description
Solventum is a new healthcare company building on a legacy of solving big challenges that improve lives and help healthcare professionals perform at their best. We are guided by empathy, insight, and clinical intelligence and collaborate with the best minds in healthcare to address our customers' toughest challenges.
The Impact You’ll Make in this RoleAs Sr. Managing Counsel, Privacy & Cybersecurity (USAC & LATAM) you will lead the legal support for privacy and cybersecurity efforts across the company’s USAC and LATAM operations. You will advise and collaborate with IT, cybersecurity, business and functional teams, and external partners to manage legal risks related to data security and privacy. You will strengthen the company's security posture, ensure compliance, and oversee security and compliance assessments across applications, processes, products, and vendors.
This role reports to the Chief Privacy Officer and the Vice President of Information and Digital.
- Provide expert legal counsel to Privacy and Cybersecurity teams to ensure compliance with contractual commitments and regulatory obligations related to data privacy and security.
- Conduct privacy and data protection impact assessments to ensure sensitive health data is used in compliance with privacy regulations and contractual rights.
- Advise cybersecurity teams on incident response and investigations, ensuring proper documentation to minimize risks, protect privacy, and fulfill legal obligations during and after security incidents.
- Collaborate with Procurement and business contracting teams to draft, negotiate, and maintain privacy/data protection terms in contracts and agreements.
- Lead the company’s legal response to product vulnerabilities, information security breaches, and cyber events, including advising on regulatory notifications at federal, state, and international levels.
- Counsel IT operations, security teams, and business units on developing and implementing cybersecurity plans, incident response strategies, and compliance with industry standards and regulations.
- Work closely with Cybersecurity, Procurement, and Legal teams to manage third‑party risks, including creating contract templates, negotiation frameworks, and advising on third‑party audits and assessments.
- Advise on the de‑identification, pseudonymization, and anonymization of sensitive health data.
- Provide guidance to business and product teams on data handling requirements based on sensitivity and compliance standards.
- Implement “privacy by design” principles in product development processes and contribute to product risk assessments.
- Stay informed on emerging global regulatory requirements impacting data privacy and security and advise the business accordingly.
- Develop and provide legal content for privacy training programs, awareness campaigns, and compliance with sensitive health information handling requirements.
To set you up for success in this role from day one, Solventum requires the following qualifications:
- Juris Doctor (JD) from an accredited law school or Law degree.
- 8 years of experience in data privacy and cybersecurity law, ideally within the life sciences, healthcare, medical devices, or similarly regulated industries.
- Expertise in global data privacy laws (including GDPR) and AI laws (including EU AI Act).
- Expertise in US data privacy laws and regulations, including HIPAA and US state consumer privacy laws (e.g., CCPA, CPA, etc.).
- Expertise in advising on cybersecurity, including product vulnerability, incident response, and legal obligations arising from privacy and security incidents.
- Experience in advising on cybersecurity standards such as PCI DSS, the NIST Cybersecurity Framework.
- Experience in Canada and LATAM data privacy laws and regulations, including LGPD, PIPEDA and the Privacy Act.
- Familiarity with medical device regulations (FDA, FD&C Act) related to data privacy and security.
- Experience managing HIPAA compliance programs and addressing legal issues related to health data.
- Experience working with IT systems, data management, and collaborating with both technical teams and senior leadership.
- Exc…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).