Privacy Analyst
Listed on 2026-09-21
-
IT/Tech
Information Security & Data Protection, Cybersecurity
Title
Privacy Analyst
Posting Numberreq
27070
University Privacy
Department Website LinkUniversity Privacy
LocationTucson Campus
AddressTucson, AZ USA
Position HighlightsThe Privacy Analyst supports the University of Arizona's privacy program by assisting in the monitoring of compliance with federal, state, and international regulations, as well as internal policies and emerging privacy requirements. Reporting to the HIPAA Privacy Officer, this role supports the investigation of potential privacy incidents, contributes to breach risk assessments, and assists with required documentation, reporting, and mitigation activities.
The Privacy Analyst collaborates with cross-functional teams to support privacy communication and training initiatives, participate in privacy assessments, and coordinate program activities across departments and colleges within the HIPAA Privacy Program.
Visa sponsorship is not available for this position.
Outstanding U of A benefits include health, dental, and vision insurance plans; life insurance and disability programs; paid vacation, sick leave, and holidays; U of A/ASU/NAU tuition reduction for the employee and qualified family members; retirement plans; access to U of A recreation and cultural activities; and more!
The University of Arizona has been recognized for our innovative work-life programs. For more information about working at the University of Arizona and relocations services, please .
Duties & ResponsibilitiesHIPAA Compliance Program:
- Coordinates program activities across departments and colleges designated as HIPAA Covered Components within the HIPAA Privacy Program.
- Participates in the annual review of HIPAA Covered Components and the annual HIPAA risk assessment process.
- Documents results of the annual assessments; tracks action items and remediation activities.
Vendor Privacy Support:
- Coordinates the review and tracking of Business Associate Agreements; performs vendor privacy risk assessments; coordinates the Authorization to Operate process for certain applications storing or processing regulated data.
- Partners with cross-functional teams to ensure appropriate safeguards and documentation are in place.
Training and Awareness Support:
- Supports privacy communication and training initiatives, including the development and updating of privacy training and marketing communications.
- Coordinates with human resources on training delivery, tracking, and reporting.
Privacy Incident Intake and Investigation:
- Supports privacy incident response activities, including incident intake, investigation, documentation, issue tracking, and remediation.
- Prepares summary reports for presentation to senior management and other stakeholders.
Privacy Program Support:
- Maintains current knowledge of applicable federal, state, and international privacy related laws, regulations, and accreditation standards.
- Supports the development, maintenance, and annual review of university privacy policies and procedures.
- Other Duties as Assigned.
- Knowledge of privacy laws (e.g., GDPR, HIPAA) and compliance standards.
- Understanding of other key subjects including cyber security and risk management.
- Strong communication skills for articulating privacy risks and policies.
- Strong critical thinking skills and the ability to assess how state, federal, and international privacy requirements apply to specific situations.
- Strong interpersonal skills and a commitment to fostering productive, respectful partnerships across teams and roles.
- Ability to collaborate with stakeholders on privacy matters.
- Ability to develop and enforce privacy policies.
- Ability to meticulously review contracts and data access requests for privacy compliance.
- Ability to translate complex privacy concepts into practical, easy-to-understand guidance for a variety of audiences.
- Familiarity with HIPAA requirements, Business Associate Agreements, or other regulated-data environments.
- Demonstrated curiosity and willingness to learn new and often complex topics, including privacy, legal regulations, and information security.
- Bachelor's degree or equivalent advanced learning attained through professional level experience required.
- Minimum of 3 years of relevant work experience, or equivalent combination of education and work experience.
- Experience in data privacy, business, information security, law, compliance, or a similar field
- Direct privacy experience is not required; relevant and transferable…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).