Auf einen Blick
- Aufgaben: Bewirb dich als Associate Director für Compliance und Risikomanagement bei Planned Parenthood.
- Unternehmen: Planned Parenthood, führend in sexueller und reproduktiver Gesundheitsversorgung.
- Vorteile: Vielfältige Entwicklungsmöglichkeiten und ein unterstützendes Arbeitsumfeld.
- Weitere Informationen: Engagiertes Team, das Vielfalt und Inklusion schätzt.
- Warum dieser Job: Gestalte die Zukunft der Gesundheitsversorgung und setze dich für wichtige gesellschaftliche Themen ein.
- Qualifikationen: Erforderlich: Bachelor-Abschluss und 5+ Jahre Erfahrung im Bereich Compliance.
Das prognostizierte Gehalt liegt zwischen 60000 - 80000 € pro Jahr.
Planned Parenthood is the nation’s leading provider and advocate of high‑quality, affordable sexual and reproductive health care for all people, and the nation’s largest provider of sex education.
Planned Parenthood Federation of America (PPFA) is a 501(c)(3) charitable organization that supports independently incorporated Planned Parenthood affiliates, which operate non‑profit health centers across the U.
S., and works to educate the public on sexual and reproductive health issues.
PPFA and Planned Parenthood Action Fund are seeking a dynamic and effective Associate Director, Regulatory Risk, Compliance & Accreditation.
This role reports to the Director, Information Security, Risk & Compliance in the Information Security department of PPFA.
- Purpose
- The Associate Director will serve as an Information Security & Technology (IS&T) Program Expert and Accreditor for the PPFA Accreditation & Certification Program, which works to assess and manage risks across the federation through routine evaluation of its affiliate and ancillary organizations.
- The Associate Director is also responsible for PCI DSS compliance activities across the federation, which ensures that relevant internal controls are assessed and meet established information security, regulatory, operational, and reporting policies, regulations, and guidelines, while also providing support to the Third Party Risk Management (TPRM) Program, as needed.
- Engagement
- The Associate Director will be part of the HIPAA, Risk & Compliance team.
- This role will engage with the Information Security team, team members across the broader TSS division, the Accreditation & Evaluation Department (AED) team, Development, Finance, Office of the General Counsel and third party vendors.
- This role will engage with the executive and operational staff within the PPFA National Office, affiliates, and ancillary organizations.
- Delivery
- The Associate Director will deliver by evaluating security and technology systems, controls, and policies of affiliate and ancillary organizations, write reports that interpret assessment results and enumerate any findings, develop and track corrective actions, and assess efficacy of risk mitigation activities performed by the affiliate or ancillary organization.
- The Associate Director will deliver by conducting PCI DSS compliance activities utilizing assessment tools to ensure regulatory compliance and risk management across the federation.
- Conducts Accreditation and Certification interviews, risk assessments, and technical analyses to determine areas of risk and non‑compliance with defined IS&T criteria aligned to cyber security frameworks (NIST CSF) and regulatory requirements (HIPAA Security, PCI DSS).
- Uses broad and deep security knowledge and technical evaluation skills to help ensure risks are appropriately identified, assessed, and documented.
- Thoroughly reviews documentation, third party assessments, and audit samples for compliance with IS&T Accreditation criteria and identifies any discrepancies or corrective actions.
- Executes IS&T Accreditation processes and activities including attestation review and technical security control analysis and testing, where applicable, to validate control effectiveness.
- Escalates potential high or critical risk Accreditation findings to ensure alignment and appropriate notification and remediation activities.
- Weighs risk scope and impact when identifying and articulating risk outcomes in final reports and presentations to Accreditation stakeholders.
- Reviews and assesses corrective action reports to determine effective remediation of identified Accreditation and PCI DSS risks.
- Identifies improvements and trends in review operations, criteria, and methodology, and develops plans and proposals to improve and evolve the IS&T Accreditation program/requirements over time.
- Identifies areas of continuous improvement in the evaluation process and criteria, and adjusts to the evolution of Accreditation operations and requirements.
- Ensures timely communications and project management of individual Accreditation reviews and PCI DSS compliance activities.
- Maintains thorough and organized tracking of Accreditation and PCI DSS requirements, assessment results, and corrective actions.
- Supports and educates affiliates and ancillary organizations on the required PCI DSS compliance activities.
- Reviews and updates internal PCI DSS training content, policies, and procedures, as necessary, for national office staff.
- Executes annual PCI DSS self‑assessment questionnaires for all payment flows to identify security and technical deficiencies and collaborate across teams to remediate appropriately.
- Finalizes and obtains signature for the annual PCI DSS AOC.
- Facilitates required vulnerability scanning of relevant cardholder data environments (CDEs), which includes running a quarterly scan, identifying security and technical deficiencies, ensuring appropriate scope, and following up for remediations or documenting exceptions.
- Obtains and manages external PCI DSS vendors’ AOCs.
- Supports the PPFA TPRM team, as needed.
- Communicates professionally and effectively with technical, non‑technical, and executive stakeholders.
- All other duties as assigned.
- Knowledge, Skills and Abilities (KSAs)
- Bachelor’s degree and 5+ years of industry experience is required.
- Experience with compliance requirements and industry standards (HIPAA Security, PCI DSS, NIST, CIS, etc.) is required.
- Current industry certifications, particularly security and/or auditing certifications, a plus (CISA, CRISC, GSEC, etc.).
- Understanding of Information Security, Risk and Compliance.
- Minimum of 2 years of experience in governance, risk, and compliance (GRC), assessing, auditing, accreditation, and evaluating or implementing IT and information security controls, including experience reviewing information security systems, policies, processes, technology environments, internal control frameworks, compliance requirements, and audit programs.
- A deep understanding of IT and information security environments and administration.
- Strong written and verbal communication, including technical and non‑technical writing skills.
- Strong attention to detail and analytical skills.
- Ability to balance firm adherence to security practices and flexibility in a fast‑paced and continuously changing environment.
- Ability to maintain neutrality and fairness in the review process, and avoid or raise any possible bias.
- Knowledge of security technologies (security tools, networking, device protections, encryption, data protection, identity and access management, etc.).
- Commitment and track record of advancing racial equity in both operations and communications.
- High proficiency in Google products.
- Flexibility and ability to adapt to quickly changing priorities and ambiguous situations.
Travel: 0‑10%, domestic travel, as needed.
Planned Parenthood's cultural ethos, “In This Together”, reflects our commitment to building a workplace culture that fosters belonging, promotes learning throughout the employee lifecycle, and recognizes individual contributions to our mission.
Planned Parenthood Federation of America participates in the E‑Verify program.
Planned Parenthood Federation of America is an equal employment opportunity employer and is committed to maintaining a non‑discriminatory work environment, and does not discriminate against any employee or applicant for employment on the basis of race, color, religion, sex, national origin, age, disability, veteran status, marital status, sexual orientation, gender identity, or any other characteristic protected by applicable law.
Planned Parenthood is committed to creating a dynamic work environment that values diversity and inclusion, respect and integrity, customer focus, and innovation.
#J-18808-Ljbffr
Associate Director, Regulatory Risk, Compliance, Accreditation Arbeitgeber: jobr.pro
jobr.pro ist ein hervorragender Arbeitgeber, der talentierte AI Backend Engineers in einer vollständig remote Position sucht. Unsere Unternehmenskultur fördert hohe Eigenverantwortung und bietet wettbewerbsfähige Vergütung sowie zahlreiche Möglichkeiten zur beruflichen Weiterentwicklung in einem globalen Team, das an modernen Engineering-Praktiken arbeitet und Millionen von Nutzern beeinflusst.
StudySmarter Expertenrat🤫
Wir sind der Meinung, dass du so Associate Director, Regulatory Risk, Compliance, Accreditation erhalten könntest
✨Mit Compliance-Events in Kontakt treten
Besuche branchenspezifische Events und Konferenzen im Bereich Compliance, wie zum Beispiel die Compliance-Akademie oder Netzwerktreffen von Fachverbänden. Hier kannst du direkt mit Experten sprechen und eventuell sogar Ansprechpartner von jobr.pro treffen!
✨Zertifizierungen und Weiterbildungen nutzen
Schaue dir relevante Zertifizierungen oder Weiterbildungsmöglichkeiten an, die in der Compliance-Branche anerkannt sind. Wenn du zum Beispiel die CCEP oder ähnliche Qualifikationen hast, zeigt das Engagement und könnte dir einen Vorteil im Auswahlprozess bei jobr.pro verschaffen.
✨Jetzt auf die richtige Stelle bei jobr.pro bewerben!
Verpass nicht die Chance, dich direkt über unsere Website bei jobr.pro zu bewerben! Da wir oft auf unseren eigenen Kanälen nach Talenten suchen, stell sicher, dass du deine Bewerbung schnell einreichst – je früher, desto besser!
✨Globalen Compliance-Netzwerke beitreten
Tritt Online-Communities und Foren bei, die sich mit Compliance-Themen beschäftigen. Plattformen wie ComplianceNetzwerk oder LinkedIn-Gruppen können dir helfen, wertvolle Kontakte zu knüpfen und auf Stellenangebote aufmerksam zu werden. Diese Verbindung kann dir in Gesprächen bei jobr.pro den entscheidenden Vorteil verschaffen.
Wir glauben, dass du diese Fähigkeiten brauchst, um Associate Director, Regulatory Risk, Compliance, Accreditation mit Bravour zu bestehen
Einige Tipps für deine Bewerbung 🫡
Kenn dein Compliance-ABC:Achte darauf, dass deine Bewerbung zeigt, dass du die relevanten Compliance-Vorgaben und Regularien beherrschst. Dies könnten z.B. ISO-Normen oder spezielle gesetzliche Anforderungen sein, die für jobr.pro wichtig sind. Wenn du relevante Zertifikate hast, zeig sie!
Lebenslauf mit klaren Nachweisen:Verstärke deinen Lebenslauf mit konkreten Beispielen, die deine Erfahrungen im Compliance-Bereich zeigen. Beleuchte deine Fähigkeiten zur Risikoanalyse und -bewertung, aber auch deine Erfahrungen in der Zusammenarbeit mit verschiedenen Abteilungen, die Compliance-Punkten unterliegen.
Motivation und Interesse ausschreiben:In deinem Bewerbungsschreiben solltest du nicht nur darstellen, was du kannst, sondern auch, warum du dich für die Compliance-Rolle bei jobr.pro interessierst. Zeige, dass du wirklich für die Themen brennst und bereit bist, dich stetig weiterzuentwickeln.
Zielgerichteter Kontakt:Falls du einen Vertreter von jobr.pro oder jemanden im Compliance-Team kennst, zögere nicht, ihn zu kontaktieren. Ein kurzes, freundliches E-Mail oder eine Nachricht kann dir zusätzliche Einblicke geben, die du in deiner Bewerbung nutzen kannst. Das zeigt Interesse und Initiative!
Wie man sich auf ein Vorstellungsgespräch bei jobr.pro vorbereitet
✨Vorbereitung auf Fachfragen zur Compliance
Bereite dich darauf vor, spezifische Fragen zu Compliance-Vorgaben, Gesetzen und ethischen Standards zu beantworten. Mach dich mit den neuesten Entwicklungen im Compliance-Bereich vertraut und sei bereit, konkrete Beispiele aus deinen Erfahrungen zu nennen, um deine Kenntnisse zu untermauern.
✨Den richtigen Umgang mit Compliance-Tools zeigen
Da Compliance oft mit speziellen Software-Tools und Datenanalyse verbunden ist, solltest du dich mit häufig genutzten Tools in der Branche vertraut machen. Sei bereit, Fragen zu beantworten, die deine Erfahrung mit diesen Tools und deine Fähigkeit, Daten zur Unterstützung von Compliance-Maßnahmen zu interpretieren, zeigen.
✨Motivation und Engagement für die Rolle
Zeige während des Gesprächs dein Interesse an den Auflagen und Standards der Branche. Arbeitgeber in der Compliance-Branche suchen nach Kandidaten, die motiviert sind und ein echtes Engagement zeigen, die Integrität des Unternehmens zu wahren und gute Praktiken zu fördern.
✨Beispiele für deine Problemlösungsfähigkeiten
Sei darauf vorbereitet, Situationen zu beschreiben, in denen du Compliance-Herausforderungen erfolgreich gemeistert hast. Beispiele aus der Praxis können dir helfen, deine Problemlösungsfähigkeiten und dein kritisches Denken zu demonstrieren. Zeige, wie du in schwierigen Situationen kreativ und effektiv Lösungen gefunden hast.