Cleveland Clinic

Cybersecurity Analyst - Compliance GDPR

Remote Location Full time

At Cleveland Clinic Health System, we believe in a better future for healthcare. And each of us is responsible for honoring our commitment to excellence, pushing the boundaries and transforming the patient experience, every day.

We all have the power to help, heal and change lives — beginning with our own. That’s the power of the Cleveland Clinic Health System team, and The Power of Every One.

Job Title

Cybersecurity Analyst - Compliance GDPR

Location

Cleveland

Facility

Remote Location

Department

Cybersecurity Assurance-Information Tech Div

Job Code

T98514

Shift

Days

Schedule

8:00am-5:00pm

Job Summary

Job Details

Join the Cleveland Clinic team where you will work alongside passionate caregivers and make a lasting, meaningful impact on patient care. Here, you will receive endless support and appreciation while building a rewarding career with one of the most respected healthcare organizations in the world.       

Performs all necessary duties to ensure the organization’s adherence to data protection and privacy regulations, with a primary focus on the General Data Protection Regulation (GDPR). This position is responsible for identifying and addressing compliance gaps, supporting the completion of Data Protection Impact Assessments (DPIAs), managing Data Subject Access Requests (DSARs), and driving continuous improvement of the cybersecurity and privacy compliance program. The analyst will collaborate across departments to promote a culture of compliance and safeguard the integrity of the organization’s data assets. 

A caregiver in this position works remotely Monday - Friday 8:00am—5:00pm EST.   

A caregiver who excels in this role will:    

  • Ensure organizational compliance with GDPR and other applicable data protection regulations by assessing controls, identifying deficiencies, and coordinating remediation efforts. 

  • Lead or support the completion of Data Protection Impact Assessments (DPIAs) and similar evaluations to identify, document, and mitigate data privacy risks across business processes and systems. 

  • Oversee the intake, coordination, and fulfillment of Data Subject Access Requests (DSARs), ensuring timely and compliant responses in accordance with regulatory standards. 

  • Contribute to the development, implementation, and maintenance of data protection policies, standards, and procedures. Recommend and implement program enhancements to strengthen privacy governance and cybersecurity maturity. 

  • Partner with Information Security, Legal, Compliance, and IT teams to align operational practices with regulatory obligations and data protection best practices. 

  • Support the design and delivery of privacy and cybersecurity awareness initiatives to promote understanding of GDPR requirements and secure data handling practices across the organization. 

  • Maintain documentation and reporting on compliance activities, risk findings, and mitigation progress. Support internal and external audits or regulatory inquiries as required. 

  • Monitor evolving data protection regulations, industry trends, and best practices to proactively identify opportunities to improve the organization’s compliance posture and maturity. 

  • Provide support for broader cybersecurity and compliance initiatives to advance the organization’s overall security objectives. 

  • Other duties as assigned 

 

 Minimum qualifications for the ideal future caregiver include:     

  • High School Diploma/GED: A minimum of 3 years of transportation management systems, payment management systems, and other systems that map shipping routes. 

  • Bachelor’s Degree: A minimum of 1 year transportation management systems, payment management systems, and other systems that map shipping routes 

  • Participate in conversations while taking notes as needed. 

  • Possessing strong critical thinking skills are essential to identify and capture relevant information during discussions with stakeholders. 

  • Requires the ability to build and maintain strong relationships with key customers or stakeholders to support open communication and effective collaboration on impact assessments, planning, and incident response and recovery. 

  • Engage in active listening skills to recognize and include relevant details in various continuity-related products. 

  • Be capable of analyzing data across critical functions, plan types, and impact analysis results to map dependencies accurately. 

  • Certified Information Privacy Professional/Europe (CIPP/E) certification is required within 12 months of position start date 

  • For Information Technology Division caregivers, ITIL Foundations certification is required within 6 months of position start date. 

Complexity of Work: 

  • Strong analytical, administrative, presentation, and project management skills are required. 

  • Must have strong communication skills (both written and verbal) and the ability to work with minimal supervision. 

  • Understanding of networking/distributed computing environment concepts. 

  • Excellent knowledge of security technology and strong analytical skills. 

 

Preferred qualifications for the ideal future caregiver include:    

  • Bachelor’s degree in Information Technology/Computer Science or related field preferred. 

  • Certifications from SysAdmin, Audit, Network and Security Institute (SANS), International Information Systems Security Certification Consortium (ISC2) or Computing Technology Industry Association (CompTIA) or other position related certifications preferred. 

  • Background in privacy with experience in GDPR preferred.

Our caregivers continue to create the best outcomes for our patients across each of our facilities. Click the link and see how we’re dedicated to providing what matters most to you: https://jobs.clevelandclinic.org/benefits-2/   

Physical Requirements:

  • Ability to perform work in a stationary position for extended periods.

  • Ability to travel throughout the hospital system.

  • Ability to operate a computer and other office equipment. 

  • Ability to communicate and exchange accurate information.

Personal Protective Equipment:

  • Follows standard precautions using personal protective equipment as required.

                       

The policy of Cleveland Clinic Health System and its system hospitals (Cleveland Clinic Health System) is to provide equal opportunity to all of our caregivers and applicants for employment in our drug free environment. All offers of employment are followed by testing for controlled substances.

Cleveland Clinic Health System administers an influenza prevention program. You will be required to comply with this program, which will include obtaining an influenza vaccination on an annual basis or obtaining an approved exemption.

Decisions concerning employment, transfers and promotions are made upon the basis of the best qualified candidate without regard to color, race, religion, national origin, age, sex, sexual orientation, marital status, ancestry, status as a disabled or Vietnam era veteran or any other characteristic protected by law. Information provided on this application may be shared with any Cleveland Clinic Health System facility. 

Please review the Equal Employment Opportunity poster

Cleveland Clinic Health System is pleased to be an equal employment employer: Women / Minorities / Veterans / Individuals with Disabilities