Privacy & Security Enterprise Engagement Officer
Position Purpose: Serves as a partner and advisor between enterprise stakeholders and Enterprise Privacy & Security Risk Management (EPSRM), ensuring regulatory and contractual privacy, security, AI, and business continuity requirements are translated into practical operational controls, processes, and governance activities. Partners closely with key stakeholders to translate complex legal, regulatory, and policy obligations within the context of business operations and supporting technology environments, enabling the organization to achieve compliance while effectively managing risk and maintaining operational efficiency. Partners with business, technology, compliance, legal, and operational stakeholders to identify emerging requirements, assess impacts, drive remediation of control gaps, and promote audit-ready compliance. Acting as an advisor and second-line risk partner, the role helps embed privacy, security, and resilience objectives into business decision-making, ensuring risks are proactively identified, communicated, and mitigated in alignment with organizational goals and regulatory expectations.
Key Details: Must be authorized to work in the U.S. without the need for employment-based visa sponsorship now or in the future. Sponsorship and future sponsorship are not available for this opportunity, including employment-based visa types H-1B, L-1, O-1, H-1B1, F-1, J -1, OPT, or CPT.
- Acts as a key partner and advisor between EPSRM and assigned business partners, including Health Plans, Health Care Enterprises, Shared Services, Compliance, and Market Technology Leads, building strong stakeholder relationships and ensuring clear understanding of requirements, risks, gaps, priorities, and compliance expectations.
- Conducts impact analysis on new requirements and facilitate cross-functional working groups to educate, identify resource needs to manage organizational and regulatory changes, and drive complex, enterprise-wide initiatives to maintain audit-ready compliance of our business and technology processes and systems.
- Enables risk-informed business decisions by translating complex contractual and regulatory privacy, security, AI, and resilience requirements into actionable business and technology guidance that balances compliance obligations with operational realities.
- Identifies, assesses, and facilitates solutions to risks, control gaps, and compliance issues related to privacy, security, AI, and business continuity, partnering with internal and external stakeholders to remove barriers, break down silos, drive collaboration, and escalate issues.
- Supports regulatory audits, assessments, and readiness reviews by coordinating and validating compliance evidence and control effectiveness, facilitating responses, and providing subject matter expertise to demonstrate audit-ready compliance.
- Supports business growth and operational readiness activities, including market expansion, contract renewals, RFP responses, tabletop exercises, and readiness reviews by evaluating privacy, security, AI, and business continuity preparedness.
- Partners with Legal, Procurement, and business stakeholders to update third-party agreements, addendums, and contractual requirements in response to evolving privacy, security, AI, and business continuity obligations.
- Partners with Government Affairs and regulatory stakeholders to provide subject matter expertise, recommendations, and impact assessments on proposed legislation and regulatory developments affecting privacy, security, AI, and business continuity.
- Maintains deep knowledge of Centene’s business operations, technology ecosystems, vendors, and supporting processes, and how privacy, security, AI, and business continuity requirements apply across those environments.
- Establishes and maintains program governance structures such as RACIs, decision frameworks, reporting mechanisms, and project tracking processes to monitor and manage progress, and provide executive-level communications that clearly convey program status, compliance posture, business impacts, risks, decisions, and required actions across complex, multi-department initiatives.
- Monitors emerging industry, regulatory, and enforcement trends through participation in professional associations, regulatory forums, industry roundtables, ISACs, and requests-for-comment activities, using insights to anticipate future requirements and risks.
- Drives continuous improvement of Enterprise Engagement practices, including methodologies, stakeholder engagement strategies, reporting processes, governance approaches, and operational effectiveness.
- Performs other duties as assigned.
- Complies with all policies and standards.
Education/Experience:
Bachelor's Degree Information Security, Information Systems, Risk/Compliance, Business Law, or industry related field; or equivalent experience required.
Master's Degree in a related field preferred.
Juris Doctor (JD) preferred.
- 5+ years Privacy/security, risk, or compliance within the managed care, payer/health plan industry required.
- 3+ years Identifying, analyzing, and communicating security or privacy control requirements within the context of health plan operations, processes, and systems required.
- Experience interpreting regulatory, contractual, and compliance requirements and translating them into operational controls, risk management processes, business capabilities, and remediation strategies within highly regulated environments required.
- Experience leading complex, cross-functional projects or workstreams involving multiple stakeholders, including the development of executive communications, risk assessments, status reporting, and corrective action plans required.
- Working knowledge of healthcare regulatory and security frameworks, including HIPAA/HITECH, state privacy laws, AI governance, business continuity and resilience requirements, NIST 800-53, CMS MARS-E/ARC-AMPE, HITRUST, SOC 2, NCQA, and ISO 27001 required.
Licenses/Certifications:
- CISSP / CISM Certified Information Systems Security Professional (CISSP) or Certified Information Security Manager (CISM) Upon Hire required.
- Certified Information Privacy Professional (CIP), Artificial Intelligence Governance Professional (AIGP), Certified Risk and Information Systems Control (CRISC) or Certified Information Security Analyst (CISA) or equivalent preferred.
At Centene, we connect people to the care they need to live healthier lives — and the work you do here makes that impact real every day. You’ll take on meaningful challenges that directly support individuals, families, and communities, building your skills while making healthcare more accessible and effective. It’s work with a purpose you can see, backed by a team committed to improving lives well beyond the workday.
Centene offers a comprehensive benefits package including: competitive pay, health insurance, 401K and stock purchase plans, tuition reimbursement, paid time off plus holidays, and a flexible approach to work with remote, hybrid, field or office work schedules. Actual pay will be adjusted based on an individual's skills, experience, education, and other job-related factors permitted by law, including full-time or part-time status. Total compensation may also include additional forms of incentives. Benefits may be subject to program eligibility.
Centene is an equal opportunity employer that is committed to diversity, and values the ways in which we are different. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, veteran status, or other characteristic protected by applicable law.
Qualified applicants with arrest or conviction records will be considered in accordance with the LA County Ordinance and the California Fair Chance Act
Required Skills
Required Languages
🇬🇧 English