Fred Hutchinson Cancer Center logo
Fred Hutchinson Cancer CenterPosted 1 month ago

Data Governance Specialist III

$115,170–$182,021 year

HybridSeattle, Washington, United States

Full TimeLarge

Job Summary

Own and maintain the enterprise data classification and handling program, including policies, standards, and data inventories. Develop and operate processes for data lifecycle management covering ownership, lineage, retention, de-identification, and secondary use in research and clinical contexts. Partner with the Office of the Chief Data Officer, Privacy, and Legal to ensure governance policies are consistently applied across systems, cloud services, and research platforms. Provide governance guidance on projects involving data collection, integration, analytics, and AI/ML use cases, including IRB-adjacent data use considerations. Assess data-related risks across systems, applications, third-party vendors, and cloud environments; track and drive remediation. Support external audits and assessments involving data (HIPAA, HITRUST, research compliance), including evidence preparation and response coordination. Collaborate with Privacy and Legal to interpret and operationalize current and emerging regulations: HIPAA/HITECH, GDPR, the Common Rule, and FDA 21 CFR Part 11. Maintain data protection impact assessments, handling standards, and records of processing activities and policy exceptions. Recommend and oversee data protection technologies including DLP, CASB, DSPM, and data discovery/classification tools. Maintain enterprise data flow documentation: systems of record, data transfers, cross-border flows, and third-party obligations. Work with Security Operations monitoring for data-related threats (exfiltration, misuse); support incident response scoping and regulatory notification requirements. Define and report metrics on data governance program effectiveness for executive and regulatory audiences. Deliver targeted awareness training on data handling, classification, and secure use of cloud and collaboration platforms. Mentor team members and contribute to maturing data governance practices across the organization.

Required Qualifications

  • Bachelor's degree in information technology, computer science, business analytics, statistics, data science, public health, or other scientific or health-related field
  • Minimum 9 years of experience in data analytics, data management, governance, privacy, security or related disciplines
  • Master's degree (can substitute for two years of professional experience)
  • Strong evidence of excellent cross-discipline communication via written and verbal communication with ability to present complex technical information in a clear and concise manner to a variety of audiences, including executives and non-technical leaders
  • Demonstrated expertise in managing enterprise-wide governance initiatives across data domains
  • Demonstrated ability to scale and sustain external and internal initiatives and partnerships around data governance functions
  • Must be able to lift 50 lbs

Desired Qualifications

  • Hands-on experience with data protection and governance tools (DLP, DSPM, data classification/discovery tools, data catalogs, or equivalent)
  • Working knowledge of healthcare and research regulatory frameworks: HIPAA/HITECH, the Common Rule, FDA 21 CFR Part 11, and related state privacy laws
  • Familiarity with security and risk frameworks: NIST 800-53, NIST CSF, HITRUST CSF, and NIST AI RMF
  • Proven ability to translate complex regulatory and policy requirements into practical controls and operational processes
  • Strong written and verbal communication skills; comfortable presenting data risk topics to executive and non-technical audiences
  • High integrity and sound judgment when handling sensitive, confidential information
  • Experience in a research or academic medical center environment, including familiarity with research data sharing agreements, data use agreements (DUAs), and IRB processes
  • Experience integrating GRC platforms with data governance and security tooling for control monitoring and evidence collection
  • Proficiency with cloud data platforms (Azure, AWS) and modern data architectures (data lakes, pipelines, analytics platforms)
  • Experience evaluating AI/ML pipelines and data sets for compliance, privacy, and ethical use requirements
  • Ability to script or automate governance processes (Python, PowerShell, or API integrations)
  • Relevant certifications: CDMP, CIPT, CIPP/US, HCISPP, CISSP, CISM, CRISC, or HITRUST CCSFP

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Apply on Sorce