Description:
What Legal Management contributes to Cardinal HealthLegal provides the company with strategic, proactive, practical and cost-effective legal advice and services in order to protect the organization's assets, operations and image. This function provides legal counsel related to commercial, corporate securities, intellectual property, labor and employment, and regulatory law, among other areas. This function also litigates all company legal matters, manages outside counsel and manages legal operations.
Legal Management provides strategic oversight, leadership and direction within the Legal function.
Responsibilities:
- Serve as a functional expert working closely with and advising business leaders, commercial counsel, and other colleagues on privacy issues, including data protection, data retention, data usage, data security and data breaches
- Review and negotiation of data privacy agreements, data processing agreements, business associate agreements and other similar privacy-related provisions
- Advise on incident response and data breach reporting processes in coordination with the VP of Privacy
- Collaborate with IT Security teams to ensure alignment between IT security and privacy compliance programs
- Provide guidance, direction, and practical translation of privacy requirements to cross-functional teams on complex projects
- Assist with the management of legislative and regulatory inquiries, investigations or administrative actions related to privacy and data security
- Review policies and procedures to ensure compliance with applicable data privacy laws and regulations
- Advise on the design and provision of the privacy training program
- Remain up to date on legislative developments in Privacy at the state, federal and international level that may affect Cardinal Health
- Support acquisitions, divestitures, and joint ventures as they relate to privacy matters
What is expected of you and others at this level:
- Manages department operations and supervises professional employees, front line supervisors and/or business support staff
- Participates in the development of policies and procedures to achieve specific goals
- Ensures employees operate within guidelines
- Decisions have a short-term impact on work processes, outcomes and customers
- Interacts with subordinates, peers, customers, and suppliers at various management levels; may interact with senior management
- Interactions normally involve resolution of issues related to operations and/or projects
- Gains consensus from various parties involved
- Standard business will be conducted during Eastern Standard Time
Qualifications:
- 8-12 years of experience, preferred
- Bachelor's degree in related field, or equivalent work experience, preferred
- Juris Doctorate degree required
- License to practice law in Ohio or active bar license in another state
- Extensive knowledge of U.S. privacy and cybersecurity laws, regulations, and standards, including HIPAA, state privacy laws (e.g., comprehensive state privacy laws, state breach notification, etc.), as well as consumer protection and employment-related privacy laws and regulations
- Knowledge of international privacy and data security laws, including GDPR, preferred
- Strong relationship-building and collaboration skills
- Solution and results oriented, with the ability to prioritize and deliver key initiatives
- Ability to assess legal, practical and business risks quickly and accurately in a fast-paced environment, and make sound judgments under tight deadlines
- Be able to find practical and creative solutions and provide concise and business-focused legal advice
- Have excellent problem-solving, written and oral communication and interpersonal skills; and
- CIPP (US) certification preferred