SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Salary: USD 100,000 - 120,000 / annual
Virta Health, a venture-backed healthtech company on a mission to reverse metabolic disease, is seeking a Privacy and Compliance Specialist to own day-to-day privacy operations and compliance execution. This role reports to the Sr. Corporate Counsel and Privacy Officer and serves as the primary point of contact for privacy matters across Legal, Engineering, Product, Security, and Commercial teams.
Key responsibilities include managing Virta's privacy compliance program (policies, procedures, documentation) under HIPAA, CCPA/CPRA, and other applicable frameworks. You will conduct and coordinate privacy impact assessments (PIAs/DPIAs) for new products, features, and vendor relationships; maintain records of processing activities, data inventories, and data flow maps; and implement Privacy by Design principles. You'll support data subject rights requests (DSARs) and privacy incident response workflows.
On the customer and partner side, you'll serve as the primary contact for privacy inquiries from customers, prospects, and partners. This includes drafting responses to privacy questionnaires, RFPs, security assessments, and due diligence requests, as well as supporting negotiation and review of Data Processing Agreements (DPAs) and Business Associate Agreements (BAAs).
You'll also drive privacy and compliance initiatives from planning through execution, manage timelines and stakeholders, develop and deliver privacy training programs, build privacy metrics and dashboards for leadership visibility, and identify opportunities to automate privacy processes.
Within 90 days, you'll get up to speed on Virta's privacy program and data flows, take ownership of the PIA/DPIA process, assume management of incoming privacy inquiries with repeatable workflows, review and improve DSAR and incident response procedures, and begin building privacy metrics and reporting.
Required: 4–7 years in privacy, compliance, data protection, or related field; working knowledge of HIPAA, state consumer privacy laws (CCPA/CPRA), and health data regulations; demonstrated project management skills managing multiple workstreams; experience with PIAs, incident response, or DSAR workflows; strong written and verbal communication; proactive use of AI tools to improve efficiency.