Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy
Jobs / Job page
Information Security and Data Privacy Analyst - Contractor image - Rise Careers
Job details

Information Security and Data Privacy Analyst - Contractor

The Kestra team has over 400 years of experience in the external and internal cardiac medical device markets. The company was founded in 2014 by industry leaders inspired by the opportunity to unite modern wearable technologies with proven device therapies. Kestra’s solutions combine high quality and technical performance with a wearable design that provides the greatest regard for patient comfort and dignity. Innovating versatile new ways to deliver care, Kestra is helping patients and their care teams harmoniously monitor, manage, and protect life. 

 The Information Security and Data Privacy Analyst provides analysis and tactical execution related to information security, data privacy, and related risk management programs. This position is hands-on and must collaborate with stakeholders from a variety of business functions including IT, Legal, Quality, Regulatory, R&D, Operations, and others. This position takes direction from IT leadership and will assist in the management of 3rd party service providers related to these programs. 

ESSENTIAL DUTIES

  • Assist in the risk management activities for Information Security, Data Privacy, and IT General Controls programs 
  • Execute plans for these programs to support overall business strategy in collaboration with the Kestra Leadership Team 
  • Review and revise policy and procedures to increase efficiency, reduce duplicate efforts, and systematically mature Information Security, Data Privacy, and IT General Controls 
  • Execute strategies to comply with relevant domestic and international privacy regulations 
  • Assist in the internal and external audits of security, privacy, and IT controls, such as SOX, HIPAA/HITRUST, etc. 
  • Utilize standardized management systems and frameworks related to these programs 
  • Manage program initiatives using project management methodologies, develop project plans, gain resource commitments, and report on status to stakeholders and leadership 
  • Evangelize for security and privacy awareness throughout the company 
  • Analyze threat and risk vulnerabilities; develop and execute mitigation strategies 
  • Execute strategies to monitor and retain records that demonstrate compliance to internal and external auditors 
  • Assist in vendor management of third party consultants and managed service providers for program initiatives 
  • Analyze processes, procedures, and metrics to develop a high-functioning, lean organization 
  • Develop working relationships with other functional departments to coordinate activities, define standards, leverage resources, and maintain consistent environments 

COMPETENCIES 

  • Ability to be a self-starter, seek new and better methods, and work with minimum supervision 
  • Demonstrates deep expertise in industry best practices 
  • Ability to collaborate within a Team environment and across functions 
  • Capability to discern relevant facts and in turn, effectively resolve issues by making good decisions (compliance, quality, integrity, ethics, and critical thinking ability) 
  • Ability to be flexible in a fast-paced goal-oriented environment 
  • Demonstrates the understanding of deadlines and time limits, ability to accomplish goals, and the desire to win 

EDUCATION/EXPERIENCE REQUIRED

  • BS or BA in Computer Science, Information Technology, Business Administration, or related field  
  • Minimum of 7-10 years’ experience in Information Security or Data Privacy 
  • Formal certification in Information Security Management, Data Privacy, Information Systems Audit, or related field  
  • Exposure to and understanding of Sarbanes-Oxley Section 404 and related assessments of internal controls 
  • Exposure to and understanding of state, federal and international data privacy regulations such as CCPA, HIPAA, and GDPR 
  • Exposure to and understanding of ISO 27001 and NIST Cybersecurity Framework 

Preferred:

  • Ability to think creatively and holistically 
  • Strong teambuilding and influence skills 
  • Proven experience successfully executing a strategic plan 
  • Broad knowledge in IT systems and infrastructure  
  • Broad knowledge of process improvement methodologies such as Six Sigma, Lean or TQM 
  • Experience in setting compliance directions and strategies  
  • Excellent written and verbal communication skills  
  • Strong project management skills  
  • Strong analytical skills  
  • Prior experience in medical technology or other life science industries 

WORK ENVIRONMENT

  • Indoor open office environment
  • Minimal noise volume typical to an office environment
  • Extended hours when needed
  • Drug-free, as per FDA regulations

PHYSICAL DEMANDS

  • Frequent repetitive motions that may include wrists, hands and/or fingers, such as keyboard and mouse usage
  • Frequent stationary position, often standing or sitting for prolonged periods of time
  • Frequent computer use
  • Frequent phone and other business machine use
  • Occasional lifting required, up to 20 pounds

TRAVEL

  • Occasional travel, less than 10%

OTHER DUTIES

This job description is not designed to cover or contain a comprehensive listing of activities, duties or responsibilities that are required of the Team Member. Duties, responsibilities, and activities may change or new ones may be assigned at any time with or without notice.

  • Contract/1099
  • Remote
  • We provide training and technology
  • Billing rate ($50-$90/hour)

Average salary estimate

$145600 / YEARLY (est.)
min
max
$104000K
$187200K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

What You Should Know About Information Security and Data Privacy Analyst - Contractor, Kestra Medical Technologies, Inc

Are you ready to delve into the world of Information Security and Data Privacy? Join Kestra as an Information Security and Data Privacy Analyst - Contractor, and become a crucial part of our mission to innovate in the cardiac medical device sector. With a remarkable legacy of over 400 years of combined experience, our team focuses on integrating cutting-edge wearable technology with patient care. As our analyst, you'll engage hands-on with stakeholders across various business functions, including IT, Legal, and Operations, to ensure the highest standards of our information security and data privacy protocols are met. Your role will involve executing risk management programs, revising policies, and complying with evolving domestic and international privacy regulations. Plus, you will assist with internal and external audits to uphold compliance with rigorous standards like HIPAA and SOX. At Kestra, you will implement effective strategies to enhance awareness and understanding of security and privacy throughout the organization, while also analyzing threats and developing risk mitigation strategies. If you have a proven track record in Information Security or Data Privacy, a passion for project management, and the ability to collaborate across diverse teams, we want to hear from you! Enjoy the flexibility of a remote position, where you will thrive in a fast-paced, team-oriented environment while contributing to innovations that truly matter for patient care and comfort.

Frequently Asked Questions (FAQs) for Information Security and Data Privacy Analyst - Contractor Role at Kestra Medical Technologies, Inc
What are the responsibilities of the Information Security and Data Privacy Analyst at Kestra?

As the Information Security and Data Privacy Analyst at Kestra, your primary responsibilities will include executing risk management activities, collaborating with various business functions to enhance information security and data privacy protocols, reviewing and revising policies for efficiency, and ensuring compliance with domestic and international regulations. You'll also assist with internal and external audits and develop strategies to monitor compliance with industry standards.

Join Rise to see the full answer
What qualifications are required for the Information Security and Data Privacy Analyst position at Kestra?

To qualify for the Information Security and Data Privacy Analyst role at Kestra, you should have a BS or BA in Computer Science, Information Technology, or Business Administration, along with 7-10 years of experience in Information Security or Data Privacy. Formal certifications in related areas, familiarity with privacy regulations like CCPA and GDPR, and an understanding of risk management frameworks such as ISO 27001 and NIST are highly desirable.

Join Rise to see the full answer
How does the Information Security and Data Privacy Analyst contribute to Kestra's mission?

The Information Security and Data Privacy Analyst plays a vital role in supporting Kestra's mission by ensuring the integrity and confidentiality of patient data, thus enhancing the delivery of innovative cardiac medical solutions. By managing compliance and security risks, you help create a safe environment for patients, ultimately enhancing their care and comfort.

Join Rise to see the full answer
What work environment can the Information Security and Data Privacy Analyst expect at Kestra?

The Information Security and Data Privacy Analyst at Kestra will work in an indoor open office environment that encourages collaboration and innovation. Remote work is available, providing flexibility. The workplace adheres to FDA regulations, ensuring a drug-free and healthy work atmosphere, with occasional travel expected (less than 10%).

Join Rise to see the full answer
What project management skills are beneficial for the Information Security and Data Privacy Analyst role at Kestra?

Strong project management skills are essential for the Information Security and Data Privacy Analyst at Kestra. This includes the ability to develop project plans, manage resources effectively, and report on initiatives' statuses to leadership. Familiarity with project management methodologies will enhance your effectiveness in executing risk management strategies and program initiatives.

Join Rise to see the full answer
Common Interview Questions for Information Security and Data Privacy Analyst - Contractor
Can you describe your experience with information security and data privacy regulations?

When answering this question, focus on your specific experience with regulations such as SOX, HIPAA, and GDPR. Discuss your understanding of compliance requirements, any involvement in audits you’ve had, and how you've ensured adherence to these regulations in past roles.

Join Rise to see the full answer
How do you prioritize competing information security tasks?

A solid answer would involve outlining a process for assessing risks based on potential impact and urgency. Discuss any frameworks or methodologies you've utilized for prioritization, emphasizing teamwork and communication with stakeholders to ensure that priority tasks align with organizational strategy.

Join Rise to see the full answer
What tools and frameworks are you familiar with for managing information security?

Highlight your experience with tools and frameworks such as NIST, ISO 27001, or specific risk management software. Demonstrating proficiency with these tools shows that you are well-prepared for the Information Security and Data Privacy Analyst role at Kestra.

Join Rise to see the full answer
Describe a time when you had to implement a new security policy. What was the process?

Use the STAR method (Situation, Task, Action, Result) to answer this. Talk about a specific instance where you identified the need for a policy change, the steps you took to develop and communicate this policy, and the results that followed, such as improved compliance or reduced incidents.

Join Rise to see the full answer
What do you find most challenging about working in information security?

It's important to be honest yet diplomatic here. You might mention the rapid evolution of threats and regulations and the need for constant adaptation. Talk about how you've tackled these challenges through continuous education and proactive engagement with industry best practices.

Join Rise to see the full answer
How do you stay current with the changes in data privacy laws?

Discuss specific resources you use to keep informed, such as professional organizations, webinars, and industry publications. Highlight your commitment to continuous learning in this dynamic field, which is crucial for the Information Security and Data Privacy Analyst position at Kestra.

Join Rise to see the full answer
What experience do you have with vendor management in relation to security services?

Provide examples that demonstrate your experience managing third-party vendors, focusing on strategies used to ensure compliance and security measures. Emphasize any specific challenges and how you worked to resolve them.

Join Rise to see the full answer
How would you approach stakeholder engagement when discussing security topics?

Discuss the importance of clear communication tailored to the audience. Relay your strategies for fostering relationships with stakeholders to ensure they understand the importance of security measures and compliance, focusing on collaborative solutions.

Join Rise to see the full answer
What steps do you take to assess security risks related to new projects?

Detail your approach to risk assessment, which could include conducting threat modeling or vulnerability assessments. Explain how you involve relevant parties and document findings for compliance and process improvements.

Join Rise to see the full answer
Can you provide an example of a successful risk mitigation strategy you implemented?

Using the STAR method, share a specific example of a risk mitigation strategy you put in place. Be sure to include the initial risk assessment, the strategy implemented, and the positive outcomes realized from its execution.

Join Rise to see the full answer
MATCH
VIEW MATCH
FUNDING
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
No info
HQ LOCATION
No info
EMPLOYMENT TYPE
Contract, remote
DATE POSTED
March 28, 2025

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!
LATEST ACTIVITY
Photo of the Rise User
Someone from OH, Dublin just viewed Cashier - Sawmill Road Market District at Giant Eagle
M
Someone from OH, Cincinnati just viewed Dental Practice Manager at Mortenson Family Dental
Photo of the Rise User
16 people applied to Associate Security Analyst at ANS
Photo of the Rise User
Someone from OH, Columbus just viewed Summer 2025 Data Intern at Reproductive Freedom for All
Photo of the Rise User
Someone from OH, Athens just viewed Medical Assistant - Podiatry - Athens at OhioHealth
K
Someone from OH, Dublin just viewed UI/UX Designer at Konrad
Photo of the Rise User
Someone from OH, Columbus just viewed EdTech Product/Program Manager at Planner5D
Photo of the Rise User
Someone from OH, Cleveland just viewed Marketing Analytics Intern - Summer 2025 at Spectrum
Photo of the Rise User
28 people applied to IT Intern at USAA
Photo of the Rise User
Someone from OH, Cincinnati just viewed Bookkeeper - Franchise Location at H&R Block
Photo of the Rise User
Someone from OH, Holland just viewed Data Intelligence Intern at Actian Corporation
Photo of the Rise User
Someone from OH, Holland just viewed Program Intern, Data Engineering at Pilot Company
Photo of the Rise User
Someone from OH, Sandusky just viewed Head of IT/Security at Aerones
Photo of the Rise User
Someone from OH, Sandusky just viewed Vice President, Technology at MedVA
I
Someone from OH, Sandusky just viewed IT Manager at Infinite Locus
Photo of the Rise User
Someone from OH, Cincinnati just viewed Finance Associate at Street Diligence
M
Someone from OH, Sandusky just viewed Director of Security, IT, & Compliance at Murmuration
W
Someone from OH, Sandusky just viewed Enterprise Technology Director at World Central Kitchen
Photo of the Rise User
Someone from OH, Sandusky just viewed Director of IT at Kyo
Photo of the Rise User
Someone from OH, North Ridgeville just viewed Remote Manager in Training- CS/Sales at Global Elite
Photo of the Rise User
Someone from OH, Cleveland just viewed Software Engineer I (DevOps) at Mastercard
C
Someone from OH, Warren just viewed Front End Developer (for AI Agent) at CyberCare