Omada Health logo

Omada Health

Director, Privacy Counsel

Work from home

Remote role where the employee must remain based in a particular country.

United States only

Employer listed it 8 weeks ago · Added yesterday

Been open since 8 weeks ago. Long-running listings are sometimes left up after the role is filled.

Salary

$242,880 to $303,600

Location

United States only

Timezone

US East

Contract

Full-time

Experience

Lead

Category

Finance

Stated by the employer in the job description

Remote flexibility

Work from home

This is a remote role, but the employee must be based in United States. It is work from home rather than work from anywhere.

What the employer says

  • Source listing states candidate location: "Remote, USA, Remote"

What Nomaders makes of it

  • Residency required in United States
  • Payroll and tax are likely handled in that country only

The quotes above are the employer's own words; the reading is ours. Always check the original listing and employment terms before working from another country.

About the role

Omada Health is on a mission to bend the curve of chronic disease.

Job overview:

Omada Health is seeking a Director, Privacy Counsel to manage and mature our enterprise-wide privacy program across a complex and rapidly evolving regulatory landscape. This individual contributor role will operate at the intersection of healthcare regulatory law, consumer technology, and clinical operations, providing practical, business-oriented guidance that enables innovation while protecting our members’ data and trust. Reporting to the VP, Privacy and Healthcare Regulatory, you will serve as Omada’s primary operational privacy leader, partnering across Product, Engineering, Clinical, Commercial, and other key functions to design, implement, and continuously improve policies, processes, and controls that keep us compliant and ahead of emerging risks.

Your impact:

Manage Omada’s HIPAA privacy program, including policy and procedure development, incident investigations, and breach determination and response, ensuring compliance with HIPAA Privacy, Security, and Breach Notification Rules.

Drive privacy-by-design across digital products and services by embedding privacy requirements into product development, engineering workflows, clinical operations, and other business processes.

Execute Omada’s privacy risk assessment program, including data governance, vendor due diligence, and privacy review for commercial deals with employers, health plans, and PBMs, ensuring our contractual and regulatory obligations are met.

Provide expert guidance on consumer privacy compliance, including state consumer health data and general consumer privacy laws, digital advertising, and tracking technologies.

Serve as a key advisor on AI and emerging technologies, including AI privacy guidance and governance considerations across Omada’s AI and machine-learning initiatives.

Support interoperability and health information exchange participation (e.g., Carequality, CommonWell, TEFCA) by counseling on privacy and data use requirements and helping design compliant data flows.

Partner with internal stakeholders on ERISA and self-funded health benefit plan privacy considerations.

Support clinical research privacy compliance and IRB-adjacent work.

Design and deliver privacy training, awareness, and culture-building initiatives that enable Omada teammates to understand and live our privacy obligations in their day-to-day roles.

Success in this role will be measured by the maturity of our privacy program, including the quality, timeliness, and effectiveness of policies, training, incident response, and privacy counseling, and feedback from leaders and partners across the business.

About you:

You have a J.D. from an accredited law school and active bar admission.

You bring 8+ years of privacy law experience, including meaningful in-house experience at a healthcare, digital health, or life sciences company and/or at a top-tier law firm counseling healthcare, digital health, and/or life sciences clients.

You have deep substantive expertise in HIPAA Privacy, Security, and Breach Notification Rules and are fluent in the evolving landscape of state consumer privacy and consumer health data laws (e.g., WMHMDA, CCPA/CPRA) and AI governance.

You have demonstrated experience managing end-to-end privacy incident response and breach notification processes, from triage and investigation through regulator and stakeholder notifications.

You have a strong track record of advising on privacy-by-design for digital products, and in digital marketing and advertising ecosystems.

You communicate complex regulatory concepts clearly and succinctly for non-legal audiences and are skilled at crafting guidance that is practical, actionable, and aligned with business goals.

You are comfortable operating with substantial autonomy, exercising sound judgment in ambiguous regulatory environments with material legal and reputational stakes.

You are highly organized, able to manage multiple complex projects simultaneously, and known for strong attention to detail.

You bring a collegial, low-ego working style, enjoy cross-functional collaboration, and balance rigor with perspective and a sense of humor.

Requirements

  • ·You have a J.D. from an accredited law school and active bar admission.
  • ·You have demonstrated experience managing end-to-end privacy incident response and breach notification processes, from triage and investigation through regulator and stakeholder notifications.
  • ·You have a strong track record of advising on privacy-by-design for digital products, and in digital marketing and advertising ecosystems.
  • ·You communicate complex regulatory concepts clearly and succinctly for non-legal audiences and are skilled at crafting guidance that is practical, actionable, and aligned with business goals.
  • ·You are comfortable operating with substantial autonomy, exercising sound judgment in ambiguous regulatory environments with material legal and reputational stakes.

Benefits

  • ·Privacy certifications (e.g., CIPP/US, CIPM, CHPS).
  • ·Experience supporting clinical research privacy compliance and IRB-adjacent studies relating to clinical evidence generation.
  • ·Competitive salary with generous annual cash bonus
  • ·Employee stock purchasing plan (ESPP)

How to apply

  1. 1Check the flexibility label above, work from home, matches where you plan to live and work.
  2. 2Tailor your CV to the role at Omada Health, mentioning your remote working experience and working hours (US East).
  3. 3Apply directly on the employer's careers page using the button below. Nomaders never handles your application.

Found 1d ago. Last checked 23 Sept. Always confirm the details on the original posting, salary and location can change after publication.

Listing sourced from Company boards.

Similar roles

Other open finance roles with comparable remote rules.

Browse all open roles

Free to apply, no account needed.

$242,880 to $303,600 · You'll be taken to the employer's careers page.