Director of IT & Privacy

Description
Company Overview:
Cedarhurst Senior Living is an experienced operator of independent living, assisted living and memory care communities across the Midwest, Mid-South, and Southeast. Cedarhurst Senior Living is part of the Dover Companies, a vertically integrated healthcare organization established in 2007 to develop, construct, acquire, own, and operate high-quality senior living communities. In addition to Cedarhurst Senior Living, the Dover Companies include Dover Development, Brahms Construction, Dover Capital, Dover Health, and Medicine Express.
Cedarhurst Senior Living and the Dover Companies are mission driven — everything we do is grounded in our higher purpose of caring for seniors. Our decision making is informed by our mission “to create communities where each person feels loved, valued, supported and able to live life to the fullest.” Each business unit and each team member have a unique ability and responsibility to impact the lives of seniors, and we take that responsibility very seriously. We also embody an entrepreneurial spirit that has fueled our growth and continues to drive us forward.
Position Summary:
The Director of IT and Privacy leads the Dover Companies' information technology function and serves as the organization's data privacy and security compliance authority. This role is responsible for the strategic direction, operation, and security of enterprise IT systems, along with the design and oversight of privacy and regulatory compliance programs governing the collection, use, and protection of sensitive data. Given the regulated nature of the business, the Director ensures the organization's technology infrastructure and data handling practices meet applicable requirements under frameworks such as HIPAA, the Sarbanes-Oxley Act (SOX), and other healthcare industry regulations, while enabling the business through reliable, secure, and scalable technology. The Director is ultimately responsible for ensuring team members have reliable, secure, and practical technology that supports business purposes.
Why Work for Cedarhurst:
- At Cedarhurst, our core values guide how we work together and how we care for those we serve. We expect every team member to be passionate, trustworthy, empathetic, positive, respectful, and approachable. Being part of Cedarhurst means making a meaningful difference every day.
- We believe our team is our greatest strength. That’s why we invest in comprehensive training, as well as opportunities for both personal and professional growth. We’re committed to promoting from within and supporting team members who want to build their careers with us.
- Cedarhurst offers a competitive benefits package, including medical insurance, life insurance, long-term disability coverage, and a 401(k) plan with company match (after one year of service) for eligible employees.
- Additional Benefits Include:
- Work that makes a difference in the lives of our residents and community
- An on-site gym with brand-new equipment
- A personal trainer offering daily group classes, stretching sessions, and one-on-one training
- Catered lunches twice a week, prepared by our on-site chef
- Monthly team events and more
Essential Duties:
The following duties are normal for this position. This list is not to be construed as exclusive or all-inclusive. Other duties may be required and assigned. Reasonable accommodations may be made to enable individuals with disabilities to perform essential functions.
- Develop and execute the organization's IT strategy, roadmap, and budget in alignment with business goals and growth plans.
- Lead, mentor, and develop the IT team, including infrastructure, help desk, and applications, and manage relationships with outsourced/managed service providers.
- Support the Help Desk Manager in ensuring high-quality, responsive, and accountable support experience for all employees. Monitor help desk performance to identify root causes and improve service.
- Lead enterprise technology rollouts from planning through implementation, adoption, and post-launch optimization. Collaborate with all departments to ensure launches are operationally sound.
- Own the enterprise data privacy program, including policies, procedures, and controls governing the collection, storage, use, and disposal of personal, financial, and protected health information.
- Ensure ongoing compliance with applicable regulatory frameworks, including HIPAA, SOX IT general controls, state and federal privacy laws, as applicable to the business.
- Design, implement, and continuously improve the organization's cybersecurity program, including network security, endpoint protection, identity and access management, and data loss prevention. Mitigate harm from known impermissible uses and disclosures.
- Serve as the organization's primary point of contact for data privacy matters, including responding to regulator inquiries, data subject requests, and privacy impact assessments.
- Lead incident response planning and execution for security incidents and data breaches, including coordination with legal counsel and executive leadership as required.
- Partner with Legal and Finance to support SOX IT controls testing, audit requests, and remediation of findings.
- Manage vendor risk assessments and third-party due diligence for technology vendors handling sensitive or regulated data, including contract review for data protection and privacy terms for IT, website and software. Coordinates and ensures privacy compliance during implementation of all new technologies.
- Oversee enterprise IT infrastructure, including networks, servers, cloud environments, disaster recovery, and business continuity planning.
- Develop, maintain, and enforce IT and privacy policies, standards, and employee training programs, including annual security and privacy awareness training.
- Oversee the access request process, amendment requests, accounting of disclosures, and restrictions
- Evaluate and recommend new technologies, tools, and processes that improve operational efficiency, data governance, and regulatory compliance.
- Prepare and present IT and privacy program updates, risk assessments, and compliance metrics to executive leadership as needed.
- Stay informed on technology trends in senior living, healthcare, hospitality, smart-home technology, artificial intelligence, automation, and resident and patient experience.
- Other duties as assigned
Qualifications, Education and/or Experience:
To perform this job successfully, an individual must be able to perform each essential duty satisfactorily. The requirements listed below are representative of the knowledge, skills, and abilities required.
- Bachelor’s degree in information technology, Computer Science, Cybersecurity, or a related field; equivalent experience considered in lieu of degree. A master’s degree is preferred.
- Eight (8) to ten (10)+ years of progressive experience in information technology, with at least four (4) years in a leadership role overseeing both IT operations and data privacy/security compliance.
- Experience leading a help desk or end-user support function is required.
- Demonstrated experience working within a regulated industry (healthcare) and direct familiarity with HIPAA and/or SOX requirements.
- Strong working knowledge of privacy frameworks and regulations, including state and federal data privacy laws.
- Experience leading incident response, vendor risk management, and audit/regulatory examination processes.
- Proven ability to manage teams, budgets, and cross-functional projects, and to communicate technical and regulatory concepts to non-technical executives and staff.
- Experience with the senior living, construction, home health, hospice, and/or pharmacy industries is a plus.
Working Conditions:
As part of The Dover Company’s commitment to providing outstanding care and support, the company ensures that staff work under conditions that prioritize safety, collaboration, and professional growth. The conditions listed below define the experience of working in the Home Office or remotely.
- This position may involve a range of physical activities, including those outlined in the Essential Duties, but is not limited to them. This position may need to walk or stand for extended periods, especially when conducting safety inspections, audits or incident investigations.
- This position may need to lift to fifty (50) pounds.
- This position may need to move through areas of the corporate office or other worksites of the organization.
- Excellent interpersonal and communication skills with the ability to build relationships at all levels of the organization is required of this role.
- The individual in this position is responsible for maintaining a safe work environment by actively preventing accidents, preserving equipment, and promoting safe working practices.
- This role involves actively participating in all staff activities aimed at fostering teamwork, unity, and morale. The individual will contribute as a collaborative team player, working alongside colleagues to create a supportive and cohesive work environment.
- Individuals in this position are required to stay current on all training and ongoing education initiatives. They are expected to actively pursue self-improvement and embrace opportunities for continuous learning to enhance their skills and knowledge.
- This position is required to work onsite at the St. Louis Dover Companies headquarters at 300 Hunter Ave, Suite 200, St. Louis, MO 63124.
- There will be situations that arise that require this role to travel to an offsite company location. Anticipated potential travel does not exceed 20% of the annual work of this position.
We are an Equal Opportunity Employer. In compliance with the Americans with Disabilities Act, we will provide reasonable accommodations to qualified individuals with disabilities and encourages prospective employees and incumbents to discuss potential accommodations with the employer.
You'll be redirected to
the company's application page