We use cookies. Find out more about it here. By continuing to browse this site you are agreeing to our use of cookies.
#alert
Back to search results
New

Security / Compliance Specialist, Senior- Data Management

LCG, Inc.
$121,400.00 - $144,500.00 / yr
retirement plan
United States, Maryland, Maryland
Apr 30, 2025

This job opportunity is part of an RFP process; candidates are invited to submit their resumes detailing relevant experience.

Job Title - Security / Compliance Specialist, Senior

Job Summary: Security / Compliance Specialist, Senior will play a critical role in establishing and managing the client supporting the NIH-funded Program. This individual will be responsible for ensuring that all data management activities across the DMCC are compliant with HIPAA, FISMA, Common Rule, FAIR guidelines, NIH data-sharing policies, and other applicable federal requirements. The Specialist will design and oversee security protocols, quality assurance processes, documentation, and compliance training to safeguard sensitive human subject data and research outputs.

Key Responsibilities

Security and Compliance Management



  • Establish, implement, and maintain data protection and compliance frameworks aligned with FISMA, HIPAA Privacy Rule, Common Rule, NIH data-sharing policies, and federal standards.





  • Lead security risk assessments and vulnerability analyses for the client data systems and public/private portals.





  • Develop and enforce SOPs for data security, access control, encryption, anonymization, and secure data transfer.





  • Ensure proper de-identification and anonymization of human subject data prior to public sharing.





  • Maintain audit trails, version control, and comprehensive security documentation according to DHHS EPLC and OMB guidelines.





  • Collaborate with internal and external stakeholders (e.g., NIH, ImmPort, CEIRR, Bioinformatics Resource Centers) to ensure interoperability and secure data exchange.



Data Quality Control and Assurance



  • Develop and execute quality control plans, including automated validation, error-checking, and regular QA/QC reports.





  • Monitor data collection processes to ensure uniformity, accuracy, and compliance across multiple study sites and data contributors.





  • Generate regular data security and compliance status reports for internal and external review.



Portal Security and Compliance Oversight



  • Maintain compliance standards for client public and private portals, ensuring secure controlled access and protection of sensitive information.





  • Oversee security features supporting data browsing, sharing of research products, and public-facing information.



Training and Communication



  • Provide training and consultations to client investigators on security practices, compliance policies, and proper use of DMCC-supported systems.





  • Develop and maintain manuals, guides, and training materials related to compliance and security.





  • Support working groups and cross-collaborative teams by providing compliance insights during the development of procedures and resources.



Support for Publications and Reporting



  • Assist in the preparation of compliance sections for client-related scientific manuscripts and reports.



Qualifications



  • Bachelor's degree in Information Security, Computer Science, Information Systems, or a related field. Master's degree preferred.





  • 6+ years of hands-on experience in IT security and federal compliance, particularly in a biomedical or clinical research environment.





  • Relevant certifications such as CISSP, CISA, CISM, or HITRUST preferred.





  • Experience working with data management platforms such as ImmPort, IEDB, CEIRR, or NIH/academic consortia.





  • Familiarity with DHHS Enterprise Performance Life Cycle (EPLC) standards.





  • Experience supporting research consortia, clinical trials, or translational science projects.





  • Strong working knowledge of HIPAA, FISMA, Common Rule, FAIR principles, and NIH data-sharing guidelines.





  • Experience with security controls for web-based portals, database systems, and cloud platforms.





  • Demonstrated ability to conduct security audits, risk assessments, and quality control analyses.





  • Proficient in creating and maintaining documentation, SOPs, compliance reports, and security plans.





  • Excellent interpersonal skills and experience providing security training to diverse scientific/technical audiences.





  • Strong organizational and project management skills.



Compensation and Benefits

The projected compensation range for this position is $121,400 to $144,500 per year benchmarked in the Washington, D.C. metropolitan area. The target salary is $132,800 per year for the role. The salary range provided is a good faith estimate representative of all experience levels. Salary at LCG is determined by various factors, including but not limited to role, location, the combination of education/training, knowledge, skills, competencies, certifications, and work experience.

LCG offers a competitive, comprehensive benefits package which includes health insurance options (medical, dental, vision), life and disability insurance, retirement plan contributions, as well as paid leave, federal holidays, professional development, and lifestyle benefits.

Devoted to Fair and Inclusive Practices

All qualified applicants will receive consideration for employment without regard to sex, race, ethnicity, age, national origin, citizenship, religion, physical or mental disability, medical condition, genetic information, pregnancy, family structure, marital status, ancestry, domestic partner status, sexual orientation, gender identity or expression, veteran or military status, or any other basis prohibited by law.

If you are interested in applying for employment with LCG and need special assistance or an accommodation to apply for a posted position, contact our Human Resources department by email at hr@lcginc.com.

Securing Your Data

Beware of fraudulent job offers using LCG's name. LCG will never request payment-related details or advancement of money during the application process. Legitimate communication will only come from lcginc.com or system@hirebridgemail.com emails, not free commercial services like Gmail or WhatsApp. If you receive suspicious emails asking for payment or personal information, contact us immediately at hr@lcginc.com.

If you believe you are the victim of a scam, contact your local law enforcement and report the incident to the U.S. Federal Trade Commission.

Applied = 0

(web-94d49cc66-c7mnv)